Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Spy Agencies could’ve installed malware using Unencrypted YouTube videos and Microsoft Live log-ins – onmsft.com

Spy Agencies could’ve installed malware using Unencrypted YouTube videos and Microsoft Live log-ins – onmsft.com

Staff Writer Staff Writer
August 18, 2014
2 min read

Spy agencies

According to a paper by Morgan Marquis at the University of Toronto based The Citizen Lab, spy agencies had been able to use unencrypted YouTube videos and Microsoft Live log-ins to install malwalware on your devices. No need to panic, however, as YouTube and Microsoft have moved on to encrypted connections, so this is not a current vulnerability for these services.

This vulnerability was a network injection, a man-in-the-middle attack. This is where agencies intercept traffic between the server and the consumer, and manipulated to include malware. It is scary because government agencies have the power to force cooperation of network providers and force their silence.

This type of attack is not possible on encrypted connections. However, a large portion of connection are not encrypted. There are sites that use encrypted connections, while also use unencrypted traffic for ad networks or third parties. These are still vulnerable to network connections.

This is a more widespread problem than merely YouTube and Microsoft Live. There are companies that provide spy agencies with the tools to continue to capitalize on these vulnerabilities. This allows an easy access to network injections in less democratic or advanced countries that could use this to target dissenters, etc. You can read the study in full here.

The only way to counter this is to promote encrypted connections. Encouragement like Microsoft’s promise of higher ranking in Bing search results to companies that implement encrypted connections will hopefully push sites to make the change faster.

The unsettling reminder that studies like this give us is that there are many potentially current exploits that we will only find out about in a paper such as this in the future. However, each of these papers do also spurn more action and bring attention to security. Hopefully, we will see a continued decline in security vulnerabilities as  companies place increasing attention on security and customers demand it. 

Share This Post:

Share this article:
Tags:
Encryption NSA Security YouTube
Previous Article Xbox One SmartGlass, Nokia Camera Beta, and MetroMail for Windows Phone receive new improvements | On MSFT Next Article Bing Developer Assistant plugin for Visual Studio adds IntelliSense, Sample Browser, and offline support | On MSFT

Related Articles

ChatGPT Atlas Update Adds Multi-Account Sign-In for Separate Profiles

March 11, 2026
Microsoft teases Xbox Helix, a powerful next-gen console with PC game support

Xbox Project Helix Has Been in the Works for Nearly a Decade

March 10, 2026

People Leaving ChatGPT for Claude Are Noticing Big Differences

March 10, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • ChatGPT Atlas Update Adds Multi-Account Sign-In for Separate Profiles
  • Xbox Project Helix Has Been in the Works for Nearly a Decade
  • People Leaving ChatGPT for Claude Are Noticing Big Differences
  • OpenAI Acquires Promptfoo to Boost AI Agent Security
  • Anthropic adds ‘Code Review’ tool to inspect Claude Code pull requests

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • ChatGPT Atlas Update Adds Multi-Account Sign-In for Separate Profiles
  • Xbox Project Helix Has Been in the Works for Nearly a Decade
  • People Leaving ChatGPT for Claude Are Noticing Big Differences
  • OpenAI Acquires Promptfoo to Boost AI Agent Security
  • Anthropic adds 'Code Review' tool to inspect Claude Code pull requests

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy