Vista SP1 Has NSA Backdoor?


Recommended Posts

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

Just skill and talent. No magic though.

I agree that the US shouldn't hold the keys to Non-US consumers machines and any machines for that matter, but I don't think there's any way that I would allow China to have a single bit of my information, whereas I might cautiously give some personal information to the US government willingly.

And by the way I would think that this "backdoor" would be slammed shut with a hardware firewall or 2. :huh:

This is not a backdoor that would allow one to break into your computer. If somebody can predict the random numbers generated, they could decrypt information you encrypt using the random number generator. In other words: they could read any information you send over the internet (including the information you wish to keep private). A hardware firewall wouldn't change anything about that.

It is interesting to note that the NSA offer a Security Enhanced Linux distro of their own which is (1) highly secure, (2) free (of course) and (3) presumably has no backdoors (source code is freely available too, of course).

This does not of course mean that they don't have backdoors left right and centre in closed source things like Windows. :shiftyninja:

Too many tin foil hats? When the US uses razor blades on people's genitals in Guantanamo Bay I have absolutely no doubt that the NSA would do this sort of thing... whether they actually have included a backdoor is another matter.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Because the NSA should have no special ability to get into systems, especially for non-US citizens. If this is true then it's yet another case of the US thinking it is superior to the rest of the world. I have more faith in China having access to my personal information than I do the US, which only goes to show how poorly I rate the US government / government agencies.

In terms of privacy, China's definitely not better than the US, at least not yet. At most they're about the same.

This isn't a Vista issue, it's an issue with the elliptic curve standard. This story came out, minus the sensationalism, months ago

Also, this isn't an issue about Microsoft (or anybody else) giving "keys" to the NSA. It's a random number generator, so it's not supposed to even have a key. The issue is that the NSA might have changed the elliptic curve referenced in the name in order to make it more predictable and easier to crack.

Yea I heard about that too, the new standards are pretty pathetic. Hopefully if windows does use it we'll be able to patch it to another generator.

No, it still doesn't. If you live in the EU, don't think the NSA won't make a phone call and have your PC inspected anyway. :)

They'd have to go through my country's authorities, who might either agree or politely tell them to f*ck off depending on the reasons and proof.

And then again you are just considering MY computer, government computers would obviously not be handed to the NSA no matter how kindly they ask.

So yes, it still does matter.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Lego Batman 2026 hahahaha. You thought I couldn't reply back???
    • The problem isn't with Epic, it's with the platform holders like Steam and Nintendo, they should be a lot more strict in their review process.
    • Hello, Installed here without issue. Regards, Aryeh Goretsky
    • Microsoft updates Visual Studio Code with easier language model discovery and in-app search by Paul Hill Microsoft has released Visual Studio Code 1.125, its latest weekly release. This week, the company has focused on discovering and installing extra language models via the Marketplace; searching the web and securely browsing over remote connections without leaving VS Code; choosing how long VS Code waits before installing extension updates; and delivering managed Copilot settings through existing device management tooling. In older versions of VS Code, extensions could contribute their own model providers, but to find these extensions, you needed the right tags to search for in the Extension view. Now, the Language Models editor gives you an Install Model Providers button that opens the Extensions view, which is filtered to extensions that contribute model providers, making it easier to find and install them. Once you install a provider, its model will appear in the model picker. If you use the integrated browser much, you can now look up information without leaving VS Code by typing a query into the integrated browser’s address bar. It will use your configured search engine, the same way a standalone browser does. You can use workbench.browser.searchEngine to pick a search engine. When the browser is opened in a remote workspace, it's now possible to proxy HTTP(S) traffic via the remote connection. This allows you to connect to any ports or services that can only be accessed from the remote machine. If you read our coverage from two weeks ago about VS Code 1.123, you might have seen that extension updates have a two-hour delay as a safety measure. In this update, Microsoft is giving you the ability to configure the time of the delay. You can find it under extensions.autoUpdateDelay. Finally, with this update, admins can deliver managed GitHub Copilot settings through native device management (MDM) channels on Windows and macOS, in addition to account-based enterprise settings files. Settings delivered via MDM appear as policy-enforced in VS Code and can’t be overridden locally. Future updates will extend the supported policy keys across Copilot surfaces. You can download the update from the Visual Studio Code website now.
  • Recent Achievements

    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      543
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      82
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!