Live data from Hacker News

_NSAKEY

en.wikipedia.org

91–100 of 118 posts

Re: _NSAKEY

#91
post #69

Earlier quoted context omitted.

Yes because the NSA snooping in everyone's data turned out to be a conspiracy...

It did though, didn't it? Intelligence organisations worldwide execute their operations in total secrecy and have hidden agreements with international counterparts to share information on each others' citizens in a way that bypasses the laws and constitutions of their host nations. Secret plans that circumvent the law is pretty much the definition of conspiracy.

Google prism, xkeyscore, TAO.

Re: _NSAKEY

#92
post #90
post #36

Earlier quoted context omitted.

Nadella has just said that he would support a "don't-call-it-a-backdoor" backdoor key for the U.S. (and I assume other) government(s): https://www.theverge.com/2020/1/13/21064267/microsoft-encryp... Also, there are at least several other instances that make Microsoft highly suspicious in regards to this stuff, starting with: - how they bought Skype not long after the NSA was promising billions of dollars (in governme…

Where do you believe MS is storing all this tracking data you believe they are taking from every Windows 10 machine on the planet? Doesn't this conspiracy theory stretch belief a great deal?

The NSA has built absolutely fuck off massive datacenters in multiple places in the United States. The parent is suggesting the telemetry from Windows 10 is mostly getting passed off to the NSA

Re: _NSAKEY

#93

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

AFAIK, NSAKEY was a mechanism where the NSA could install their own cipher suites on their Windows machines, without needing to know or trust Microsoft's signing key (and vice-versa.)

DoD and IC use Suite A algorithms, which are classified. So they needed NSAKEY, or a private build of Windows that would let them do what they wanted. I think all they could do maliciously with this key is install backdoored crypto suites on victims' computers, which would require Administrator access anyway.

Disclaimer: work at MS, this is well before my time, I have no inside knowledge.

Re: _NSAKEY

#94
post #10

Earlier quoted context omitted.

Normally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.

Well, I would think so as well, but we have at least some anecdata (N=1) in the other direction [0]: > In doing this I discovered that the NSA public key had an organizational name of "MiniTruth", and a common name of "Big Brother". Specifically what I saw in my debugger late one night, which was spooky for a short moment was: O=MiniTruth CN=Big Brother [0]: http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html

That was specifically a key escrow-style system, so you're right there. Lotus Notes wanted to provide strong encryption abroad, in the bad old days of ITAR. they used a hybrid of an exportable-sized key (~50 bit encryption) and a stronger, backdoored key (MiniTruth.)

They were very public about it, though. It sucked they had to water down their encryption, but that was the reality until PGP challenged ITAR head-on.

Re: _NSAKEY

#95
post #90

Earlier quoted context omitted.

Where do you believe MS is storing all this tracking data you believe they are taking from every Windows 10 machine on the planet? Doesn't this conspiracy theory stretch belief a great deal?

The NSA has built absolutely fuck off massive datacenters in multiple places in the United States. The parent is suggesting the telemetry from Windows 10 is mostly getting passed off to the NSA

That's a nice conspiracy theory, but that doesn't make it any less absurd.

Re: _NSAKEY

#96

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

MS said: "the key ensures compliance with U.S. export laws"

"the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks"

Why not both?

Re: _NSAKEY

#97
post #70

Earlier quoted context omitted.

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

I think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)

> (likely, the NSA does as the conspiracy goes)

Pardon my pedantry but I think you meant conspiracy theory. Conspiracies happen all the time, and by itself the word doesn't imply anything far-fetched or unproven, just plotting to do harm.

Re: _NSAKEY

#98
post #96

20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.

MS said: "the key ensures compliance with U.S. export laws" "the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks" Why not both?

Because nobody has managed to demonstrate a possible attack in the past 20 years.

Re: _NSAKEY

#99
post #70

Earlier quoted context omitted.

In the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.

I think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)

Surely the NSA could just give MS the key to sign a message with and then generate a new key for themselves to replace it.

Re: _NSAKEY

#100

Earlier quoted context omitted.

Conspiracy theories tend to hinge on the idea that the conspirators are simultaneously 5-dimensional chess playing lizard people from the future and , at the end of the day, dumb as a rock.

Coincidence theories tend to hinge on the idea that everyone is incompetent and that nobody could ever collude together in secret for any sort of malicious or self interested purpose.

They hinge on the idea that the greater the value of T or N, the less likely a conspiracy will remain a secret, where T is time and N is the number of conspirators. N is usually the dominate factor.
Post reply on HN