Live data from Hacker News

_NSAKEY

en.wikipedia.org

11–20 of 118 posts

Re: _NSAKEY

#11
post #9
post #3

This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Re: _NSAKEY

#12
post #9
post #3

This seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!

How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?

But if it's really the key to a backdoor, it has to be used somewhere in the code. E.g., some part of Windows had to check something signed with the key or encrypt something with it.

Re: _NSAKEY

#14
Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

Re: _NSAKEY

#15

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

They probably decided to rename the variable to something unfamiliar and legit sounding like _winsysdg or _realtek2100m

Re: _NSAKEY

#16
post #10
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

Conspiracy theories tend to hinge on the idea that the conspirators are simultaneously 5-dimensional chess playing lizard people from the future and, at the end of the day, dumb as a rock.

Re: _NSAKEY

#17
post #11
post #9

Earlier quoted context omitted.

How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.

Re: _NSAKEY

#18
post #15

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

They probably decided to rename the variable to something unfamiliar and legit sounding like _winsysdg or _realtek2100m

[deleted]

Re: _NSAKEY

#19

Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

This is sort of circular, or tautological: “I believe in it because it’s so believable “

FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones.

Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other countries.

In any case, my usual argument about cynicism applies: spreading such theories becomes self-fulfilling, because why should MS work for the NSA/every politician take bribes/every cook spit in your food, if that’s what the people believe anyway, no matter what you actually do?

Re: _NSAKEY

#20
post #8
post #7

Earlier quoted context omitted.

How so? I don't think there's a controversy around the semantics of this key. What is not known is who has the private key and what they sign with it.

>Microsoft claimed the third key was only in beta builds of Windows 2000 and that its purpose was for signing Cryptographic Service Providers. So it’s not controversial that this was utterly unexploitable without pre-existing local access? Nobody has ever described how this purported backdoor would be used.

That's a seperate key, which doesn't seem to have an interesting name, not _NSAKEY:

> In addition, Dr. Nicko van Someren found a third key in Windows 2000, which he doubted had a legitimate purpose, and declared that "It looks more fishy".

Post reply on HN