This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!
How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?
_NSAKEY
11–20 of 118 posts
Re: _NSAKEY
#12This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!
How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?
Re: _NSAKEY
#13Oh wow, there's an `nsagate` subdomain on `apple.com`! https://www.robtex.com/dns-lookup/nsagate.apple.com
Re: _NSAKEY
#14Re: _NSAKEY
#1520 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.
Re: _NSAKEY
#16If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.
Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.
Re: _NSAKEY
#17Earlier quoted context omitted.
How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?
Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.
Re: _NSAKEY
#1820 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.
They probably decided to rename the variable to something unfamiliar and legit sounding like _winsysdg or _realtek2100m
Re: _NSAKEY
#19Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?
FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones.
Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other countries.
In any case, my usual argument about cynicism applies: spreading such theories becomes self-fulfilling, because why should MS work for the NSA/every politician take bribes/every cook spit in your food, if that’s what the people believe anyway, no matter what you actually do?
Re: _NSAKEY
#20Earlier quoted context omitted.
How so? I don't think there's a controversy around the semantics of this key. What is not known is who has the private key and what they sign with it.
>Microsoft claimed the third key was only in beta builds of Windows 2000 and that its purpose was for signing Cryptographic Service Providers. So it’s not controversial that this was utterly unexploitable without pre-existing local access? Nobody has ever described how this purported backdoor would be used.
> In addition, Dr. Nicko van Someren found a third key in Windows 2000, which he doubted had a legitimate purpose, and declared that "It looks more fishy".