Earlier quoted context omitted.
I'm speculating here, but surely by this argument Apple has a backdoor to unlock the phone if it physically has it.
No. What Apple had was the option of updating the phone with a compromised (or compromisable) security implementation. Apple refused to do that. The FBI did find an exploit (which AFAIR they've refused to disclose, in controvention of previous policy if not regulation and/or law), but that represents a flaw in implementation which Apple can then remedy. http://mashable.com/2016/02/16/apple-hack-san-bernardino-pho...…
Microsoft proves backdoor keys are a bad idea
81–90 of 106 posts
Re: Microsoft proves backdoor keys are a bad idea
#82Earlier quoted context omitted.
>I will base my criticism on actual events such as this one instead of hypotheticals. The problem is that due to its nature, you only hear about one side of these events. We never hear about the attacks that were stopped or could have been stopped by backdoors. Many people take that as proof that these events don't happen but as the old saying goes absence of proof is not proof of absence. Without that proof, all we…
> absence of proof is not proof of absence I don't think this applies here. I suppose your point is goverment's exploits might be effective but they keep it low not to expose the fact of their existence. Well, this might very well justify anything from 1984 or any other anti-utopia — "let us do whatever, it is effective and needed, but we won't give any facts or details, because it might compromise our system".
The only difference is that the other side of the debate is already in power. So if the tech community doesn't even want to discuss this issue, guess which side of the issue will win the debate and decide future encryption law.
Re: Microsoft proves backdoor keys are a bad idea
#83Earlier quoted context omitted.
The term "backdoor" derives from the very notion of a door. In the back whatever it is you're trying to secure. I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.
With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…
I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger.
That said, I myself agree with other commenters that your stance "this isn't a backdoor because it requires physical access; if you've given up physical access you're already screwed" is beyond disingenuous. Disregarding a login screen bypass by the same logic would be rightly pilloried. Yes, physical security is the hardest to improve, but that's exactly the carrot Microsoft has used to try and convince the world Secure Boot isn't a pure anti-consumer move.
Re: Microsoft proves backdoor keys are a bad idea
#84What does leaking your private key have to do with backdoor keys? Isn't this like saying that CAs are backdoored because somewhere there exists a private key for those certs?
No private keys were leaked; however a signed policy file, that lets you disable the protections within secureboot was discovered and repurposed. Its not so much a backdoor key, but an overly permissive mechanism within microsofts secureboot implementation that could be used to implement a backdoor within the system. A similar analogy in the CA world would be when the Microsoft Terminal Server Licensing CA (which acc…
Re: Microsoft proves backdoor keys are a bad idea
#85Earlier quoted context omitted.
The term "backdoor" derives from the very notion of a door. In the back whatever it is you're trying to secure. I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.
With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…
Spaghetti to a wall as well.
You're not arguing coherently, effectively, logically, or using terms defined as they're commonly understood.
Re: Microsoft proves backdoor keys are a bad idea
#86Earlier quoted context omitted.
With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…
I'll bite. The original article is from the Register. If you work at Microsoft and read HN I'd expect you have a reasonable idea of their average article quality. I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger. That said, I myself agree with other commenters that your stance "this isn't a backdoor because it…
Re: Microsoft proves backdoor keys are a bad idea
#87Earlier quoted context omitted.
> absence of proof is not proof of absence I don't think this applies here. I suppose your point is goverment's exploits might be effective but they keep it low not to expose the fact of their existence. Well, this might very well justify anything from 1984 or any other anti-utopia — "let us do whatever, it is effective and needed, but we won't give any facts or details, because it might compromise our system".
You are proving my point. Not everything is black and white. Not every slope is slippery. There is room for discussion and compromise. You comparing the people on the other side of the debate to fans of 1984 style totalitarian government gets nothing accomplished just like people on the other side saying you are enabling terrorists gets nothing accomplished. The only difference is that the other side of the debate is…
Re: Microsoft proves backdoor keys are a bad idea
#88Earlier quoted context omitted.
Like the IoT makers who lock their devices by means of clear text passwords hardcoded into the device firmware? Most companies don't go to the extent of having a cryptographically secure key validated by a TPM. At least MS is trying to secure the system.
MS are trying to secure their monopoly. If they wanted to secure the system, key management would be up to the user.
Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?
Re: Microsoft proves backdoor keys are a bad idea
#89Earlier quoted context omitted.
I s there any difference between a test/development backdoor and a FBI backdoor?. If you let backdoors in the system, of course the secret services will demand to have it. In fact, backdoors that were put in place because secret services' pressure, will be suited as developer backdoors as an excuse when found by the mainstream. First they install backdoors in systems, in order for MS or the US gobertment to have comp…
I think you're missing my point (and my poor wording probably didn't help). A backdoor that requires physical access isn't a backdoor. If an attacker has such access, you're already screwed. A backdoor that requires administrative privileges isn't a backdoor. If an attacker has such access, you're already screwed. The so-called dev/test 'backdoor' really isn't a backdoor. It's a 'unlock' tool that's required for anyo…
(I'm not sure if that's what the Register was trying to say, because they're kind of screechy and incoherent at the best of times, but that's how I personally read it.)
Re: Microsoft proves backdoor keys are a bad idea
#90Earlier quoted context omitted.
MS are trying to secure their monopoly. If they wanted to secure the system, key management would be up to the user.
But it's ok if Samsung, Google, Apple or whoever else lock you out of the device? Or at least they're not doing it to protect their monopoly. Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?
No, it is not ok. Kindly point me to the place where I said it is ok. (That said, Google sells phones with unlocked boot loaders, and have similar "Developer Mode" support for Chromebooks. Samsung and Apple to the best of my knowledge do not sell unlocked phones but do sell unlocked laptops).
> Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?
Ah, but they wouldn't have produced millions of these devices if they didn't think they could sell them. The ARM based devices were a test of the waters.
Microsoft requires, on x86, that trust of the MS key be preinstalled and that it be possible to turn off UEFI - but they do not require (e.g.) that there be an ability for the user to remove the MS trust or add new trust. (All of these requirements support their monopoly).
I cannot know, but I suspect Microsoft is playing the long game here, and that at some point after Win7 extended support (4 years from now), they plan to require that UEFI cannot be turned off for a machine to be certified to run Win10 "dominion edition". They've started with restricting kernel drivers in the "anniversary edition". I suspect The ARM UEFI was a test for this.
If I am right, the failure of WindowsRT will not change the course of this long game; hopefully something else will (right now, the emergence of reasonable Chromebooks is the only thing that appears to have the potential to stop it)