Live data from Hacker News

_NSAKEY

en.wikipedia.org

81–90 of 118 posts

Re: _NSAKEY

#81

Earlier quoted context omitted.

> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.

Make sure you've also read, understood and recompiled the compiler. And the compiler used to compile the compiler.

That reminds me of an answer on Quora where a compiler was infected and would insert white supremacy messages into the compiled program. And if you tried to recompile the compiler, it would inject its code into the new compiler[0].

[0]: http://www.quora.com/What-is-a-coders-worst-nightmare/answer...

Re: _NSAKEY

#82
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

> everything you don't have source to is compromised. Everything for which you haven't read, fully understood, and compiled from the source can be compromised. Just because there's source for something somewhere doesn't mean the binary you downloaded is secure.

Because open source projects like OpenSSL never have bugs sitting wide open for years. cough Heartbleed

Re: _NSAKEY

#83

Everyone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

They weren't breaking your crypto to snoop on you though. Turns out the public information about you is enough to generate a pretty reliable profile of a person.

Re: _NSAKEY

#84
post #73

Earlier quoted context omitted.

Look at Snowden’s leaks and RDRAND.

Nothing in the Snowden leaks suggests that RDRAND is backdoored.

Nothing in the Snowden leaks PROVES the RDRAND was backdoored.

Bullrun [0] definitely suggests it..

[0] https://en.wikipedia.org/wiki/Bullrun_(decryption_program)

Re: _NSAKEY

#85
post #62
post #6

Earlier quoted context omitted.

We will soon see what this Windows update is about - but I seriously doubt that there exists any relationship.

If you mean the relationship between NSA and the vulnerability, then no, there actually is: it was NSA who discovered the vulnerability and it has not been used in the wild (according to NSA themselves; source: https://twitter.com/briankrebs/status/1217082363391377408 )

"we lost the backdoor key and its in the wild" constitutes the NSA "discovering" and "informing" MS.

Re: _NSAKEY

#86
post #8

Earlier quoted context omitted.

>Microsoft claimed the third key was only in beta builds of Windows 2000 and that its purpose was for signing Cryptographic Service Providers. So it’s not controversial that this was utterly unexploitable without pre-existing local access? Nobody has ever described how this purported backdoor would be used.

That's a seperate key, which doesn't seem to have an interesting name, not _NSAKEY: > In addition, Dr. Nicko van Someren found a third key in Windows 2000, which he doubted had a legitimate purpose, and declared that "It looks more fishy".

https://en.wikipedia.org/wiki/Nicko_van_Someren

Excerpt:

"Van Someren has published numerous papers in the field of computer security. In 1998 he co-authored a paper[13] with Adi Shamir introducing the concept of key finding attacks. A statistical key finding attack was used by van Someren to locate the signature verification keys used by Microsoft to validate the signatures on MS-CAPI plug-ins. One of these key was later discovered to be referred to as the NSAKEY by Microsoft, sparking some controversy.[14]"

https://en.wikipedia.org/wiki/Microsoft_CryptoAPI

Excerpt:

"The Microsoft Windows platform specific Cryptographic Application Programming Interface (also known variously as CryptoAPI, Microsoft Cryptography API, MS-CAPI or simply CAPI) is an application programming interface included with Microsoft Windows operating systems that provides services to enable developers to secure Windows-based applications using cryptography. It is a set of dynamically linked libraries that provides an abstraction layer which isolates programmers from the code used to encrypt the data."

===End Excerpt===

Observation: MS-CAPI -- would seem to be, prima facie, similar to Linux's OpenSSL...

Re: _NSAKEY

#87
post #70

Earlier quoted context omitted.

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

I think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)

> it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key.

It would also be trivial for Microsoft to call up the NSA and say "they're ON TO US and it looks bad to our customers, can you please sign this message?" That is, the test you suggest proves nothing-- you can't prove that only you hold a private key.

Re: _NSAKEY

#88
post #73

Earlier quoted context omitted.

Look at Snowden’s leaks and RDRAND.

Nothing in the Snowden leaks suggests that RDRAND is backdoored.

He's probably thinking of either Dual EC DRBG, or the HTTP header they came up with to leak enough data from it to compromise it.

Re: _NSAKEY

#89

Earlier quoted context omitted.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

They weren't breaking your crypto to snoop on you though. Turns out the public information about you is enough to generate a pretty reliable profile of a person.

PRISM utilized entirely public info? Information regarding every phone call you've ever made, including time, recipient, length, and location are public?

Re: _NSAKEY

#90
post #36
post #5

If it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.

Nadella has just said that he would support a "don't-call-it-a-backdoor" backdoor key for the U.S. (and I assume other) government(s): https://www.theverge.com/2020/1/13/21064267/microsoft-encryp... Also, there are at least several other instances that make Microsoft highly suspicious in regards to this stuff, starting with: - how they bought Skype not long after the NSA was promising billions of dollars (in governme…

Where do you believe MS is storing all this tracking data you believe they are taking from every Windows 10 machine on the planet?

Doesn't this conspiracy theory stretch belief a great deal?

Post reply on HN