Earlier quoted context omitted.
"Why does the NSA have full access to your servers?" Because they ordered him to give it, and he elected not to go to jail.
He means "how". Open-source protects against software backdoors (though obviously not against key-sharing et alii)
Microsoft helped the NSA bypass encryption, new Snowden leak reveals
111–118 of 118 posts
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#112Yet another reason to stick to open source.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#113This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.
Edit : the site seems to have some difficulties, here's the google cache http://webcache.googleusercontent.com/search?q=cache:JZEtYXR... The description of the decryption suite is in the module tab.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#114going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…
>could there be a case where the parties in a conversation are legitimate suspects? It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day). We shouldn't accept the government listening in on digital communication just because it's easy.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#115Earlier quoted context omitted.
>could there be a case where the parties in a conversation are legitimate suspects? It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day). We shouldn't accept the government listening in on digital communication just because it's easy.
are you saying Microsoft helped to wiretap email?
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#116Earlier quoted context omitted.
are you saying Microsoft helped to wiretap email?
That's what you got from what I said? I'm saying that people think because communication is digital, and digital is easy to listen in on that we should be listening in on it. I say fuck that. Today it would be easy to listen in on anyone anywhere with a little hardware. Easy is not a justification for doing something.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#117Earlier quoted context omitted.
Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…
Take a look at Alex Ionescu's "Ninja's and Harry Potter" talk from NoSuchCon this year [1]. He specifically mentions he could access the FileVault key of a machine by having physical access, and discovered two secret keys (KPPW and KPST) one of which is enabled when the input buffer is "SpecialisRevelio" [2]. It's a very interesting deck to read through. [1] http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_an…
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#118Earlier quoted context omitted.
That's what you got from what I said? I'm saying that people think because communication is digital, and digital is easy to listen in on that we should be listening in on it. I say fuck that. Today it would be easy to listen in on anyone anywhere with a little hardware. Easy is not a justification for doing something.
you're stating a general argument which everyone can agree with. but how is it tied to this post about Microsoft helping with breaking encryption?