Live data from Hacker News

_NSAKEY

en.wikipedia.org

1–10 of 118 posts

Re: _NSAKEY

#2
20 years on, and nobody has ever found anything signed with this "NSAKEY".

That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct.

I doubt anyone will ever know.

Re: _NSAKEY

#3
This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

Re: _NSAKEY

#5
If it looks and sounds like a duck then its probably a duck.

I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Re: _NSAKEY

#6

Does it have anything to do with today's Windows update and this cryptic rumbling ahead of time? https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-...

We will soon see what this Windows update is about - but I seriously doubt that there exists any relationship.

Re: _NSAKEY

#7
post #3

This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

How so? I don't think there's a controversy around the semantics of this key. What is not known is who has the private key and what they sign with it.

Re: _NSAKEY

#8
post #7
post #3

This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

How so? I don't think there's a controversy around the semantics of this key. What is not known is who has the private key and what they sign with it.

>Microsoft claimed the third key was only in beta builds of Windows 2000 and that its purpose was for signing Cryptographic Service Providers.

So it’s not controversial that this was utterly unexploitable without pre-existing local access?

Nobody has ever described how this purported backdoor would be used.

Re: _NSAKEY

#9
post #3

This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?

Re: _NSAKEY

#10
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it.

As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

Post reply on HN