Live data from Hacker News

German government warns Windows 8 is a security risk

zeit.de

1–10 of 125 posts

Re: German government warns Windows 8 is a security risk

#2
This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages):

[German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA.

[..]

According to their [expert's] opinion the operating system contains a backdoor which cannot be closed. This backdoor is called Trusted Computing and might have the consequence that Microsoft could control every computer remotely. And therefore NSA could do it as well.

[..]

Three points are decisive: First the [new] TPM, in contrary to the existing standard, is active from the time when you switch on the computer. As soon as you start the computer you cannot decide anymore if you want Trusted-Computing (Opt-in). Secondly it is not possible to deactivate in future the TPM (Opt-out). Third the OS takes over the control over the TPM, in the case of Windows OS it means that the computer is controlled by Microsoft.

----

In the light of the current situation on spying, I have to say that I am happy that it goes in this direction.

Re: German government warns Windows 8 is a security risk

#3
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

Translated version: http://translate.google.co.uk/translate?sl=de&tl=en&js=n&pre...

Re: German government warns Windows 8 is a security risk

#4
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

If what Snowden showed us is true, the same thing for the (recent) versions of MacOsX. I'd say things are looking up for Linux on the desktop.

Re: German government warns Windows 8 is a security risk

#5
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

Being unable to read German I can't comment fully on the original article, but based on this summary this warning seems pretty silly.

The operating system kernel always has full control over the system, how are they suggesting the TPM adds control here? The TPM is a small chip that handles certain crypto operations more securely (especially key management), how does this provide any additional backdoor scenarios?

If Microsoft wanted a backdoor it could easily be added to the OS without a TPM.

Re: German government warns Windows 8 is a security risk

#7
This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA.

1) The TPM still can't control your computer(yet). It can only measure it's state, allow you access to keys you created in some state, and attest to things about the state (which would allow other parties to mandate what state your system is in when interacting with it, but presumably those entities would be bond by German law and likely be German themselves)

2) If Microsoft wanted to backdoor your system, they don't need the TPM to do it. In fact, the TPM can be used to protect against a whole bunch of malware that various intelligence agencies might use: it can protect keys with passwords (with rate limiting/self destruct for guessing), make sure the system is in the same state(i.e. malware free) when you created you PGP key as it is when your using it to decrypt an e-mail, and it can isolate an application from the rest of your system.

Re: German government warns Windows 8 is a security risk

#8

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

Your second point is exactly what the German government is afraid of according to the article. According to the article there seem to be security vulnerabilities on 3 levels in TPM 2.0, which might be used by intelligence agencies - the article states NSA and China who is actually producing most of the TPM chips.

Re: German government warns Windows 8 is a security risk

#9
post #5
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

Being unable to read German I can't comment fully on the original article, but based on this summary this warning seems pretty silly. The operating system kernel always has full control over the system, how are they suggesting the TPM adds control here? The TPM is a small chip that handles certain crypto operations more securely (especially key management), how does this provide any additional backdoor scenarios? If…

If I remember my German correctly the articles argues around many different points.

One is spying (NSA), another is restrictions on what to install (Microsoft) and some parts discuss the threat from China, manufactures of the TPM chips.

Re: German government warns Windows 8 is a security risk

#10
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

If what Snowden showed us is true, the same thing for the (recent) versions of MacOsX. I'd say things are looking up for Linux on the desktop.

Can you elaborate on the OS X issue (I think I've missed that disclosure)? Everything I can find, which admittedly is not anything authoritative (nothing from Apple directly), says that Apple hasn't shipped TPMs for a few years now.
Post reply on HN