toadeater Posted December 19, 2007 Share Posted December 19, 2007 Any thoughts about this? A US cryptographer is warning that the random number generator Microsoft is bundling with SP1 includes a backdoor exploitable by the National Security Agency.Random number generators are important because they provide the bedrock for SSL keys, which ensure secure internet communications for web browsing, email and instant messaging. Breaking the random number generator could leave user communications open to interception. Security blogger Bruce Schneier believes this is precisely what will happen to the "Dual_EC-DRBG" random number generator employed by Vista. "There are a bunch of constants - fixed numbers - in the standard used to define the algorithm's elliptic curve," he says on his blog. "These numbers have a relationship with a second, secret set of numbers that can act as a kind of skeleton key." "To put that in real terms, you only need to monitor one TLS internet encryption connection in order to crack the security of that protocol. If you know the secret numbers, you can completely break any instantiation of Dual_EC_DRBG." Schneier believes that this "secret" second set of numbers are held by the US's National Security Agency, one of the agencies which he claims championed Dual EC-DRBG as a cryptographic standard. Microsoft hadn't replied to request for comment at the time of publication. http://www.pcpro.co.uk/news/149133/vista-s...or-exploit.html Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/ Share on other sites More sharing options...
argonite Posted December 19, 2007 Share Posted December 19, 2007 This theory relies on the NSA holding the secret key, if they don't, no theory. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072709 Share on other sites More sharing options...
toadeater Posted December 19, 2007 Author Share Posted December 19, 2007 This theory relies on the NSA holding the secret key, if they don't, no theory. AT&T once said they weren't spying for the NSA, until they were forced to admit that they were. This one is going to be a lot harder to prove, or disprove I guess. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072722 Share on other sites More sharing options...
Argi Posted December 19, 2007 Share Posted December 19, 2007 Still, it'd be stupid for anyone (especially Microsoft of all companies) to knowlingly use an RNG algorithm that contains what looks like a backdoor unless they either didn't know or it's intended. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072747 Share on other sites More sharing options...
SirEvan Posted December 19, 2007 Share Posted December 19, 2007 I dont know much about cryptography or such, but...couldn't you null-and-void this problem by running a program on your system like peer guardian or something to block any connections to your machine from known ips such as the NSA? Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072751 Share on other sites More sharing options...
Argi Posted December 19, 2007 Share Posted December 19, 2007 I dont know much about cryptography or such, but...couldn't you null-and-void this problem by running a program on your system like peer guardian or something to block any connections to your machine from known ips such as the NSA? That's not really the point. ?Apart from the fact that if the NSA wants in your computer PeerGuardian wont save you, if a backdoor exists it's only a matter of time before someone with malicious intent cracks it. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072779 Share on other sites More sharing options...
Chicane-UK Veteran Posted December 19, 2007 Veteran Share Posted December 19, 2007 I wish they wouldn't pull crap like this :| Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072785 Share on other sites More sharing options...
Deathray Posted December 19, 2007 Share Posted December 19, 2007 I wish they wouldn't pull crap like this :| Most major corporations probably do this... you'll just never hear about it unless you're lucky Plus, it's the NSA... I'm pretty sure they could find a way around our security Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072788 Share on other sites More sharing options...
Miuku. Posted December 19, 2007 Share Posted December 19, 2007 Plus, it's the NSA... I'm pretty sure they could find a way around our security Unlikely - they wouldn't be trying to go all out on cracking down on businesses developing high end security products (such as extremely high end encryption) and threatening them to sneak in backdoors if they could just "crack it all". It's also not that easy to operate in foreign countries, no matter what movies tell you. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072956 Share on other sites More sharing options...
zhangm Supervisor Posted December 19, 2007 Supervisor Share Posted December 19, 2007 Here's the original source. The followup articles are more speculative. BTW, its not that Microsoft is specifically complying or collaborating with the NSA. Its more that the US government is releasing this as one of four encryption standards... http://www.wired.com/print/politics/securi...itymatters_1115 Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589072970 Share on other sites More sharing options...
hagjohn Posted December 19, 2007 Share Posted December 19, 2007 wouldn't surprise me. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073461 Share on other sites More sharing options...
seta-san Posted December 19, 2007 Share Posted December 19, 2007 lets keep in mind Microsoft chose to do this. This standard was one of many that were filed with the standards community. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073474 Share on other sites More sharing options...
Evolution Posted December 19, 2007 Share Posted December 19, 2007 Doubt it.... any backdoor that exists could be turned around and used by hackers :/ Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073488 Share on other sites More sharing options...
BigBoy Posted December 19, 2007 Share Posted December 19, 2007 Someone ordered too many tin foil hats. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073499 Share on other sites More sharing options...
neufuse Veteran Posted December 19, 2007 Veteran Share Posted December 19, 2007 So what? Apple probably gives their keys over to the NSA also... just no one has taken the time to figure out if it has or hasn't.. I kinda think anything that is a "major" OS the NSA tries to coax the maker into helping them Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073503 Share on other sites More sharing options...
Farchord Posted December 19, 2007 Share Posted December 19, 2007 You can tighten a lock all you want, it will never make it 100% secure. It's a bit like mathematics. You can divide '1' by '2' as much as you want, you will never reach '0', you will always end up with more and more decimals. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073549 Share on other sites More sharing options...
Eric Veteran Posted December 19, 2007 Veteran Share Posted December 19, 2007 While I can't dismiss this as FUD, I can say it doesn't matter. If the NSA really wants to know what's on your computer, they'll either come in your house and look when you're not there or they'll seize it directly and examine it. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589073667 Share on other sites More sharing options...
ichi Posted December 19, 2007 Share Posted December 19, 2007 While I can't dismiss this as FUD, I can say it doesn't matter. If the NSA really wants to know what's on your computer, they'll either come in your house and look when you're not there or they'll seize it directly and examine it. The NSA is an USA agency (or whatever) while Windows is distributed worldwide. Does it really still not matter? Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074200 Share on other sites More sharing options...
Pippin666 Posted December 19, 2007 Share Posted December 19, 2007 That's not really the point. ?Apart from the fact that if the NSA wants in your computer PeerGuardian wont save you, if a backdoor existsit's only a matter of time before someone with malicious intent cracks it.>That's why backdoor are bullcrap stories.Pip' Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074251 Share on other sites More sharing options...
raskren Posted December 19, 2007 Share Posted December 19, 2007 The NSA have a backdoor in Windows XP, SP1, SP2, SP3 as well. And Windows 2000, SP1, SP2, SP3, SP4. And Vista, and Vista SP1. Do you see how the same bull**** theory keeps getting reiterated over and over again? Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074263 Share on other sites More sharing options...
xendrome Posted December 19, 2007 Share Posted December 19, 2007 Yea the NSA has a backdoor in every piece of software.... It's called a Federal Search Warrant... Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074267 Share on other sites More sharing options...
JonathanVP Posted December 19, 2007 Share Posted December 19, 2007 it is true...the NSA can get into your computer anytime they want and download all your pr0n Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074281 Share on other sites More sharing options...
Impact Posted December 19, 2007 Share Posted December 19, 2007 This is old news. The same article from wired was posted like 3 weeks ago. Also, why is this news? Its been like this for every major Windows release. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074299 Share on other sites More sharing options...
theyarecomingforyou Posted December 19, 2007 Share Posted December 19, 2007 Also, why is this news? Its been like this for every major Windows release. Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies. Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074329 Share on other sites More sharing options...
neufuse Veteran Posted December 19, 2007 Veteran Share Posted December 19, 2007 Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies. What do you mean for especially not for non-us citizens... thats the whole point of the NSA :whistle: Link to comment https://www.neowin.net/forum/topic/607936-vista-sp1-has-nsa-backdoor/#findComment-589074526 Share on other sites More sharing options...
Recommended Posts