Live data from Hacker News

_NSAKEY

en.wikipedia.org

31–40 of 118 posts

Re: _NSAKEY

#31

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

>20 years on, and nobody has ever found anything signed with this "NSAKEY".

Hm, wouldn't Microsoft make a proof by singing something publically with a private key?

Re: _NSAKEY

#32
post #11

Earlier quoted context omitted.

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.

It was for crypto specifically, to enforce export controls.

Re: _NSAKEY

#33
post #11

Earlier quoted context omitted.

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.

Us companies are also not allowed to export software with “pluggable crypto modules”.

Re: _NSAKEY

#34
post #10
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

I'd wager that there's a high probability that an arbitrary engineer tasked with implementing things like this either doesn't care or is antagonistic, thereby calling the duck a duck.

Also, the name was never supposed to be known - it was due to early releases mistakenly having debug symbols included.

Re: _NSAKEY

#35
post #23

"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws" Occam's Razor.

In that case, why was it the backup key that was named after the NSA, and not the key that was actually used for this purpose in practice?

Re: _NSAKEY

#36
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Nadella has just said that he would support a "don't-call-it-a-backdoor" backdoor key for the U.S. (and I assume other) government(s):

https://www.theverge.com/2020/1/13/21064267/microsoft-encryp...

Also, there are at least several other instances that make Microsoft highly suspicious in regards to this stuff, starting with:

- how they bought Skype not long after the NSA was promising billions of dollars (in government contracts most likely) to the company that would bypass Skype's encryption somehow

- changing Skype's architecture to be intercept-able

- Skype entering the PRISM program the moment Microsoft bought it

- some other suspicious "bugs" and design choices in regards to how Bitlocker works, including storing the encryption keys on its servers or defaulting to break-able OEM encryption. Plus the fact that you never do hear about law enforcement being thwarted by laptop encryption

- silently adding root certificates in Windows with no official documentation, some for some oppressive regimes, other for the U.S. government

- Not to mention that the first thought that came to my mind after hearing about all the hidden tracking stuff built into Windows 10 was that Windows 10 must have been designed based on a FBI/NSA wishlist.

If you've ever done anything "wrong" on your Windows 10 machine, the U.S. government will know about it, because Microsoft will know about it. At least Microsoft revealed to us that half of the government's orders to the company were secret and came with gag orders -- too bad they never really fought the government on it and ended-up supporting it with the Cloud Act.

There are probably others I missed myself or forgot about. Nadella must think of us all as idiots if he thinks we'll buy the idea that a specially-made encryption key for various governments doesn't equal a backdoor.

Re: _NSAKEY

#37
Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

Re: _NSAKEY

#38
post #11

Earlier quoted context omitted.

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.

[deleted]

Re: _NSAKEY

#39
post #11

Earlier quoted context omitted.

Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.

Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.

Hijack Windows Update on the infrastructure level and you're good to go, basically.

All it takes is compromising the ISP, the DNS provider or the local network admin.

Re: _NSAKEY

#40
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

> everything you don't have source to is compromised.

Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.

Post reply on HN