This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…
I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer: - I can't enter BIOS before entering OS. - Once I enter the BIOS from the OS I can't activate the hard disk password. - I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already prese…
German government warns Windows 8 is a security risk
51–60 of 125 posts
Re: German government warns Windows 8 is a security risk
#52This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…
I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer: - I can't enter BIOS before entering OS. - Once I enter the BIOS from the OS I can't activate the hard disk password. - I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already prese…
Re: German government warns Windows 8 is a security risk
#53Earlier quoted context omitted.
I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer: - I can't enter BIOS before entering OS. - Once I enter the BIOS from the OS I can't activate the hard disk password. - I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already prese…
What brand notebook is that? Just so I can make a mental note to avoid purchasing that brand in the future :)
The discussions of kernel-level "giving up control" existed in Palladium and "technologies formerly known as Palladium (http://en.wikipedia.org/wiki/Next-Generation_Secure_Computin...) even 10 years ago but with Windows 8 they start to be ubiquitous and nobody even notices.
Re: German government warns Windows 8 is a security risk
#54How trustworthy is Microsoft? This is the question that concerns the Federal Administration and other German government agencies, as well as companies and private users who might want to use the Windows operation system now and in the future. Sooner or later they will be forced to use Windows 8 or its successor. According to documents available to the ZEIT ONLINE, government IT experts consider Windows 8 to be dangerous. They contend that the operating system contains a backdoor which cannot be closed. This backdoor is called Trusted Computing and it might empower Microsoft and the NSA to remotely control any device that uses it.
[...] The way in which the chip and the operating system cooperate is standardized and the specification for this is defined by the Trusted Computing Group (TCG). The TCG was founded ten years ago by Microsoft, Intel, Cisco, AMD, HP, and Wave Systems - all of which are US companies.
The current TPM specification is scheduled to be replaced by a new one dubbed TPM 2.0. Together, TPM 2.0 and Windows 8 achieve what has become the norm on smartphones, tablets, and gaming consoles: hardware and operating system become a tightly coupled unit that allows the OS vendor to tie down precisely what can be installed on a device and what cannot. To put it another way, Trusted Computing is a vehicle for Digital Rights Management (DRM) enforcement.
[...] Three issues arise here: First, contrary to the current generation standard TPM will be enabled right from the first boot-up of the device. Whoever uses this computer will no longer be able to decide if they want to use TPM (Opt-in). Secondly, TPM can no longer be deactivated on systems that have it (Opt-out). Thirdly, how TPM functions are used is entirely up to the operating system [vendor], in the case of Windows computers this will be Microsoft.
From the year 2015 on every single PC will be shipped with Windows 8.x and TPM 2.0. For the user there is simply no way to tell what exactly Microsoft does to their system through remote updates.
To summarize, users of a Trusted Computing System lose control of their computer. This is the design goal of Trusted Computing, as the Federal Ministry for IT Security (BSI) explains in detail here [link]. The BSI suggests that government agencies, companies, and private users actually make use of this technology - but only if certain conditions are met. A way to Opt-in and Opt-out is part of these conditions, and these options are being eliminated now. [...] Accordingly, the Federal Administration and the BSI now express very clear warnings against the use of Trusted Computing 2.0 within German agencies.
According to a paper issued by the Ministry for Commerce from early 2012: "Due to the loss of control over [the capabilities of] information technology" "the security-oriented principles of 'confidentiality' and 'integrity' are no longer achievable". Other statements assert for example: "this could have severe consequences for the IT security of the Federal Administration." Thus the conclusion is: "The use of 'Trusted Computing' technology in this form ... is not acceptable within the Federal Administration and other critical infrastructure".
[end of page 1]
Another document reveals that Windows 8 and its successors combined with TPM 2.0 are already unusable "even today". Windows 7 could "be used securely until 2020". After that, other solutions would have to be found.
In an assessment the BSI writes that "unconditional and complete trust" in Trusted Computing is not possible with TPM 2.0. The documents contain evidence that the German government did try to influence the development of the new standard. This type of cooperation has been taking place for years, this time the Germans have been simply ignored though. However, other parties got exactly what they wanted. The NSA, for example. "The NSA approves" was a catch phrase that has been issued during the last meeting between TCG and interested parties, according to some participants.
[end of translation]
The second page contains a lot of predictable conclusions about suspected NSA/US spying capabilities.
Re: German government warns Windows 8 is a security risk
#552013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…
What portion of people you communicate with email were you able to convince to use PGP with you? My understanding is, that there isn't an email privacy, since at least they will have your metadata. In my limited understanding, secure communication is to be done using some secure chat service.
I'm also fairly sure that Google will start integrating PGP into their desktop clients (Android, iOS) because this is affecting their bottom line (just wait until governments will start banning Gmail usage in the public sector).
Re: German government warns Windows 8 is a security risk
#562013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…
It is even worse. The attempt to escape into OSS/Linux is a step in the right direction. But as long as we are dependent on mass consumer hardware then there is always a risk of being spied through hardware backdoors. In this case it doesn't matter which software we use. Even encryption is useless. It is NOT enough to avoid Windows 8 because the real problem is modern hardware that uses Trusted Computing chips. Trust…
Re: German government warns Windows 8 is a security risk
#57Earlier quoted context omitted.
Key point: "Trusted" in this sense refers to trust to an external entity and not the owner or user of the actual computer, which ironically is not trusted to have full access to all things on the computer. The biggest problem is that the "trusted" party which has full access is almost certainly under NSA/PRISM jurisdiction and can be forced to do things which most people would find objectionable.
Where do you see that a trusted party has full access? Yes, the NSA could probably create a Windows build with a backdoor, and forge a signature that the TPM would accept, but they could (and probably did) just ask Microsoft to do that and save the bother. What attack vector, exactly , does the TPM enable that isn't present pre-TPM?
But wait, it gets worse. At least in the case of MacBooks you only have to trust Apple, but in the case of Microsoft you also have to trust the computer manufacturer. And that's a really tough pill to swallow.
I actually hope that Windows 8 will be banned by governments in the public sector, as Trusted Computing is a scourge upon this industry.
Re: German government warns Windows 8 is a security risk
#582013, it's the post-snowden era. We don't have a cold war any more, but the level of spying is unbelievable. I am currently moving out my emails from GMail and installed PGP. At the moment I am using OSX since I do for years. But in the end the only "safe" way to protect your business and privacy is to use Linux/Unix. The FSF said it for years; the german CCC told us for years. I admit, I didn't believe it's so bad.…
It is even worse. The attempt to escape into OSS/Linux is a step in the right direction. But as long as we are dependent on mass consumer hardware then there is always a risk of being spied through hardware backdoors. In this case it doesn't matter which software we use. Even encryption is useless. It is NOT enough to avoid Windows 8 because the real problem is modern hardware that uses Trusted Computing chips. Trust…
Before the Snowden leaks, you'd be hard pressed to find a technically-minded person arguing that the NSA doesn't have, at the least, the potential to have their fingers in every pie.
Re: German government warns Windows 8 is a security risk
#59Earlier quoted context omitted.
Where do you see that a trusted party has full access? Yes, the NSA could probably create a Windows build with a backdoor, and forge a signature that the TPM would accept, but they could (and probably did) just ask Microsoft to do that and save the bother. What attack vector, exactly , does the TPM enable that isn't present pre-TPM?
Because you can only install software approved by Microsoft, you cannot install software on it for detecting a backdoor installed by Microsoft. These computers are only more secure if you trust Microsoft. If Microsoft can't be trusted (and they can't be, as they are under NSA's jurisdiction), then the Windows 8 computers are less secure. But wait, it gets worse. At least in the case of MacBooks you only have to trust…
Re: German government warns Windows 8 is a security risk
#60This is about the TPM in windows 8. It's the same argument about treacherous computing that goes around, except the article seems to be suggesting people think it's a extent problem now because the TPM is always on, not a hypothetical in the future/ Microsoft's long term plan. Further, there is a nebulous assertion linking this to the NSA. 1) The TPM still can't control your computer(yet). It can only measure it's st…
I have a Windows 8 notebook and for the first time in my life I have no control over my own general purpose computer: - I can't enter BIOS before entering OS. - Once I enter the BIOS from the OS I can't activate the hard disk password. - I can't install the Windows 8 OS clean. The MSFT has the deal with the computer producers that doesn't allow them to deliver the pure OS medium, you can only backup the already prese…