Vista SP1 Has NSA Backdoor?


Recommended Posts

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

Just skill and talent. No magic though.

I agree that the US shouldn't hold the keys to Non-US consumers machines and any machines for that matter, but I don't think there's any way that I would allow China to have a single bit of my information, whereas I might cautiously give some personal information to the US government willingly.

And by the way I would think that this "backdoor" would be slammed shut with a hardware firewall or 2. :huh:

This is not a backdoor that would allow one to break into your computer. If somebody can predict the random numbers generated, they could decrypt information you encrypt using the random number generator. In other words: they could read any information you send over the internet (including the information you wish to keep private). A hardware firewall wouldn't change anything about that.

It is interesting to note that the NSA offer a Security Enhanced Linux distro of their own which is (1) highly secure, (2) free (of course) and (3) presumably has no backdoors (source code is freely available too, of course).

This does not of course mean that they don't have backdoors left right and centre in closed source things like Windows. :shiftyninja:

Too many tin foil hats? When the US uses razor blades on people's genitals in Guantanamo Bay I have absolutely no doubt that the NSA would do this sort of thing... whether they actually have included a backdoor is another matter.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

In terms of privacy, China's definitely not better than the US, at least not yet. At most they're about the same.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Yea I heard about that too, the new standards are pretty pathetic. Hopefully if windows does use it we'll be able to patch it to another generator.

No, it still doesn't. If you live in the EU, don't think the NSA won't make a phone call and have your PC inspected anyway. :)

They'd have to go through my country's authorities, who might either agree or politely tell them to f*ck off depending on the reasons and proof.

And then again you are just considering MY computer, government computers would obviously not be handed to the NSA no matter how kindly they ask.

So yes, it still does matter.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Google's new hand-wave reCAPTCHA can be bypassed with a stock photo by Ivan Jenic Image: Screenshot Google is testing a new reCAPTCHA method that asks you to wave at your camera to prove you're human. So, besides solving puzzles and reading distorted text, you can now use your computer’s camera to pass the verification test. When the hand gesture verification is triggered, your browser asks for camera access and prompts you to perform a simple gesture, like a wave or an open palm. Google says it records a short video of the movement and uses AI to extract 21 hand-knuckle coordinates to complete the verification process. The video is then immediately deleted, and Google swears it doesn't keep it. The process alone can be uncomfortable for people who wouldn’t want their biometric data, which hand scans technically qualify as, recorded. But it gets even more nuanced, as early testers discovered that the new hand-waving reCAPTCHA can be passed with a simple stock image. A user on X tested the new challenge using a stock image of a hand fed through OBS Virtual Camera, and it passed. I wanted to verify it, so I tried the same thing. It took me a few tries and a few stock images, but in the end, I was also able to pass the test. I simply had to readjust the stock image of a generic person waving inside OBS, and Google’s mechanism registered it as a legitimate hand gesture. Once again, it didn’t even have to be a video or an AI-generated hand animation. Given the simplicity of the process, the entire action can be automated in minutes. All it takes is a simple Python script to render the new reCAPTCHA method obsolete. And it doesn’t even have to be an AI bot, which is usually used for solving puzzles and other verification methods. The new reCAPTCHA method is still in its early phase, and Google will, hopefully, update its AI to at least reject still images. However, this incident, combined with users’ initial skepticism about Google’s practices regarding user data, likely won’t make too many people wave at the camera anytime soon.
    • 🤣🤣🤣🤣🤣 "to fund healthcare and tuition" 🤣🤣🤣🤣 Who do you think you are talking about, some COMMUNIST? We are better than them, doG bless Murica!!! p.s. I'm from a country where government does exactly that, i.e. not form US.
    • Apparently not. I know it is on Edge for business at the moment, but how long will it be before it become on the home version of Edge?
    • Microsoft details new Edge for Business security features, including AI-powered scareware detection So Edge is adding a "scarecrow." Will it be animated?
    • I have this one and it's great, also paired with a Mac. I like the white back aesthetics of it and ability to have all your wireless usb peripherals under a clean lid. 4K @ 120 Hz and 65W usb-c charging is not bad even at its typical price point. The U series is probably better for commercial photo work though; IIRC one reason this one is priced in a different bracket is because it's not calibrated and verified for optimal color accuracy. Not something I think of in daily use, coding, and light gaming though.
  • Recent Achievements

    • Apprentice
      Asgardi went up a rank
      Apprentice
    • One Month Later
      sunrisea2milk earned a badge
      One Month Later
    • Week One Done
      sunrisea2milk earned a badge
      Week One Done
    • Week One Done
      Snow Day Calculator Alert earned a badge
      Week One Done
    • Conversation Starter
      KMilenkoski1202 earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      495
    2. 2
      +Edouard
      251
    3. 3
      PsYcHoKiLLa
      154
    4. 4
      Steven P.
      86
    5. 5
      macoman
      65
  • Tell a friend

    Love Neowin? Tell a friend!