Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

111–118 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#111
post #50

Earlier quoted context omitted.

"Why does the NSA have full access to your servers?" Because they ordered him to give it, and he elected not to go to jail.

He means "how". Open-source protects against software backdoors (though obviously not against key-sharing et alii)

What are you talking about? Open-source doesn't protect against backdoors even theoretically. Think about it. Have you read every line of every piece of software you run? Would you understand it all if you did? Even if you read the source code, did you actually compile it all from scratch or did you use a binary (like virtually every single OSS user on earth)? Are you certain that the compiler you used wasn't compromised? How exactly?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#112

Yet another reason to stick to open source.

That's nothing more than the illusion of security. Nearly anyone using open source is using a distro. Do you imagine distro maintainers would willingly go to jail rather than putting in backdoors in the binaries they release?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#113

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

This reminds me about something one of my teacher (a very stallman-like guy in his views) told us about encase. It's an (apparently) fairly common suite of tools used by law enforcement agencies around the world for forensic analysis. In the description of their decryption module (http://www.guidancesoftware.com/encase-forensic.htm#tab=2) they claim to be able to decrypt quite a few whole-disk encryption schemes. Now it's hard to imagine that they would put an outright lie on their website but there could be several explanations for that. I think the consensus among the students was that they were exaggerating quite a bit, and were only capable to do it upon some specific circumstances (weak passwords, setup errors, various cryptographic edge cases, etc). However the other obvious explanation was that some kind of backdoors were built among those schemes (you can notice the absence of common open source stuff like luks or truecrypt in the list) and that there's accords between some vendors and governmental agencies (via this software) to allow for access into their encryption schemes. I was fairly skeptical back then, but now I'm not so sure... There might be a combination of the two explanations. Someone well-versed into cryptography might be able to tell if some of those products have well-known vulnerabilities.

Edit : the site seems to have some difficulties, here's the google cache http://webcache.googleusercontent.com/search?q=cache:JZEtYXR... The description of the decryption suite is in the module tab.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#114

going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…

>could there be a case where the parties in a conversation are legitimate suspects? It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day). We shouldn't accept the government listening in on digital communication just because it's easy.

are you saying Microsoft helped to wiretap email?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#115

Earlier quoted context omitted.

>could there be a case where the parties in a conversation are legitimate suspects? It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day). We shouldn't accept the government listening in on digital communication just because it's easy.

are you saying Microsoft helped to wiretap email?

That's what you got from what I said? I'm saying that people think because communication is digital, and digital is easy to listen in on that we should be listening in on it. I say fuck that. Today it would be easy to listen in on anyone anywhere with a little hardware. Easy is not a justification for doing something.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#116

Earlier quoted context omitted.

are you saying Microsoft helped to wiretap email?

That's what you got from what I said? I'm saying that people think because communication is digital, and digital is easy to listen in on that we should be listening in on it. I say fuck that. Today it would be easy to listen in on anyone anywhere with a little hardware. Easy is not a justification for doing something.

you're stating a general argument which everyone can agree with. but how is it tied to this post about Microsoft helping with breaking encryption?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#117
post #30

Earlier quoted context omitted.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

Take a look at Alex Ionescu's "Ninja's and Harry Potter" talk from NoSuchCon this year [1]. He specifically mentions he could access the FileVault key of a machine by having physical access, and discovered two secret keys (KPPW and KPST) one of which is enabled when the input buffer is "SpecialisRevelio" [2]. It's a very interesting deck to read through. [1] http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_an…

That's really very interesting, and quite concerning. I saw that talk was only presented in May. Any new info since then?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#118

Earlier quoted context omitted.

That's what you got from what I said? I'm saying that people think because communication is digital, and digital is easy to listen in on that we should be listening in on it. I say fuck that. Today it would be easy to listen in on anyone anywhere with a little hardware. Easy is not a justification for doing something.

you're stating a general argument which everyone can agree with. but how is it tied to this post about Microsoft helping with breaking encryption?

I'm replying with someone who was challenging the general assertion that the spying might actually be good.
Post reply on HN