MSFT Criminal Compliance Handbook Leaked

February 24, 2010 -

The release of an internal Microsoft document, which details how the software giant stores information and the ways in which law enforcement members can access it, has drawn the wrath of Redmond.

As detailed on GeekOSystem.com, the document, entitled Global Criminal Compliance Handbook, and dated March, 2008, was originally posted by the whistleblower website Cryptome. Microsoft reacted quickly, claiming that the document was copyright material under the Digital Millennium Copyright Act (DMCA), and the offending content, and indeed, the whole website, was taken down swiftly.

Fortunately, BusinessInsider decided to host the PDF on its website for anyone interested in viewing it. The document is a version for U.S. law enforcement officials, and pertains to Microsoft’s online services such as Windows Live, Windows Live ID Windows Live Messenger, Hotmail and Xbox Live.

Cryptome editor John Young detailed what he found most distasteful in the document:

Most repugnant in the MS guide was its improper use of copyright to conceal from its customer violations of trust toward its customers. Copyright law is not intended for confidentiality purposes, although firms try that to save legal fees. Copyright bluffs have become quite common, as the EFF initiative against such bluffs demonstrates.


Second most repugnant is the craven way the programs are described to ease law enforcement grab of data. This information would also be equally useful to customers to protect themselves when Microsoft cannot due to its legal obligations under CALEA.

For Xbox 360 users who have registered on Xbox Live with a credit card, Microsoft collects and stores your: date of birth, name, e-mail address, physical address, telephone number, credit card number, type of credit card, credit card expiration and Microsoft Passport.

Xbox Live users will have their registration and IP connection history recorded “for the life of the gamertag account.” Also collected, and stored, is the Xbox’s serial number (if it was registered online).

Law enforcement officials armed with a subpoena can grab “basic subscriber information,” such as name, address, screen names, IP address, IP logs, billing info and email content “more than 180 days old.”

A court order results in “disclosure of all of the basic subscriber information available under a subpoena plus the e-mail address book, Messenger contact lists, the rest of a customer’s profile not already listed above, internet usage logs and e-mail header information (to/from) excluding subject line.”

Search warrants allow law enforcement members to access emails in electronic storage 180 days or less.

The Cryptome site has since returned on a different domain and posted the full email trail from Microsoft and Network Solutions that led to the original site being shuttered.


Comments

Re: MSFT Criminal Compliance Handbook Leaked

 I hope they're not storing Canadian personal information on a server farm within the United States.  That's definitely illegal and perhaps some Canadian lawyer that wanted to "get rich quick" should take them to task over it.

Re: MSFT Criminal Compliance Handbook Leaked

What are they covering up?  The fact they cooperate with law enforcement when Microsoft is given the appropriate supoenas/warrents?

Sounds less like a cover up and more like buisness as usual for most companies located in the United States.

Re: MSFT Criminal Compliance Handbook Leaked

It's not a coverup if an internal document was leaked and taken down.

 

If GamePolitics had a website leak one of their internal documents, are you telling me they wouldn't take steps to have it taken down? And if they did, would THAT be considered a coverup?

Re: MSFT Criminal Compliance Handbook Leaked

Yes, yes it would.

--------------------------------------------------

I LIKE the fence. I get 2 groups to laugh at then.

-------------------------------------------------- I LIKE the fence. I get 2 groups to laugh at then.

Re: MSFT Criminal Compliance Handbook Leaked

 no it wouldn't.

Re: MSFT Criminal Compliance Handbook Leaked

While cover ups aren't exactly appreciated, isn't all that's being covered up standard regulation that i would assume all companies have? that is to supply information when the proper legal actions (warrents and such) are taken?

doesn't really seem something to get up in arms about. sure one could say it implies microsoft is covering worse things up, but then again any action can imply a lot of things.

Re: MSFT Criminal Compliance Handbook Leaked

I read the PDF.  There really isn't anything there that we didn't know already.   What it really does confirm is that Microsoft only complies with a government's request for information if they have a subpoena from a court.  I don't know why Microsoft is getting their panties into a bunch, this is stuff the criminals already know...

ZOMG U GUYS HAVE LOGS OF WHAT SERVICES I USE FROM U! OMGWTFBBQ

Re: MSFT Criminal Compliance Handbook Leaked

Pretty much every company does that. Personally, I don't see what the problem is or why people are complaining.

I've worked for several large cellular carriers, and trust me, the information THEY have about their customers and keep on file is much more extensive than this, and no one is up in arms. Their proceedure for giving up information was the same: law enforcement needed a subpeona to get it. And I bet they work with criminal investigators a lot more often than Microsoft.

Also, stuff like credit card numbers, type of credit card, expiration date, physical address, and phone number are all information that's needed to repeat bill the credit card. Xbox Live has auto renew. Blame the credit card companies.

Re: MSFT Criminal Compliance Handbook Leaked

It seems to me that the coverup is far worse than what's being covered up.  It sounds like MS is actually complying with due process and only giving away this information to law enforcement if they have a warrant or subpoena.  Sprint was recently revealed doing much worse (allowing law enforcement to track people's physical locations using their cell phones, WITHOUT a warrant), and nobody batted an eye.

MS's real abuse here is in misusing copyright law in an attempt to silence whistleblowers.  If they'd just come out and say "Yes, we store this information, and yes, we will comply with law enforcement, but only if a warrant is provided," then most people would find that perfectly reasonable.

Re: MSFT Criminal Compliance Handbook Leaked

Yeah, it kinda pisses me off that they claimed copyright infringement to get the site locked.  And I fear that this is what's going to happen to many sites in the near future.

---

I once had a dream about God. In it, he was looking down upon the planet and the havoc we recked and he said unto us, "Damn Kids get off my lawn!"

I once had a dream about God. In it, he was looking down upon the planet and the havoc we recked and he said unto us, "Damn Kids get off my lawn!"

Re: MSFT Criminal Compliance Handbook Leaked

And although plenty will complain about it, not a single one of you will cancel your accounts over it, continuing to shovel them money, thereby aproving of what they are doing. 

A few years ago an analysis was done showing how much personal information MSFT "could" get from the apps running in XP and Vista systems, if they actually wanted it. People on a website i frequented were all up in arms, many stating "That's the final straw, i'm going to linux!"

Years later, they're all still using MSFT OS's

Re: MSFT Criminal Compliance Handbook Leaked

Although I still have an xbox account. I stopped paying for live a long time ago. Perfer the ps3 for my online needs. Once my 360 died for the 3rd time from the ring of death I decided that most of my game buys would be for the ps3 or pc. I still buy games for 360 but only exclusive titles.

 
Forgot your password?
Username :
Password :

Shout box

You're not permitted to post shouts.
Cheater87Look what FINALLY came to Australia uncut! http://www.gamespot.com/articles/left-4-dead-2-gets-reclassified-in-australia/1100-6422038/?utm_source=gamefaqs&utm_medium=partner&utm_content=news_module&utm_campaign=hub_forum09/02/2014 - 6:49am
Andrew EisenHence the "Uh, yeah. Obviously."09/02/2014 - 12:53am
SleakerI think Nintendo has proven over the last 2 years that it doesn't.09/02/2014 - 12:31am
Andrew EisenSleaker - Uh, yeah. Obviously.09/01/2014 - 8:20pm
Sleaker@AE - exclusives do not a console business make.09/01/2014 - 8:03pm
Papa MidnightI find it disappointing that, despite the presence of a snopes article and multiple articles countering it, people are still spreading a fake news story about a "SWATter" being sentenced to X (because the number seems to keep changing) years in prison.09/01/2014 - 5:08pm
Papa MidnightAnd resulting in PC gaming continuing to be held back by developer habits09/01/2014 - 5:07pm
Papa MidnightI find it disappointing that the current gen of consoles is representative of 2009-2010 in PC gaming, and will be the bar by which games are released over the next 8 years - resulting in more years of poor PC ports (if they're ever ported)09/01/2014 - 5:06pm
Andrew EisenMeanwhile, 6 of Wii U's top 12 are exclusive: Mario 3D World, Nintendo Land, Pikmin 3, Mario Kart 8, Wonderful 101, and ZombiU. (Wind Waker HD is on the list too but I didn't count it.)09/01/2014 - 4:36pm
Andrew EisenLikewise, only two of Xbox One's top 12 are exclusive: Dead Rising 3 and Ryse: Son of Rome (if you ignore a PC release later this year).09/01/2014 - 4:34pm
Andrew EisenNot to disrespect the current gen of consoles but I find it telling that of the "12 Best Games For The PS4" (per Kotaku), only two are exclusive to the system: Infamous: Second Son and Resogun.09/01/2014 - 4:30pm
MaskedPixelantehttp://www.joystiq.com/2014/09/01/beyond-two-souls-ps4-trophies-emerge-directors-cut-reported/ MMM MMM, nothing quire like reheated last gen games to make you appreciate the 400 bucks you spent on a new console.09/01/2014 - 4:24pm
Andrew EisenThat's actually a super depressing thought, that a bunch of retweeters are taking that pic as an illustration of the actual issue instead of an example of a complete misunderstanding of it.09/01/2014 - 4:20pm
Andrew EisenObviously, the picture was created by someone who doesn't understand what the issue actually is (or, possibly, someone trying to satire said misunderstanding).09/01/2014 - 4:10pm
Papa MidnightPeople fear and attack what they do not understand.09/01/2014 - 4:04pm
Papa MidnightWell, let's not forget. Someone held their hand in a peace sign a few weeks ago and people started claiming it was a gang sign. Or a police chief displayed the hand signal of their fraternity and was accused of the same.09/01/2014 - 4:04pm
SleakerEither people don't understand that what the picture is saying is true, or the picture was created out of a misunderstanding of what sexism is.09/01/2014 - 3:52pm
Sleaker@AE ok yah that's where the kind of confusion I'm getting. Your tweet can be taken to mean two different things.09/01/2014 - 3:51pm
Andrew EisenSleaker - No. No, not even remotely. The pic attached to my tweet was not made by me; it's not a statement I'm making. It's an illustration of the complete misunderstanding of the issue my tweet is referring to.09/01/2014 - 3:13pm
Papa MidnightIn other news, Netflix states why it paid Comcast: http://money.cnn.com/2014/08/29/technology/netflix-comcast/index.html?hpt=hp_t209/01/2014 - 3:10pm
 

Be Heard - Contact Your Politician