It's only fitting that for recurring posts we have recurring comments. Oh wow, there's an `nsagate` subdomain on `apple.com`! https://www.robtex.com/dns-lookup/nsagate.apple.com
Could be a nameserver.
_NSAKEY
41–50 of 118 posts
Re: _NSAKEY
#42Earlier quoted context omitted.
Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.
Well, I would think so as well, but we have at least some anecdata (N=1) in the other direction [0]: > In doing this I discovered that the NSA public key had an organizational name of "MiniTruth", and a common name of "Big Brother". Specifically what I saw in my debugger late one night, which was spooky for a short moment was: O=MiniTruth CN=Big Brother [0]: http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html
Re: _NSAKEY
#43"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws" Occam's Razor.
In that case, why was it the backup key that was named after the NSA, and not the key that was actually used for this purpose in practice?
Re: _NSAKEY
#44Earlier quoted context omitted.
Do you know how this NSAKEY backdoor is supposed to work? I don’t, nor does anyone else apparently. This should not be a difficult question to answer.
Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.
Re: _NSAKEY
#45Earlier quoted context omitted.
Is it not by creating whatever software you want and signing it as Microsoft software. You could essentially replace core windows components and the OS would run them without warning.
Hijack Windows Update on the infrastructure level and you're good to go, basically. All it takes is compromising the ISP, the DNS provider or the local network admin.
Do you have any evidence to back up this claim?
Re: _NSAKEY
#46If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.
> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.
> Ken describes how he injected a virus into a compiler. Not only did his compiler know it was compiling the login function and inject a backdoor, but it also knew when it was compiling itself and injected the backdoor generator into the compiler it was creating. The source code for the compiler thereafter contains no evidence of either virus.
Re: _NSAKEY
#47If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.
> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.
Re: _NSAKEY
#48Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?
Re: _NSAKEY
#49Earlier quoted context omitted.
Hijack Windows Update on the infrastructure level and you're good to go, basically. All it takes is compromising the ISP, the DNS provider or the local network admin.
As far as I understand you’re the first person to claim that windows update uses this key. Do you have any evidence to back up this claim?
Would be curious to learn why this wouldn't be so, though.
Given Microsoft's close relationship in NSA programs in the past (PRISM, Snowden leaks, others), it's not far-fetched to assume they have a key for a root CA or whatever else is needed for such an attack.
Re: _NSAKEY
#50Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.