Live data from Hacker News

NSA's Backdoor Key from Lotus Notes

cypherspace.org

51–55 of 55 posts

Re: NSA's Backdoor Key from Lotus Notes

#51
post #50
post #42

Earlier quoted context omitted.

What's your explanation for it then? Microsoft explicitly admitted it was there for Windows to be "compliant" with NSA: http://web.archive.org/web/20000520001558/http://www.microso... "The keys in question are the ones that allow us to ensure compliance with the NSA's technical review." Very clear. It was there because otherwise Windows wasn't compliant according to the NSA. Then only thing NSA could worry about comm…

It is true that _NSAKEY was necessary for the technical implementation of cryptographic export controls. It is also true that one of the goals of cryptographic export controls was weakening the security of people who use exported software. (Although saying that the NSA had only one goal is pretty wrong: read up about DES's S-boxes, which caused all sorts of cries of "Backdoor!" before Snowden was even born.) But call…

This is a great comment. My new go-to link on NSAKEY threads. Thank you!

Re: NSA's Backdoor Key from Lotus Notes

#52
post #49
post #22

Earlier quoted context omitted.

So, serious question: Why would they backdoor Windows, when apparently they could just buy an exploit for $X00k[1]? Its seems buying an exploit serves all those same factors, at a similar price range, while making it much harder to point a finger at the NSA when it eventually gets discovered. Its probably a safe assumption that if someone is found using a backdoor in Windows, its probably the US Government that put i…

You talk like they're different things. This is something the Chinese do. Leave the backdoor as a vulnerability. Sure other people may find it, but that means they have access to it from the git-go (on another note, this should be how you initialize repos in git) That way when someone finds it, they could go "oops. thanks for pointing this vulnerability out for us. Will fix"

That gives you the worst of both worlds, though. You get the major developmental downside of a backdoor - making sure no one in the development pipeline finds and removes it - while still having to do the non-trivial work of actually exploiting the bug. Admittedly I don't have real experience with the 0-day black market, but the internet tells me I can just show up with $200k and buy a Chrome/Windows/iOS 0-day, if I know the right people. I find it hard to believe its actually cheaper or even easier to backdoor software than it is to just buy the exploits.

Re: NSA's Backdoor Key from Lotus Notes

#53
post #3

There was also a key marked as 'NSAKEY' in a normally encrypted part of Windows NT that was revealed in a Service Pack. However Microsoft said it had another purpose. http://en.m.wikipedia.org/wiki/NSAKEY

NSAKEY or NO NSAKEY...it's clear Microsoft is in bed with the NSA. I don't trust ANY of their crap products.

Re: NSA's Backdoor Key from Lotus Notes

#54
post #50
post #42

Earlier quoted context omitted.

What's your explanation for it then? Microsoft explicitly admitted it was there for Windows to be "compliant" with NSA: http://web.archive.org/web/20000520001558/http://www.microso... "The keys in question are the ones that allow us to ensure compliance with the NSA's technical review." Very clear. It was there because otherwise Windows wasn't compliant according to the NSA. Then only thing NSA could worry about comm…

It is true that _NSAKEY was necessary for the technical implementation of cryptographic export controls. It is also true that one of the goals of cryptographic export controls was weakening the security of people who use exported software. (Although saying that the NSA had only one goal is pretty wrong: read up about DES's S-boxes, which caused all sorts of cries of "Backdoor!" before Snowden was even born.) But call…

So the arguments you give are: the presence of the NSAKEY doesn't point to the backdoor because the whole system is a backdoor and because US Windows was anyway more secure, who cares for dem Europeans or Asians.

The catch 22 is not a catch 22, the whole system is a catch 22, therefore don't ever call the catch 22 the catch 22.

Re: NSA's Backdoor Key from Lotus Notes

#55

Earlier quoted context omitted.

FPGA are very very inefficient at doing anything, they are very flexible and you can program them to perform specific operations very quickly relative to general purpose hardware however most of the silicon is dedicated to facilitate the programmability of the FPGA rather than the actual processing. If you only have access to commodity hardware than GPU's would probably be better. Xeon Phi is also insanely cheap righ…

Factoring RSA-2048 in 2020 sounds impossible. tptacek said it's extraordinarily unlikely NSA can scalably factor RSA-1024 today [1]. Look at how difficulty increases in the Yafu with GGNFS benchmark on wikipedia [2]. 1 - https://news.ycombinator.com/item?id=8844239 2 - https://en.wikipedia.org/wiki/RSA_%28cryptosystem%29#Integer...

Just because some dude says something in the Internet doesn't make it true. Especially that dude, when he talks about US intelligence agencies.
Post reply on HN