Live data from Hacker News

Microsoft proves backdoor keys are a bad idea

theregister.co.uk

91–100 of 106 posts

Re: Microsoft proves backdoor keys are a bad idea

#91
post #40
post #2

I genuinely hope this will influence the whole government mandated back door debate for the better but I'm afraid that this will just be forgotten in a matter of minutes. Like Gove said "we've had enough of experts", especially when their educated opinions don't suit us.

If a terrorist attack occurred and it was clear that it could have been prevented if the authorities could have read encrypted information, would that change your opinion of backdoors? If not, why are you criticizing the other side for being just as steadfast in their beliefs as you are in yours? The truth is that no policy is going to be 100% effective so I'm not sure why either side of the debate should overadjust…

Are you of the opinion that all beliefs are above ridicule, or just this one? Because in my opinion the idea of a government controlled key escrow is the most stupid thing I've heard suggested and its proponents are either willfully ignorant or just insane. Recent history is full of major failures on the part of the USG to properly safeguard data of the most sensitive nature, as well as cases where they had collected clear text intel and just failed to connect the dots. So there is nothing to gain and everything to lose; they have enough data, they should work on their analytics before they endeavor to intentionally weaken everybody's security.

Re: Microsoft proves backdoor keys are a bad idea

#92
post #83

Earlier quoted context omitted.

With all due respect, What argument do you think I'm trying to make? I ask this because I'm still rather unclear about the argument that the original article is trying to make . I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Other…

I'll bite. The original article is from the Register. If you work at Microsoft and read HN I'd expect you have a reasonable idea of their average article quality. I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger. That said, I myself agree with other commenters that your stance "this isn't a backdoor because it…

> "...your stance "this isn't a backdoor because it requires physical access; if you've given up physical access you're already screwed" is beyond disingenuous. "

Ok, I'm open to the possibility that my views might be dated on this.

But, to be fair:

1) the 'physical access' rule was an absolute given in training that I've taken. (I'll let you draw your own conclusions since that the training was hosted by Microsoft). I guess I've had it drilled into my head for so long that I didn't even think the assertion would be controversial here.

2)Schneier commented on here (https://www.schneier.com/blog/archives/2009/10/evil_maid_att...) stating: "As soon as you give up physical control of your computer, all bets are off."

Granted, Schneier's comment was in 2009, and it's possible that expectations on security have changed since then, but

3) this stackexchange question (http://security.stackexchange.com/questions/19334/what-can-a...) is a bit more recent. Some quotes:

"Physical security is a critical (arguably the most critical) part of IT Security. At the end of the day, almost anything can be overridden with local access to the hardware."

"If a "hacker" with any real experience or skill has physical access to a PC, I would just throw away the hard drive and start fresh."

4) even some other comments in this thread (https://news.ycombinator.com/item?id=12264137) don't paint my notion as disingenuous as you might.

Again, I'm not a security expert, but do you think I could be forgiven for making such an assertion?

Re: Microsoft proves backdoor keys are a bad idea

#93
post #74

Earlier quoted context omitted.

I think you're missing my point (and my poor wording probably didn't help). A backdoor that requires physical access isn't a backdoor. If an attacker has such access, you're already screwed. A backdoor that requires administrative privileges isn't a backdoor. If an attacker has such access, you're already screwed. The so-called dev/test 'backdoor' really isn't a backdoor. It's a 'unlock' tool that's required for anyo…

It's like saying the admin/root account is a backdoor because it allows you to do anything to the system.

> It's like saying the admin/root account is a backdoor because it allows you to do anything to the system.

It's more like saying having a admin/root account and a post-it with a password hint is a backdoor (which is also wrong, of course).

Re: Microsoft proves backdoor keys are a bad idea

#94
post #83

Earlier quoted context omitted.

I'll bite. The original article is from the Register. If you work at Microsoft and read HN I'd expect you have a reasonable idea of their average article quality. I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger. That said, I myself agree with other commenters that your stance "this isn't a backdoor because it…

> "...your stance "this isn't a backdoor because it requires physical access; if you've given up physical access you're already screwed" is beyond disingenuous. " Ok, I'm open to the possibility that my views might be dated on this. But, to be fair: 1) the 'physical access' rule was an absolute given in training that I've taken. (I'll let you draw your own conclusions since that the training was hosted by Microsoft).…

Not to split hairs, but there's physical access and there's physical access. I've got a Windows RT device up there in my livingroom, but as much as I can pick it up, heft it at the wall, or poke my pinkie into its USB port, I'm not the kind of dude who can crack it open and steal an encryption key that's being transmitted across a bus on the third layer down of its motherboard. I can, however, log in as administrator, download a CMD script (or whatever), and run it. Which one of those is physical access? I guarantee that if you asked one of those greybeards who told you about physical access, they'd back up to the stealing-a-key-from-a-bus scenario, which is out of bounds of reality for most of us. The exploit at hand is not, and I think that's the difference.

> Again, I'm not a security expert, but do you think I could be forgiven for making such an assertion?

Yeah, I forgive you.

Re: Microsoft proves backdoor keys are a bad idea

#95
post #48

> The Register understands that this debug-mode policy was accidentally shipped on retail devices, and discovered by curious minds including Slip and MY123. > The policy was effectively inert and deactivated on these products but present nonetheless. Whenever I read things like this, I always envision that it's not a cock-up at all, but instead a deliberate effort by righteous free software-minded people who happen t…

a deliberate effort by righteous free software-minded people who happen to work at Microsoft Or maybe a deliberate effort by developers who are paid by a three letter agency to sneak in a backdoor that looks like an accidental bug. In this case you might be right, but the last time a similar issue was widely circulated (Heartbleed in OpenSSL), it also looked like an accident (or rather gross negligence), but its effe…

> Or maybe a deliberate effort by developers who are paid by a three letter agency to sneak in a backdoor that looks like an accidental bug.

Why would a three-letter agency bother to do that, when they could just as well get their malware EFI module signed by MS, and thus pass the secure-boot requirement?

That way they wont risk exposing the existence of a backdoor on every single Windows-copy deployed worldwide.

I honestly don't see the value in it for them.

Re: Microsoft proves backdoor keys are a bad idea

#96

I think people should be able to sue companies that do this. They surely did not advertise it as "secure unless we lose the key". Having a backdoor in the first place could be counted as negligent (should be counted as outright fraud).

> I think people should be able to sue companies that do this. They surely did not advertise it as "secure unless we lose the key".

I think you misunderstand what this is. This is not a remote backdoor, which can be used by MS/NSA to hack your machine.

Windows RT devices comes with a bootloader locked to only allow UEFI secure-boot signed boot media. Effectively that means Windows RT only. No Linux, FreeBSD or other free OSen for you.

This is a hack, which requires you to have full admin-access on the device, which uses Microsoft's own UEFI mechanisms (policies and what not), to allow booting other non-signed media as well.

Effectively this is a bootloader unlocking. With this hack in place, you can now boot Linux. Or run malware. Anything goes. It's the same as being able to disable secure-boot.

And would you honestly sue HTC or whoever if you found out that the bootloader on your phone could be unlocked, to allow the installation of third party firmware?

Surely you would only see that as a positive thing? Or am I missing something?

Re: Microsoft proves backdoor keys are a bad idea

#97

Earlier quoted context omitted.

No. What Apple had was the option of updating the phone with a compromised (or compromisable) security implementation. Apple refused to do that. The FBI did find an exploit (which AFAIR they've refused to disclose, in controvention of previous policy if not regulation and/or law), but that represents a flaw in implementation which Apple can then remedy. http://mashable.com/2016/02/16/apple-hack-san-bernardino-pho...…

If Apple can take the phone and unlock it with the tools and knowledge at their disposal, then they have a backdoor for it. The distinction that you're drawing is meaningless.

A backdoor is typically reserved for solutions that bypass the existing security. As I understood it, the only thing Apple could do was provide a firmware without rate limiting. This would have allowed the FBI to perform an exhaustive search for the key. We already know that brute-forcing a key is always possible, that's not a new way to bypass security.

Re: Microsoft proves backdoor keys are a bad idea

#98
post #5

(disclaimer, MS employee, non-security expert here). I've read through the article, here, and in other places, and I'm seeing sentiment that this is a big fuck up on Microsoft's part. I might be completely misunderstanding, but I just don't see it. In order to use the backdoor, you've got to flash firmware, so, you've got to have physical access to the device. If an attacker has physical access to your device, you're…

I think the worst part is that the trusted boot environment can no longer be trusted.

Re: Microsoft proves backdoor keys are a bad idea

#99

I think people should be able to sue companies that do this. They surely did not advertise it as "secure unless we lose the key". Having a backdoor in the first place could be counted as negligent (should be counted as outright fraud).

> I think people should be able to sue companies that do this. They surely did not advertise it as "secure unless we lose the key". I think you misunderstand what this is. This is not a remote backdoor, which can be used by MS/NSA to hack your machine. Windows RT devices comes with a bootloader locked to only allow UEFI secure-boot signed boot media. Effectively that means Windows RT only. No Linux, FreeBSD or other…

I got what this is, my point is, that it is not what they advertised. Maybe I should have made this more clear.

I myself would be thankful to be able to install Linux if I had a device like that. Nevertheless some (enterprise) users would maybe like it otherwise and were screwed by Microsoft claiming something is secured, when they in fact knew, that it was not.

A scenario I can think of is when the machine is not owned by the one using it and the owner wants to sandbox the user as much as possible. In this in the view of the owner it really is a backdoor.

I would love to see companies getting punished for things like that. This case does not seem severe, still, what I want is that you are accountable for stuff you say. You cannot have a backdoor - being remote or not remote - if you say that the thing is secure. You knew it was not, you have committed fraud.

Re: Microsoft proves backdoor keys are a bad idea

#100

Earlier quoted context omitted.

> I think people should be able to sue companies that do this. They surely did not advertise it as "secure unless we lose the key". I think you misunderstand what this is. This is not a remote backdoor, which can be used by MS/NSA to hack your machine. Windows RT devices comes with a bootloader locked to only allow UEFI secure-boot signed boot media. Effectively that means Windows RT only. No Linux, FreeBSD or other…

I got what this is, my point is, that it is not what they advertised. Maybe I should have made this more clear. I myself would be thankful to be able to install Linux if I had a device like that. Nevertheless some (enterprise) users would maybe like it otherwise and were screwed by Microsoft claiming something is secured, when they in fact knew, that it was not. A scenario I can think of is when the machine is not ow…

Seeing as this bypass requires admin rights to execute in the first place, a sandboxed user should by all accounts remain sandboxed anyway.

But fair enough point about different use cases.

Post reply on HN