Live data from Hacker News

Microsoft proves backdoor keys are a bad idea

theregister.co.uk

81–90 of 106 posts

Re: Microsoft proves backdoor keys are a bad idea

#81
post #52

Earlier quoted context omitted.

I'm speculating here, but surely by this argument Apple has a backdoor to unlock the phone if it physically has it.

No. What Apple had was the option of updating the phone with a compromised (or compromisable) security implementation. Apple refused to do that. The FBI did find an exploit (which AFAIR they've refused to disclose, in controvention of previous policy if not regulation and/or law), but that represents a flaw in implementation which Apple can then remedy. http://mashable.com/2016/02/16/apple-hack-san-bernardino-pho...…

If Apple can take the phone and unlock it with the tools and knowledge at their disposal, then they have a backdoor for it. The distinction that you're drawing is meaningless.

Re: Microsoft proves backdoor keys are a bad idea

#82
post #72

Earlier quoted context omitted.

>I will base my criticism on actual events such as this one instead of hypotheticals. The problem is that due to its nature, you only hear about one side of these events. We never hear about the attacks that were stopped or could have been stopped by backdoors. Many people take that as proof that these events don't happen but as the old saying goes absence of proof is not proof of absence. Without that proof, all we…

> absence of proof is not proof of absence I don't think this applies here. I suppose your point is goverment's exploits might be effective but they keep it low not to expose the fact of their existence. Well, this might very well justify anything from 1984 or any other anti-utopia — "let us do whatever, it is effective and needed, but we won't give any facts or details, because it might compromise our system".

You are proving my point. Not everything is black and white. Not every slope is slippery. There is room for discussion and compromise. You comparing the people on the other side of the debate to fans of 1984 style totalitarian government gets nothing accomplished just like people on the other side saying you are enabling terrorists gets nothing accomplished.

The only difference is that the other side of the debate is already in power. So if the tech community doesn't even want to discuss this issue, guess which side of the issue will win the debate and decide future encryption law.

Re: Microsoft proves backdoor keys are a bad idea

#83

Earlier quoted context omitted.

The term "backdoor" derives from the very notion of a door. In the back whatever it is you're trying to secure. I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.

With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…

I'll bite. The original article is from the Register. If you work at Microsoft and read HN I'd expect you have a reasonable idea of their average article quality.

I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger.

That said, I myself agree with other commenters that your stance "this isn't a backdoor because it requires physical access; if you've given up physical access you're already screwed" is beyond disingenuous. Disregarding a login screen bypass by the same logic would be rightly pilloried. Yes, physical security is the hardest to improve, but that's exactly the carrot Microsoft has used to try and convince the world Secure Boot isn't a pure anti-consumer move.

Re: Microsoft proves backdoor keys are a bad idea

#84

What does leaking your private key have to do with backdoor keys? Isn't this like saying that CAs are backdoored because somewhere there exists a private key for those certs?

No private keys were leaked; however a signed policy file, that lets you disable the protections within secureboot was discovered and repurposed. Its not so much a backdoor key, but an overly permissive mechanism within microsofts secureboot implementation that could be used to implement a backdoor within the system. A similar analogy in the CA world would be when the Microsoft Terminal Server Licensing CA (which acc…

Yeah, I see now, thanks to the other source. The Register's misuse of "key" followed by excessive drivel in that article had me navigating away with the wrong impression before I could make the connection.

Re: Microsoft proves backdoor keys are a bad idea

#85

Earlier quoted context omitted.

The term "backdoor" derives from the very notion of a door. In the back whatever it is you're trying to secure. I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.

With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…

Deflecting all possible arrows, comes to mind.

Spaghetti to a wall as well.

You're not arguing coherently, effectively, logically, or using terms defined as they're commonly understood.

Re: Microsoft proves backdoor keys are a bad idea

#86
post #83

Earlier quoted context omitted.

With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…

I'll bite. The original article is from the Register. If you work at Microsoft and read HN I'd expect you have a reasonable idea of their average article quality. I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger. That said, I myself agree with other commenters that your stance "this isn't a backdoor because it…

The "backdoor" isn't the package that got leaked, it's the private key that signed the package. Without the key, the deployed packages wouldn't be serviceable in case a real exploit was found. Without a serviceability plan, they couldn't have released Secure Boot. So the question isn't whether there was a back door - there had to be a back door - it's whether Secure Boot is a legitimate thing to have.

Re: Microsoft proves backdoor keys are a bad idea

#87
post #82

Earlier quoted context omitted.

> absence of proof is not proof of absence I don't think this applies here. I suppose your point is goverment's exploits might be effective but they keep it low not to expose the fact of their existence. Well, this might very well justify anything from 1984 or any other anti-utopia — "let us do whatever, it is effective and needed, but we won't give any facts or details, because it might compromise our system".

You are proving my point. Not everything is black and white. Not every slope is slippery. There is room for discussion and compromise. You comparing the people on the other side of the debate to fans of 1984 style totalitarian government gets nothing accomplished just like people on the other side saying you are enabling terrorists gets nothing accomplished. The only difference is that the other side of the debate is…

Writing the law is easy. Enforcing it, on the other hand ...

Re: Microsoft proves backdoor keys are a bad idea

#88
post #55

Earlier quoted context omitted.

Like the IoT makers who lock their devices by means of clear text passwords hardcoded into the device firmware? Most companies don't go to the extent of having a cryptographically secure key validated by a TPM. At least MS is trying to secure the system.

MS are trying to secure their monopoly. If they wanted to secure the system, key management would be up to the user.

But it's ok if Samsung, Google, Apple or whoever else lock you out of the device? Or at least they're not doing it to protect their monopoly.

Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?

Re: Microsoft proves backdoor keys are a bad idea

#89
post #29

Earlier quoted context omitted.

I s there any difference between a test/development backdoor and a FBI backdoor?. If you let backdoors in the system, of course the secret services will demand to have it. In fact, backdoors that were put in place because secret services' pressure, will be suited as developer backdoors as an excuse when found by the mainstream. First they install backdoors in systems, in order for MS or the US gobertment to have comp…

I think you're missing my point (and my poor wording probably didn't help). A backdoor that requires physical access isn't a backdoor. If an attacker has such access, you're already screwed. A backdoor that requires administrative privileges isn't a backdoor. If an attacker has such access, you're already screwed. The so-called dev/test 'backdoor' really isn't a backdoor. It's a 'unlock' tool that's required for anyo…

Installing an OS when Microsoft doesn't want you to is the exploit. The legitimate user is the "attacker," Microsoft (or their policy) is the "target."

(I'm not sure if that's what the Register was trying to say, because they're kind of screechy and incoherent at the best of times, but that's how I personally read it.)

Re: Microsoft proves backdoor keys are a bad idea

#90
post #55

Earlier quoted context omitted.

MS are trying to secure their monopoly. If they wanted to secure the system, key management would be up to the user.

But it's ok if Samsung, Google, Apple or whoever else lock you out of the device? Or at least they're not doing it to protect their monopoly. Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?

> But it's ok if Samsung, Google, Apple or whoever else lock you out of the device? Or at least they're not doing it to protect their monopoly.

No, it is not ok. Kindly point me to the place where I said it is ok. (That said, Google sells phones with unlocked boot loaders, and have similar "Developer Mode" support for Chromebooks. Samsung and Apple to the best of my knowledge do not sell unlocked phones but do sell unlocked laptops).

> Also, we're talking about Microsoft ARM based devices so what monopoly are they trying to protect? The monopoly on landfill space they used to dump all the Windows RT devices they failed to sell?

Ah, but they wouldn't have produced millions of these devices if they didn't think they could sell them. The ARM based devices were a test of the waters.

Microsoft requires, on x86, that trust of the MS key be preinstalled and that it be possible to turn off UEFI - but they do not require (e.g.) that there be an ability for the user to remove the MS trust or add new trust. (All of these requirements support their monopoly).

I cannot know, but I suspect Microsoft is playing the long game here, and that at some point after Win7 extended support (4 years from now), they plan to require that UEFI cannot be turned off for a machine to be certified to run Win10 "dominion edition". They've started with restricting kernel drivers in the "anniversary edition". I suspect The ARM UEFI was a test for this.

If I am right, the failure of WindowsRT will not change the course of this long game; hopefully something else will (right now, the emergence of reasonable Chromebooks is the only thing that appears to have the potential to stop it)

Post reply on HN