Live data from Hacker News

_NSAKEY

en.wikipedia.org

21–30 of 118 posts

Re: _NSAKEY

#21
post #10
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

Well, I would think so as well, but we have at least some anecdata (N=1) in the other direction [0]:

> In doing this I discovered that the NSA public key had an organizational name of "MiniTruth", and a common name of "Big Brother". Specifically what I saw in my debugger late one night, which was spooky for a short moment was:

O=MiniTruth CN=Big Brother

[0]: http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html

Re: _NSAKEY

#22

Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

This is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other count…

Microsoft is listed as a provider in the NSA's Prism program in Powerpoint slides released in the Snowden leak. In fact, the timeline indicates that they were the first on board.

https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...

Re: _NSAKEY

#23
"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws"

Occam's Razor.

Re: _NSAKEY

#24
I remember that part of the Windows 2000 source code leaked years ago.

I'm presuming people looked at it for dubious keys.

Re: _NSAKEY

#25
post #10
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

What if it is a case of malicious compliance like Lotus Notes' backdoor someone else already has mentioned (the classic O=MiniTruth CN=Big Brother)?

Re: _NSAKEY

#26
post #12
post #9

Earlier quoted context omitted.

How do you mean? The presence of a public key doesn't tell us what has been encrypted with it or if the private key has been shared with anyone. How will a debugger tell us any of that?

But if it's really the key to a backdoor, it has to be used somewhere in the code. E.g., some part of Windows had to check something signed with the key or encrypt something with it.

Windows used _NSAKEY (and another key) to check that Cryptographic Service Providers are signed. Otherwise it wouldn't allow them to be used. This was explained in the article.

Re: _NSAKEY

#27
post #13

It's only fitting that for recurring posts we have recurring comments. Oh wow, there's an `nsagate` subdomain on `apple.com`! https://www.robtex.com/dns-lookup/nsagate.apple.com

Could be a nameserver.

Re: _NSAKEY

#28

Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

This is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other count…

> if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones

The FBI is not the NSA.

Re: _NSAKEY

#29
post #23

"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws" Occam's Razor.

I'm trying to understand what it means - does it mean your code have to have a symbol called `_NSAKEY`? Or how does it affect compliance?

Re: _NSAKEY

#30
post #23

"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws" Occam's Razor.

Occam's Glomar
Post reply on HN