Live data from Hacker News

_NSAKEY

en.wikipedia.org

71–80 of 118 posts

Re: _NSAKEY

#71

Earlier quoted context omitted.

This is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other count…

Microsoft is listed as a provider in the NSA's Prism program in Powerpoint slides released in the Snowden leak. In fact, the timeline indicates that they were the first on board. https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...

[deleted]

Re: _NSAKEY

#72

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

Ah the old conspiracy conspiracy.

Re: _NSAKEY

#73

Even if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?

Look at Snowden’s leaks and RDRAND.

Nothing in the Snowden leaks suggests that RDRAND is backdoored.

Re: _NSAKEY

#74
post #69

Earlier quoted context omitted.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

It did though, didn't it? Intelligence organisations worldwide execute their operations in total secrecy and have hidden agreements with international counterparts to share information on each others' citizens in a way that bypasses the laws and constitutions of their host nations. Secret plans that circumvent the law is pretty much the definition of conspiracy.

Just because they didn't need to 'circumvent the law' doesn't mean what they did was any less than subversive. Thanks to secret courts the law is whatever they want it to be.

Re: _NSAKEY

#75
post #70

Earlier quoted context omitted.

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

I think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)

Well I don't know if that would necessarily prove anything, since in this scenario, microsoft and the nsa are working closely enough together to modify one of their drivers. In that case, couldn't the point of contact at microsoft simply send the message to the nsa to have it signed, and then show it as proof that the key is owned by microsoft?

Re: _NSAKEY

#76

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

If I was trying to hide my presence, I wouldn't name something after myself. $0.02

Maybe that was the incompetence you guys are talking about.

Re: _NSAKEY

#77
post #46

Earlier quoted context omitted.

> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.

Relevant... [1] > Ken describes how he injected a virus into a compiler. Not only did his compiler know it was compiling the login function and inject a backdoor, but it also knew when it was compiling itself and injected the backdoor generator into the compiler it was creating. The source code for the compiler thereafter contains no evidence of either virus. [1] https://wiki.c2.com/?TheKenThompsonHack

This has always impressed me, I'd love to peek the code and try to read it but I highly doubt I'd be proficient enough to understand it.

Re: _NSAKEY

#78
Well, it does seem remarkable that you never hear the DOJ or Attorney General complaining loudly about how MSFT refused to decrypt something for them.

Re: _NSAKEY

#79
post #74
post #69

Earlier quoted context omitted.

It did though, didn't it? Intelligence organisations worldwide execute their operations in total secrecy and have hidden agreements with international counterparts to share information on each others' citizens in a way that bypasses the laws and constitutions of their host nations. Secret plans that circumvent the law is pretty much the definition of conspiracy.

Just because they didn't need to 'circumvent the law' doesn't mean what they did was any less than subversive. Thanks to secret courts the law is whatever they want it to be.

[deleted]
Post reply on HN