Live data from Hacker News

German government warns Windows 8 is a security risk

zeit.de

41–50 of 125 posts

Re: German government warns Windows 8 is a security risk

#41

2013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…

It is even worse. The attempt to escape into OSS/Linux is a step in the right direction. But as long as we are dependent on mass consumer hardware then there is always a risk of being spied through hardware backdoors. In this case it doesn't matter which software we use. Even encryption is useless. It is NOT enough to avoid Windows 8 because the real problem is modern hardware that uses Trusted Computing chips.

Trusted Computing (TC) is way more dangerous than classical hardware backdoors. I consider TC an evil technology because it not only takes control away from the user but it even allows to inject faked evidence into computers which could make innocent people -- independent journalists, political activists etc. -- suspect to crime.

TC could also be used to delete evidence from computers of journalists who would have no power to keep it. TC allows to control people without letting them even know about it. TC is a huge danger for freedom of speech. It should be banned politcally and boycotted in business. My recommendation: Don't buy consumer hardware but use embedded Linux systems with bare bone technology.

If we want to be truly secure from being spied then we must do a complete restart with new hardware and software from scratch. There is no way around.

I am actually "glad" about the NSA scandal (thank you Snowden) because it woke people up and made them aware of the reality of global surveilliance, and about the huge threats of Trusted Computing. NSA should be controlled by the people of the United States but obviously it has become out of control. This single NSA case has silenced the mouth of the conspiracy mockers once and for all.

Re: German government warns Windows 8 is a security risk

#43
post #18

So because Windows 8 has support for trusted boot and friends that might (it's pure speculation) contain a backdoor, it's less secure than previous versions that did not support trusted boot at all? I agree that the NSA spying is a real threat, but so is traditional malware. The article is basically saying that, because the malware protection is not good enough (i.e. not securing against NSA malware), it's worse than…

"I do agree that locking down the OS so that it runs only MS-signed applications is a dick move in general and we'll probably see really bad changes in the market overall, but I see no relation to the NSA spying issue."

You see no relation?

If MS is the only who could control your computer, and MS is an American company tat has to obey American laws, and the American laws says they must spy on every customer, specially non Americans, like Germans, as they are defined "adversaries"...

You see no relation?

Re: German government warns Windows 8 is a security risk

#45

Nothing prevents you from buying a non-Windows, non-Mac laptop. It's not the year 2000 anymore when there were hardly any other options.

Or using a system without tpm I am looking at building a new pc and all the motherboards I have looked at do not have a tpm module they have the header to implement one but its not installed by default.

Re: German government warns Windows 8 is a security risk

#47
post #20

This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…

> If Microsoft wanted to backdoor your system ... ... they already have Windows Update. It cannot be null-routed (respective entries in /etc/hosts are simply ignored), it is virtually always on and it can be trivially used to deliver custom patches to specific boxes. What more can you ask for?

Who says the original windows binaries don't have backdoors in them? So far as I can see the only difference TPM makes is that it potentially opens vulnerabilities in non-MS operating systems you run. If you're running any version Windows, or in fact any software you don't compile yourself from source(1), you just have to trust on faith it's not back-doored up to the eyeballs from the get-go. This has always been true.

(1) And in fact also have total confidence in the compiler itself: http://scienceblogs.com/goodmath/2007/04/15/strange-loops-de...

Re: German government warns Windows 8 is a security risk

#48
post #5
post #2

This leads to a German article. Sorry I did not find any English article on this topic yet. So here the short summary (actually my translations of selected passages): [German] government experts warn, Windows 8 is an unacceptable security risk for governmental offices and companies. The so-called Trusted Computing might be a backdoor for NSA. [..] According to their [expert's] opinion the operating system contains a…

Being unable to read German I can't comment fully on the original article, but based on this summary this warning seems pretty silly. The operating system kernel always has full control over the system, how are they suggesting the TPM adds control here? The TPM is a small chip that handles certain crypto operations more securely (especially key management), how does this provide any additional backdoor scenarios? If…

>If Microsoft wanted a backdoor it could easily be added to the OS without a TPM.

Without a TPM, it is possible to detect and remove (or more likely mitigate) a backdoor. With the TPM, even if you know about a backdoor and have a patch you can not apply it without Microsofts blessing. At least, thats my understanding.

Re: German government warns Windows 8 is a security risk

#49
post #36
post #26

Earlier quoted context omitted.

What portion of people you communicate with email were you able to convince to use PGP with you? My understanding is, that there isn't an email privacy, since at least they will have your metadata. In my limited understanding, secure communication is to be done using some secure chat service.

For most contacts you just move away from people who don't use secure communication and may compromise you in the future, no need to convince someone. Works for me.

Those of you who downvoted this comment, please explain your reasons.

E.g. here are mine: not enough people communicate securely right now. I can't just abandon everyone; that's way too isolationist for my personal taste. Still, if you want to that _is_ an option.

Re: German government warns Windows 8 is a security risk

#50

2013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…

I have no intention of moving away from Windows 8. I do, however, have a laptop that never connects to a network. Ever. It's where I keep things I consider private. Data transfer, minimal as it is, is done using swivel-chair integration.

Everything else (i.e. all my remaining devices and apps on those devices) are treated like any PC in an Internet café - untrusted and compromised.

Post reply on HN