Live data from Hacker News

German government warns Windows 8 is a security risk

zeit.de

31–40 of 125 posts

Re: German government warns Windows 8 is a security risk

#31

Earlier quoted context omitted.

http://en.wikipedia.org/wiki/Trusted_Platform_Module

Key point: "Trusted" in this sense refers to trust to an external entity and not the owner or user of the actual computer, which ironically is not trusted to have full access to all things on the computer. The biggest problem is that the "trusted" party which has full access is almost certainly under NSA/PRISM jurisdiction and can be forced to do things which most people would find objectionable.

Where do you see that a trusted party has full access? Yes, the NSA could probably create a Windows build with a backdoor, and forge a signature that the TPM would accept, but they could (and probably did) just ask Microsoft to do that and save the bother.

What attack vector, exactly, does the TPM enable that isn't present pre-TPM?

Re: German government warns Windows 8 is a security risk

#32
post #10

Earlier quoted context omitted.

If what Snowden showed us is true, the same thing for the (recent) versions of MacOsX. I'd say things are looking up for Linux on the desktop.

Can you elaborate on the OS X issue (I think I've missed that disclosure)? Everything I can find, which admittedly is not anything authoritative (nothing from Apple directly), says that Apple hasn't shipped TPMs for a few years now.

I have no knowledge about OS X and TPMs specifically, but I do know some people have concerns about what OS X stores in the SMC: http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_and_Harry_P...

I'm not remotely qualified to comment on the contents of that talk, but it's a very concerning read–they claim that the SMC stores your FileVault key (though they don't seem to prove this?) and that the SMC has a backdoor. I'm all ears if anyone else has any additional info/knowledge about this...

Re: German government warns Windows 8 is a security risk

#33
post #18

So because Windows 8 has support for trusted boot and friends that might (it's pure speculation) contain a backdoor, it's less secure than previous versions that did not support trusted boot at all? I agree that the NSA spying is a real threat, but so is traditional malware. The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than…

> The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than no protection at all.

No. If the OS is locked down so only MS-signed applications can run, it is impossible to run software that can detect malware that has been approved by MS. It is also impossible to run software that can remove such malware.

If the OS makes it impossible to detect or remove malware, it is less secure than OS that do allow detection and removal of malware. This is not FUD.

What should happen, is that MS should be held strict liable for any illegal acts which their restrictions helps to propagate. Held under vicarious liability by non-US markets (so they can't get immunity by the US government), MS shareholders would demand the elimination of the restrictions in favor of less legal risk for the company.

Re: German government warns Windows 8 is a security risk

#34
post #18

So because Windows 8 has support for trusted boot and friends that might (it's pure speculation) contain a backdoor, it's less secure than previous versions that did not support trusted boot at all? I agree that the NSA spying is a real threat, but so is traditional malware. The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than…

> FUD.

Fud or not, this is what happens when you shake the public's trust in... anything. In this case it happens to be government, the internet and technology. The NSA scandal will have wide reaching and unpredictable implications.

Losers will be traditional technology providers like Microsoft, HP, Cisco, etc. Remember how the US blocked China from supplying networking gear domestically on grounds of "security concerns"? (Which no doubt are totally valid.) Well, would you trust your company's or government's security to Cisco gear?

Re: German government warns Windows 8 is a security risk

#35

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer:

- I can't enter BIOS before entering OS.

- Once I enter the BIOS from the OS I can't activate the hard disk password.

- I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already present installed files to some external HDD.

- Because of the previous and the fact that the binaries are controlled on the hardware level (TPM), I have no control of what's running on my computer -- I can't know, to be precise.

- It's even worse than that, there is some Intel built-in technology on the hardware/BIOS/drivers level which also has built-in "features" that allow communication with some external "command and control center" which I don't control. It supposedly allows, among other "features" disabling the notebook once it's stolen. But I don't control how it's done, and I don't know if it has additional backdoors. It proudly claims to facilitate "remote access."

It's scary how it looks like all together. I haven't even figured out how I'd be able to install Linux on the computer. In some forums people claim that the OEM should allow that, but apparently a lot of people haven't managed to actually install it on different specific computers -- there are BIOS problems that can't be avoided, and the OEMs don't give you support or the updates. Mine is an Intel i5 processor-based modern Acer. It's fast, but I have no control. Definitely not FUD.

Personally I like Apple approach more: thanks to their approach of the OSX or iOS (no third party pre-installed crap) at least I have to just trust Apple. Here I have to trust Microsoft, Intel and every company who has the drivers on my machine. Much more chance for some of them to do what they want, in the name of "cloud." Remember routers that are controlled from the producer of the router, even "protecting" you from browsing all the sites? Remember Android phones which upload all your passwords to the cloud of the mobile operator? That's where the "cloud" support of the driver writers goes now. It is scary.

(Globally, we're talking about this: http://xkcd.com/743/ -- We've been giving up the control of "infrastructures" for a long time)

Re: German government warns Windows 8 is a security risk

#36
post #26

2013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…

What portion of people you communicate with email were you able to convince to use PGP with you? My understanding is, that there isn't an email privacy, since at least they will have your metadata. In my limited understanding, secure communication is to be done using some secure chat service.

For most contacts you just move away from people who don't use secure communication and may compromise you in the future, no need to convince someone. Works for me.

Re: German government warns Windows 8 is a security risk

#38
post #15

Earlier quoted context omitted.

Sorry, I should have provided more details. I ment to say Prism program also taps in to user data of Apple. PRISM showed us the NSA has direct access to Apple servers. The Guardian: http://www.theguardian.com/world/2013/jun/06/us-tech-giants-...

Ah, I see. (I thought you were talking about something found in OS X, not Apple's PRISM involvement.) I'm not sure if I personally consider this a reason not to use OS X, but it is definitely a reason to not use iCloud.

Same for me too, I don't use iCloud or iOS, I don't even have an AppleID. But my MBA/OSX a very nice unix client.

Re: German government warns Windows 8 is a security risk

#39
post #20

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

> If Microsoft wanted to backdoor your system ... ... they already have Windows Update. It cannot be null-routed (respective entries in /etc/hosts are simply ignored), it is virtually always on and it can be trivially used to deliver custom patches to specific boxes. What more can you ask for?

You are right that MSFT has the "update". The bigger problem with Windows 8 computers is that similar things are in practice available to all the "third parties" who have hardware or kernel-driver components. And you have less control than before about them all. It's a broader problem than just Microsoft.

The new "you as the user can't control the kernel stuff, even with the debugger" concept is really about the user (you) giving up the control. The excuse is that you as the user aren't supposed to be able to copy movies. In practice, you have no more control of your own computer whereas the companies have real-time control even of the content by directly controlling your computer. Some routers already did such stuff. It is really worrying -- having the part of the "great firewall of China/whateverothercountry" on your own computer which you paid with your own money.

Re: German government warns Windows 8 is a security risk

#40
post #24

Earlier quoted context omitted.

> that might (it's pure speculation) contain a backdoor Maybe, just maybe we have come to the point in time that unless a system has been shown to be secure, it should be assumed to be wiretaping the user. We can no longer assume secure until proven insecure. > FUD. Absolutely. This is what the reputational damage to american firms like Microsoft looks like. Why the hell should their systems be trusted now?

>Maybe, just maybe we have come to the point in time that unless a system has been shown to be secure, it should be assumed to be wiretaping the user. We can no longer assume secure until proven insecure. I 100% agree. But I really fail to see how this makes Windows 8 a worse operating system in that regards than its predecessors. A system that provides no trusted computing support is equally easily hacked by the NSA…

If a system has engineered access for government investigators, then that system is more vulnerable than systems which have no such access built in, because it really isn't "hacking" (cracking) if the system is built to allow access.
Post reply on HN