Live data from Hacker News

_NSAKEY

en.wikipedia.org

61–70 of 118 posts

Re: _NSAKEY

#61

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

If I was trying to hide my presence, I wouldn't name something after myself. $0.02

It was MS who named it, probably

Re: _NSAKEY

#62
post #6

Does it have anything to do with today's Windows update and this cryptic rumbling ahead of time? https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-...

We will soon see what this Windows update is about - but I seriously doubt that there exists any relationship.

If you mean the relationship between NSA and the vulnerability, then no, there actually is: it was NSA who discovered the vulnerability and it has not been used in the wild (according to NSA themselves; source: https://twitter.com/briankrebs/status/1217082363391377408)

Re: _NSAKEY

#63

Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

This is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other count…

In the case of the FBI claiming they needed Apple's help to retrieve encrypted data from an iPhone, it's reasonable to suspect that it was simply a ploy to pressure Apple into making concessions in the face of public pressure. A third party firm was quick to assist the FBI, but I doubt the technique used to bypass Apple's security on the iPhone was entirely novel. I would guess the firm was surprised the government didn't have enough resources to overcome the obstacle themselves long before anyone else. The San Bernardino shooting was a low stakes case of terrorism that may have been classified as a normal workplace shooting, and the FBI didn't have to make haste nor use all of the tools at their disposal. At the same time, the FBI's request to Apple can be considered legitimate after some hand waving because most of the FBI was probably told that it was technically impossible to crack into an iPhone because the necessary tool is classified and kept in reserve.

Also, I don't think any number of people believing to any extent that a corporation may have been compromised removes an important incentive for that corporation to maintain its integrity. For a security-conscious company, reputation and trust don't go that far so it would be safer to assume that Apple can be or has been compromised maybe even without their knowledge. That company would have to look after its own security and use custom protocols / devices. If it was forced to trust Apple, it would have to find an ingenious way to ensure that was not at all in the interest of Apple to betray them.

Re: _NSAKEY

#64
post #31

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

>20 years on, and nobody has ever found anything signed with this "NSAKEY". Hm, wouldn't Microsoft make a proof by singing something publically with a private key?

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

Re: _NSAKEY

#65

Earlier quoted context omitted.

This is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other count…

Microsoft is listed as a provider in the NSA's Prism program in Powerpoint slides released in the Snowden leak. In fact, the timeline indicates that they were the first on board. https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...

No, they give data for specific accounts being wiretapped to the FBI. The FBI is a participant in the PRISM program.

Re: _NSAKEY

#66

Earlier quoted context omitted.

> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.

Make sure you've also read, understood and recompiled the compiler. And the compiler used to compile the compiler.

Even then, assembly is too high level.

https://m.youtube.com/watch?v=eunYrrcxXfw

And then we get into hardware design...

https://m.youtube.com/watch?v=_eSAF_qT_FY

Re: _NSAKEY

#67
post #45

Earlier quoted context omitted.

As far as I understand you’re the first person to claim that windows update uses this key. Do you have any evidence to back up this claim?

No, I don't have enough insight into how WU verification/certificates work to make such a strong claim in confidence actually. Would be curious to learn why this wouldn't be so, though. Given Microsoft's close relationship in NSA programs in the past (PRISM, Snowden leaks, others), it's not far-fetched to assume they have a key for a root CA or whatever else is needed for such an attack.

Microsoft has no relationship with the NSA in PRISM according to the Snowden leaks. The slides show they handle wiretaps for specific people under court order for the FBI, which we already knew.

Re: _NSAKEY

#68

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

Using an intentionally built in Windows backdoor, it did, yes. Instead they relied on good ol' completely unencrypted traffic flowing across wires they had hooks in.

Re: _NSAKEY

#69

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

It did though, didn't it? Intelligence organisations worldwide execute their operations in total secrecy and have hidden agreements with international counterparts to share information on each others' citizens in a way that bypasses the laws and constitutions of their host nations. Secret plans that circumvent the law is pretty much the definition of conspiracy.

Re: _NSAKEY

#70
post #31

Earlier quoted context omitted.

>20 years on, and nobody has ever found anything signed with this "NSAKEY". Hm, wouldn't Microsoft make a proof by singing something publically with a private key?

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

I think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key.

The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)

Post reply on HN