Live data from Hacker News

German government warns Windows 8 is a security risk

zeit.de

11–20 of 125 posts

Re: German government warns Windows 8 is a security risk

#12
2013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad. I always thought: good there are a few of us paranoid, they take care there is a balance.

Now we see, there is no balance. Good we have had these paranoid people because they are now providing us a chance to opt-out.

Good there were these programmers who worked for years and often in their prime time in free and open solutions like GNU/Linux. Snort, the intrusion detection system. GPG. And so on.

For me it is a hard job to opt-out of being spied. But I will move on, step for step. Email privacy is the first; no GMail, no Apple Mail. Old friend Thunderbird/Enigmail it is. I also installed TrueCrypt.

The biggest move will be to change the OS (again). Guess it takes me months or longer as I have a lot of great OSX software. But on the other hand, I can simply set up a new machine for private tasks - or dual boot my macbook with Linux.

I hope my government will take this warning serious and support more "Linux @ City" projects (Munich runs on Linux and Open- or LibreOffice).

Wow, long comment. I just needed to say. I am worried.

Re: German government warns Windows 8 is a security risk

#13
post #10

Earlier quoted context omitted.

If what Snowden showed us is true, the same thing for the (recent) versions of MacOsX. I'd say things are looking up for Linux on the desktop.

Can you elaborate on the OS X issue (I think I've missed that disclosure)? Everything I can find, which admittedly is not anything authoritative (nothing from Apple directly), says that Apple hasn't shipped TPMs for a few years now.

Sorry, I should have provided more details. I ment to say Prism program also taps in to user data of Apple. PRISM showed us the NSA has direct access to Apple servers. The Guardian: http://www.theguardian.com/world/2013/jun/06/us-tech-giants-...

Re: German government warns Windows 8 is a security risk

#14
post #8

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

Your second point is exactly what the German government is afraid of according to the article. According to the article there seem to be security vulnerabilities on 3 levels in TPM 2.0, which might be used by intelligence agencies - the article states NSA and China who is actually producing most of the TPM chips.

Bundestrojaner.

Re: German government warns Windows 8 is a security risk

#15
post #10

Earlier quoted context omitted.

Can you elaborate on the OS X issue (I think I've missed that disclosure)? Everything I can find, which admittedly is not anything authoritative (nothing from Apple directly), says that Apple hasn't shipped TPMs for a few years now.

Sorry, I should have provided more details. I ment to say Prism program also taps in to user data of Apple. PRISM showed us the NSA has direct access to Apple servers. The Guardian: http://www.theguardian.com/world/2013/jun/06/us-tech-giants-...

Ah, I see. (I thought you were talking about something found in OS X, not Apple's PRISM involvement.) I'm not sure if I personally consider this a reason not to use OS X, but it is definitely a reason to not use iCloud.

Re: German government warns Windows 8 is a security risk

#17

can anyone elaborate on TPMs, what are they, why are they the risk in MS case etc.?

http://en.wikipedia.org/wiki/Trusted_Platform_Module

Key point: "Trusted" in this sense refers to trust to an external entity and not the owner or user of the actual computer, which ironically is not trusted to have full access to all things on the computer.

The biggest problem is that the "trusted" party which has full access is almost certainly under NSA/PRISM jurisdiction and can be forced to do things which most people would find objectionable.

Re: German government warns Windows 8 is a security risk

#18
So because Windows 8 has support for trusted boot and friends that might (it's pure speculation) contain a backdoor, it's less secure than previous versions that did not support trusted boot at all?

I agree that the NSA spying is a real threat, but so is traditional malware. The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than no protection at all.

FUD.

I do agree that locking down the OS so that it runs only MS-signed applications is a dick move in general and we'll probably see really bad changes in the market overall, but I see no relation to the NSA spying issue. The NSA can install malware as well on XP machines as it can on Windows 8 machines, so in that regard, Win8 is no better nor worse than previous versions.

(also: I really don't intend to be trolling and my argument seems reasonable. As such I wonder what the reason for the downvotes is. Is it possible that you guys are getting an english article with a different content? If I click the link I get to see a german article)

Re: German government warns Windows 8 is a security risk

#20

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

> If Microsoft wanted to backdoor your system ...

... they already have Windows Update. It cannot be null-routed (respective entries in /etc/hosts are simply ignored), it is virtually always on and it can be trivially used to deliver custom patches to specific boxes. What more can you ask for?

Post reply on HN