Ballmer's replacement will have to build trust overseas, especially after report Germany advised to not use Windows 8 because of backdoor When Microsoft Chief Executive Steve Ballmer steps down in the next 12 months, his successor will be left with the task of easing rising privacy concerns fueled by reports of massive Internet snooping by the U.S. National Security Agency.Ballmer announced his plans for retirement on Friday, saying the company needed someone who would be with Microsoft long enough to see through its transition from a software maker to a “devices and services” business.The next CEO will have to provide a much better strategy than Ballmer on moving Microsoft into the fast-growing tech markets Ballmer missed early on, including the shift in Internet advertising to search and the movement from PCs to tablets and smartphones.On top of all that, the new top executive will have to guide the company in mistrustful overseas markets shaken by the steady stream of media reports of NSA Internet data gathering. In the latest fallout from the NSA’s terrorist-hunting, the German national weekly newspaper Die Zeit reported that experts are warning the government not to use Windows 8 or its successor because they contain a backdoor that could be exploited by the U.S. agency. Ironically, the offending technology, called Trusted Computing, is the foundation for a much higher level of security than what has existed in Windows PCs in the past. What Microsoft has done is link the operating system to a special chip called a Trusted Platform Module. Working together, the technologies provide Microsoft a protected channel for automatic updating and monitoring for software piracy.Specifications for the architecture come from the Trusted Computing Group, a non-profit organization whose members include the biggest names in the U.S. tech industry, including Microsoft, IBM, Cisco, Hewlett-Packard and Intel.[Also see: Latest NSA revelations could help pending lawsuits | Groklaw shutdown shows ‘chilling effect’ of NSA surveillance | NSA revelations a mixed bag for private clouds | Cloud market destined to change following NSA leaks | U.S. openness, restraint could lessen fallout from NSA surveillance]Experts advising the German Federal Office for Information Security (BSI) say the backdoor created by Microsoft’s Trusted Computing implementation in Windows 8 cannot be closed and “could have the effect that Microsoft can control any computer remotely … and thus [also] the NSA,” Die Zeit reports, according to a Google translation of the report.The wariness toward Microsoft goes beyond just Trusted Computing. In July, the British newspaper The Guardian reported that Microsoft helped the NSA in intercepting web chats on the new Outlook.com portal and in collecting video calls on Skype, which Microsoft purchased in 2011 for $8.5 billion.Microsoft is only one of many U.S. Internet companies forced under federal law to cooperate with the NSA when it comes calling. Other companies reportedly working with the NSA include Google, Facebook, Yahoo and Apple. Therefore, Ballmer’s successor and the CEOs of the other companies face the same problem, which is proving to foreign customers they can be trusted while abiding by U.S. laws. “Microsoft, because it is the world’s most popular desktop operating system, faces this in spades,” said Frank Gillett, an analyst with Forrester Research.Microsoft’s next CEO will have to reach agreements with overseas customers that build trust, Gillett said. In addition, that person will have to establish a working relationship with each government, since foreign countries are as interested in surveillance to prevent terrorism as the NSA.“They’re going to have to brainstorm in private with the governments also to figure out where to try and draw the boundaries,” Gillett said. Related content feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO CSO and CISO C-Suite news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry news UK data regulator warns that data breaches put abuse victims’ lives at risk The UK Information Commissioner’s Office has reprimanded seven organizations in the past 14 months for data breaches affecting victims of domestic abuse. By Michael Hill Sep 28, 2023 3 mins Electronic Health Records Data Breach Government news EchoMark releases watermarking solution to secure private communications, detect insider threats Enterprise-grade software embeds AI-driven, forensic watermarking in emails and documents to pinpoint potential insider risks By Michael Hill Sep 28, 2023 4 mins Communications Security Threat and Vulnerability Management Security Software Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe