Live data from Hacker News

NSA's Backdoor Key from Lotus Notes

cypherspace.org

41–50 of 55 posts

Re: NSA's Backdoor Key from Lotus Notes

#41
post #33

Earlier quoted context omitted.

I don't doubt the NSA has Windows source code; many companies already do have it (as well as a small number of individuals actually). It's not unusual to have access to the Windows source code TBH. Saying that the NSA backdoored windows is not a boogeyman type claim; it's exactly within their real capabilities and seems like a very plausible path for them to have taken. Nor does it mean we can't fight against it. We…

> We can use OpenBSD and have a higher confidence that it's not backdoored. Why? As a non-technical user, from my POV I'm simply trading my trust that NSA hasn't backdoored MS with trusting that your, or De Raadt's authority is meaningful. I can't review the source code I'm running (without a prohibitively large time investment), and as we saw with Heartbleed, the "many eyes" theory is flawed as well. As an individua…

They also coerced Google as a part of PRISM. The NSA likes redundancy.

Re: NSA's Backdoor Key from Lotus Notes

#42
post #27
post #25

Earlier quoted context omitted.

So if that was a key which allowed the NSA access to the communication that was otherwise unreachable to it, it's not a backdoor to the computer, just to the communication, and therefore you deny it to be a backdoor at all? Or do we just play the game of the "proper" names? How can we call the key which allows the access to the encrypted communication? Wikipeda calls that a backdoor too: http://en.wikipedia.org/wiki/…

There may have been a key that allowed the NSA that access, there may have been a backdoor, but the object with the name "_NSAKEY" was not it.

What's your explanation for it then? Microsoft explicitly admitted it was there for Windows to be "compliant" with NSA:

http://web.archive.org/web/20000520001558/http://www.microso...

"The keys in question are the ones that allow us to ensure compliance with the NSA's technical review."

Very clear. It was there because otherwise Windows wasn't compliant according to the NSA.

Then only thing NSA could worry about commercial products was the same that made Lotus to implement what we read here.

Ask Schneier if he would now, after Snowden, react the same as in 1999 while writing about it.

Re: NSA's Backdoor Key from Lotus Notes

#43
post #33

Earlier quoted context omitted.

I don't doubt the NSA has Windows source code; many companies already do have it (as well as a small number of individuals actually). It's not unusual to have access to the Windows source code TBH. Saying that the NSA backdoored windows is not a boogeyman type claim; it's exactly within their real capabilities and seems like a very plausible path for them to have taken. Nor does it mean we can't fight against it. We…

> We can use OpenBSD and have a higher confidence that it's not backdoored. Why? As a non-technical user, from my POV I'm simply trading my trust that NSA hasn't backdoored MS with trusting that your, or De Raadt's authority is meaningful. I can't review the source code I'm running (without a prohibitively large time investment), and as we saw with Heartbleed, the "many eyes" theory is flawed as well. As an individua…

Your argument makes no sense.

> I have no reason to be anymore confident in OpenBSD than in Windows

Past statistics show that OpenBSD is safer. It's had far fewer security issues and has a much cleaner codebase. If you don't place faith in past statistics then you're willfully ignoring the best means of predicting future behavior.

In addition, OpenBSD has far fewer lines of code, and the most reliable correlation with security holes is lines of code. Simply by having fewer LoC, OpenBSD is already statistically less likely to contain a security hole.

> chain of trust

Yeah, with microsoft your chain of trust is microsoft employees and the word of other people reverse engineering the code (e.g. the people who said the _NSAKEY thing was legit after reverse engineering a small portion of the code).

With OpenBSD your chain of trust includes me, the developers, and other eyes that have looked at the code. The "many eyes" theory is not flawed. It never stated that having many eyes eliminates all bugs, merely that it's better to have more eyes than fewer eyes and increases the chance a bug is noticed. There's no sane way to argue against that statement unless you turn it into a ridiculous strawman of "many eyes means heartbleed couldn't have happened QED".

> Am I to believe that the NSA gagged with thousand or so developers who work on windows, or just the 10 who manage OpenSSL

It's much easier to believe that the NSA could gag one or two of a thousand developers than one or two of 10. Believe me, you don't have to get all MS employees to futz windows security. Just getting one at random already gives you a decent probability of getting a kernel level exploit, and selecting five or so specific employees can get you a hell of a lot more.

> the "NSA paid/forced MS" boogeyman

Evidence in this post-Snowden era indicates the NSA has worked to backdoor commercial software. It's also quite possible heartbleed was an NSA inspired hole, though I don't think that would be a productive discussion to have.

If you read leaked NSA slides and look at what they have done (such as the Verizon MITM closet) then backdooring operating systems is not a bogeyman, it's quite reasonable. You cite that they have intercepted data without the consent of the parties involved, but that ignores the fact that they also coerce parties as well; just because they have used the tactic you mention does not mean it's the only tactic they use.

If you're going to argue that BSD is no more secure than Windows and the NSA is not in fact using gag-orders and subverting software you'll need a heck of a better argument.

Re: NSA's Backdoor Key from Lotus Notes

#44
post #33

Earlier quoted context omitted.

I don't doubt the NSA has Windows source code; many companies already do have it (as well as a small number of individuals actually). It's not unusual to have access to the Windows source code TBH. Saying that the NSA backdoored windows is not a boogeyman type claim; it's exactly within their real capabilities and seems like a very plausible path for them to have taken. Nor does it mean we can't fight against it. We…

I guess what I meant was, "We now have a huge amount of evidence about what they really are doing, lets talk about that and where the line should be drawn; speculating gets us nowhere."

I agree we're not doing enough with the information we do have to curb this, but speculation also has value. Speculating is a way to explore what the line might be and also could bring attention to an unknown infringement since the NSA surely isn't telling us everything yet.

Re: NSA's Backdoor Key from Lotus Notes

#45
post #21
post #20

Earlier quoted context omitted.

By "scalably factor", I was referring to their ability to take arbitrary 1024 bit public keys as they appeared in random TLS sessions on the Internet and factor them on demand. NSA can virtually certainly target a specific, hardcoded 1024 bit key and break it. In fact, leaving out the cost and difficulty of recruiting the team to actually put the pieces together, the typical California venture capital firm has the re…

Yea, this is one reason why I don't consider 1024-bit end entity certs (as opposed to roots) that much of a threat.

Watson Ladd has pointed out that since breaking authentication 10 years after it's been deprecated does not let you retroactively MITM someone but breaking key exchange 10 years after it's been deprecated allows decryption of stored intercepts, KEX should be stronger than certificates. So make sure your TLS server with 1024 bit key uses ECDHE or 2048 bit DHE, not plain RSA KEX.

Re: NSA's Backdoor Key from Lotus Notes

#47
post #3

There was also a key marked as 'NSAKEY' in a normally encrypted part of Windows NT that was revealed in a Service Pack. However Microsoft said it had another purpose. http://en.m.wikipedia.org/wiki/NSAKEY

No one credible believes this was a backdoor.

Re: NSA's Backdoor Key from Lotus Notes

#48
post #21

Earlier quoted context omitted.

Yea, this is one reason why I don't consider 1024-bit end entity certs (as opposed to roots) that much of a threat.

Watson Ladd has pointed out that since breaking authentication 10 years after it's been deprecated does not let you retroactively MITM someone but breaking key exchange 10 years after it's been deprecated allows decryption of stored intercepts, KEX should be stronger than certificates. So make sure your TLS server with 1024 bit key uses ECDHE or 2048 bit DHE, not plain RSA KEX.

Yea, it would still be at the customer's own risk.

Re: NSA's Backdoor Key from Lotus Notes

#49
post #22
post #18

Earlier quoted context omitted.

Answers from my POV: 1 - Privileged access to the dominant consumer operating system, also used by many corporations likely to be targeted. 2 - Minimal effort cost. Good will cost seems like something NSA ignores. Exposure to risk seems minimal given the existence of NDA contracts. 3 - I think anyone who isn't deluded and/or a member of the "nothing to hide; nothing to fear" camp already knows you can't trust Windows…

So, serious question: Why would they backdoor Windows, when apparently they could just buy an exploit for $X00k[1]? Its seems buying an exploit serves all those same factors, at a similar price range, while making it much harder to point a finger at the NSA when it eventually gets discovered. Its probably a safe assumption that if someone is found using a backdoor in Windows, its probably the US Government that put i…

You talk like they're different things. This is something the Chinese do. Leave the backdoor as a vulnerability. Sure other people may find it, but that means they have access to it from the git-go (on another note, this should be how you initialize repos in git)

That way when someone finds it, they could go "oops. thanks for pointing this vulnerability out for us. Will fix"

Re: NSA's Backdoor Key from Lotus Notes

#50
post #42
post #27

Earlier quoted context omitted.

There may have been a key that allowed the NSA that access, there may have been a backdoor, but the object with the name "_NSAKEY" was not it.

What's your explanation for it then? Microsoft explicitly admitted it was there for Windows to be "compliant" with NSA: http://web.archive.org/web/20000520001558/http://www.microso... "The keys in question are the ones that allow us to ensure compliance with the NSA's technical review." Very clear. It was there because otherwise Windows wasn't compliant according to the NSA. Then only thing NSA could worry about comm…

It is true that _NSAKEY was necessary for the technical implementation of cryptographic export controls. It is also true that one of the goals of cryptographic export controls was weakening the security of people who use exported software. (Although saying that the NSA had only one goal is pretty wrong: read up about DES's S-boxes, which caused all sorts of cries of "Backdoor!" before Snowden was even born.) But calling _NSAKEY a "backdoor" is confusing for lots of reasons.

At the same time as _NSAKEY, there was another bizarre mechanism in the '90s called "server-gated cryptography". US law was that exported cryptography could not be stronger than 40-bits, but there was an exception for financial organizations. The implementation was that certain CAs were trusted to verify whether their customer was in fact a financial organization (trusted in the sense that, if the browsers decided wrong, they were violating munitions control laws...) and could place a special extension in the certificate. If that certificate was present, export browsers would negotiate 128-bit cipher suites; otherwise they would only negotiate 40-bit cipher suites.

This mechanism, incidentally, blew up in our collective faces two weeks ago under the name "FREAK", and there was a lot of talk about whether the NSA's meddling was appropriate.

But where's the backdoor? In this case, it is the presence of certain CA keys that allows strong crypto, and their absence weakens it. _NSAKEY has the same goal, but it's just done in reverse. So calling the key a backdoor is not very meaningful, since in the SGC case, we'd have to call the absence of a key a backdoor.

This is a very different sort of thing from the Lotus escrow business in this article, where the software silently encrypts the data to a public key owned by the NSA. The Windows _NSAKEY is just a signing key, and in US versions of the software, _KEY is also allowed to sign all the same things. Nothing is ever encrypted to _NSAKEY.

Or, in other words, the presence of _NSAKEY in US versions of the software cannot possibly weaken anyone's security.

If there is a backdoor here at all, it is the entire system of export controls for crypto. (Which everyone knew about because it was literally the law, so calling it a "backdoor" is sorta like calling Wikipedia's edit-this-page button a "security vulnerability".) All of this was very different from the Lotus backdoor described in the article.

Post reply on HN