Vista SP1 Has NSA Backdoor?


Recommended Posts

Any thoughts about this?

A US cryptographer is warning that the random number generator Microsoft is bundling with SP1 includes a backdoor exploitable by the National Security Agency.

Random number generators are important because they provide the bedrock for SSL keys, which ensure secure internet communications for web browsing, email and instant messaging. Breaking the random number generator could leave user communications open to interception.

Security blogger Bruce Schneier believes this is precisely what will happen to the

"Dual_EC-DRBG" random number generator employed by Vista.

"There are a bunch of constants - fixed numbers - in the standard used to define the algorithm's elliptic curve," he says on his blog.

"These numbers have a relationship with a second, secret set of numbers that can act as a kind of skeleton key."

"To put that in real terms, you only need to monitor one TLS internet encryption connection in order to crack the security of that protocol. If you know the secret numbers, you can completely break any instantiation of Dual_EC_DRBG."

Schneier believes that this "secret" second set of numbers are held by the US's National Security Agency, one of the agencies which he claims championed Dual EC-DRBG as a cryptographic standard.

Microsoft hadn't replied to request for comment at the time of publication.

http://www.pcpro.co.uk/news/149133/vista-s...or-exploit.html

Link to comment
https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/
Share on other sites

I dont know much about cryptography or such, but...couldn't you null-and-void this problem by running a program on your system like peer guardian or something to block any connections to your machine from known ips such as the NSA?

I dont know much about cryptography or such, but...couldn't you null-and-void this problem by running a program on your system like peer guardian or something to block any connections to your machine from known ips such as the NSA?

That's not really the point. ?Apart from the fact that if the NSA wants in your computer PeerGuardian wont save you, if a backdoor exists it's only a matter of time before someone with malicious intent cracks it.

Plus, it's the NSA... I'm pretty sure they could find a way around our security

Unlikely - they wouldn't be trying to go all out on cracking down on businesses developing high end security products (such as extremely high end encryption) and threatening them to sneak in backdoors if they could just "crack it all".

It's also not that easy to operate in foreign countries, no matter what movies tell you.

Here's the original source. The followup articles are more speculative. BTW, its not that Microsoft is specifically complying or collaborating with the NSA. Its more that the US government is releasing this as one of four encryption standards...

http://www.wired.com/print/politics/securi...itymatters_1115

You can tighten a lock all you want, it will never make it 100% secure.

It's a bit like mathematics. You can divide '1' by '2' as much as you want, you will never reach '0', you will always end up with more and more decimals.

While I can't dismiss this as FUD, I can say it doesn't matter. If the NSA really wants to know what's on your computer, they'll either come in your house and look when you're not there or they'll seize it directly and examine it.

The NSA is an USA agency (or whatever) while Windows is distributed worldwide. Does it really still not matter?

That's not really the point. ?Apart from the fact that if the NSA wants in your computer PeerGuardian wont save you, if a backdoor existsit's only a matter of time before someone with malicious intent cracks it.>
That's why backdoor are bullcrap stories.

Pip'

Also, why is this news? Its been like this for every major Windows release.

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

What do you mean for especially not for non-us citizens... thats the whole point of the NSA :whistle:

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Password Safe 3.72.0 by Razvan Serea Password Safe is a password database utility. Like many other such products, commercial and otherwise, it stores your passwords in an encrypted file, allowing you to remember only one password (the "safe combination"), instead of all the username/password combinations that you use. Once stored, your user names and passwords are just a few clicks away. Using Password Safe you can organize your passwords using your own customizable references—for example, by user ID, category, web site, or location. You can choose to store all your passwords in a single encrypted master password list (an encrypted password database), or use multiple databases to further organize your passwords (work and home, for example). And with its intuitive interface you will be up and running in minutes. PasswordSafe was originally designed by the renowned security technologist Bruce Schneier and released as a free utility application. Password Safe 3.72.0 changelog: Fixed bugs Improved font scale handling - should resolve font size issues on high resolution displays. GH1749 In the Master Password Setup window, "Show Master Password" is no longer truncated on some displays. GH1092, SF1595 Size and position of main window is now correctly restored on scaled displays. SF1630 Keep password expiry date when both password and password expiry are changed; don't clear a non-recurring expiry when the password's changed. SF1628 Custom values can now be copied to the clipboard in read-only mode via Ctrl-C and right-click->Copy Value. New features GH1196 Dark display mode support: Password Safe now supports the system display mode, as well as setting the mode directly via Manage->Options->Display->Display Mode. This change also updates the general "look & feel" of the app to the current Windows theme. Known limitations: The Date picker and keyboard shortcut controls do not switch to dark theme The Customize Toolbar dialog does not switch to dark theme Custom Field support has been added to the more advanced features: Filters XML and Text import and export Comparison, Sync and Merge databases SF938 Custom field values may now be selected by name and copied via a "Copy Custom Field Value..." submenu in the entry context popup menu. SF936 Notes and Custom fields layout now overlap, selectable by tabs, resulting in a more compact and less cluttered layout. SF935 Autotype: Specifying '\v{name}' in the autotype text will cause the corresponding value to be autotyped. Download: PasswordSafe 64-bit | Portable 64-bit | ~20.0 MB (Open Source) Download: PasswordSafe 32-bit | Portable 32-bit View: PasswordSafe Website | Quickstart Guide | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Google DeepMind published a document on June 18, 2026, that may be the most consequential admission yet from a frontier AI lab: alignment training alone cannot guarantee that AI agents will remain under human control, so structural containment must be built before more capable models arrive.............. https://www.techtimes.com/articles/318758/20260620/google-deepmind-ai-control-roadmap-when-alignment-fails-defense-depth-takes-over.htm  
    • I've got a SoundBlasterX G6 that I use in my streaming setup. Sounds great to me and I've had zero issues with the ancient software package so far in Win11. That G6 has 7.1, Dolby, fully working SPDIF and since it's a USB device it's outside of my rig so I don't have to worry about EMF distortion. Looks like for now this is a pass for me as I think I have better hardware....
    • How do you connect 5.1 Speakers to this thing?
    • I agree with both of you... It's absolutely imperative that science is completely based on actual proven facts and hard evidence and is not considered dogmatic in any way. Science is not a religion and it will never be, and that's exactly how it's supposed to be.
  • Recent Achievements

    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      503
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      88
    4. 4
      Steven P.
      75
    5. 5
      Michael Scrip
      74
  • Tell a friend

    Love Neowin? Tell a friend!