Vista SP1 Has NSA Backdoor?


Recommended Posts

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

Just skill and talent. No magic though.

I agree that the US shouldn't hold the keys to Non-US consumers machines and any machines for that matter, but I don't think there's any way that I would allow China to have a single bit of my information, whereas I might cautiously give some personal information to the US government willingly.

And by the way I would think that this "backdoor" would be slammed shut with a hardware firewall or 2. :huh:

This is not a backdoor that would allow one to break into your computer. If somebody can predict the random numbers generated, they could decrypt information you encrypt using the random number generator. In other words: they could read any information you send over the internet (including the information you wish to keep private). A hardware firewall wouldn't change anything about that.

It is interesting to note that the NSA offer a Security Enhanced Linux distro of their own which is (1) highly secure, (2) free (of course) and (3) presumably has no backdoors (source code is freely available too, of course).

This does not of course mean that they don't have backdoors left right and centre in closed source things like Windows. :shiftyninja:

Too many tin foil hats? When the US uses razor blades on people's genitals in Guantanamo Bay I have absolutely no doubt that the NSA would do this sort of thing... whether they actually have included a backdoor is another matter.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

In terms of privacy, China's definitely not better than the US, at least not yet. At most they're about the same.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Yea I heard about that too, the new standards are pretty pathetic. Hopefully if windows does use it we'll be able to patch it to another generator.

No, it still doesn't. If you live in the EU, don't think the NSA won't make a phone call and have your PC inspected anyway. :)

They'd have to go through my country's authorities, who might either agree or politely tell them to f*ck off depending on the reasons and proof.

And then again you are just considering MY computer, government computers would obviously not be handed to the NSA no matter how kindly they ask.

So yes, it still does matter.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft's fast coding model MAI-Code-1-Flash comes to Copilot Business and Enterprise by Karthik Mudaliar Microsoft’s recently announced MAI-Code-1-Flash model is now generally available to GitHub Copilot Business and Copilot Enterprise customers. With this support, organizations can have more centralized policy controls and billing while finally being able to use Microsoft’s lightweight, first-party coding model. According to GitHub’s announcement, Business and Enterprise plan administrators must enable the MAI-Code-1-Flash policy in Copilot settings before developers can access the model. Microsoft says that MAI-Code-1-Flash is for fast, iterative coding work rather than the most demanding architectural or debugging tasks. GitHub’s official model comparison page says that the model is great for "general-purpose coding and writing," while it excels at fast, accurate code completions and explanations Microsoft introduced MAI-Code-1-Flash on June 2 as part of a broader collection of internally developed MAI models. GitHub subsequently expanded support to Copilot CLI, the Copilot cloud agent, GitHub.com chat, GitHub Mobile, Visual Studio, JetBrains IDEs, Eclipse, and Xcode, but said support for managed Business and Enterprise customers was still on the way. In Microsoft’s own benchmark testing, MAI-Code-1-Flash scored 51.2% on SWE-Bench Pro, compared with 35.2% for Anthropic’s Claude Haiku 4.5. Microsoft also claimed that the model used up to 60% fewer tokens on SWE-Bench Verified. Do note that these are vendor-run results rather than independent measurements. The model is billed at provider list pricing under GitHub’s usage-based system. GitHub currently lists MAI-Code-1-Flash at $0.75 per million input tokens, $0.075 per million cached input tokens, and $4.50 per million output tokens. For organizations, the main incentive to use MAI-Code-1-Flash is likely to be efficiency rather than maximum capability. A smaller model that responds quickly and limits unnecessary output is quite useful for repetitive agent tasks at scale, especially after GitHub Copilot’s move toward usage-based billing. The "Flash" model is recommended for fast work and not necessarily for huge repositories with loads of context. It's better if teams compare their output with other larger models, especially if they're working on security-sensitive changes and complex, multi-file work.
    • yes AND no the "original" or plain/normal Optiplex 7010 won't be getting any more new firmware updates BUT the Optiplex SFF/SFF Plus {small form factor}, Micro/Micro Plus & Tower/Tower Plus 7010 editions DO get new updates such as this new one   and here are similar guides from the Dell web site for Dell systems: https://www.dell.com/support/kbdoc/en-us/000390990/secure-boot-transition-faq https://www.dell.com/support/kbdoc/en-us/000347876/microsoft-2011-secure-boot-certificate-expiration
    • AT&T has been spying on US citizens with the NSA for decades.. they just know how to keep it more under wraps.. the evil level is still there.
  • Recent Achievements

    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      444
    2. 2
      +Edouard
      200
    3. 3
      PsYcHoKiLLa
      155
    4. 4
      FloatingFatMan
      71
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!