UK Government Wants a Backdoor Into Windows
REBloomfield writes "The BBC is reporting that the British Government is working with Microsoft in order to gain backdoor access to hard drives encrypted by the forthcoming Windows Vista file system. Professor Anderson, professor of security engineering at Cambridge University, urged the Government to contact Microsoft over fears that evidence could be lost by suspects claiming to have forgotten their encryption key."
... until the crack is published :)
(sadly this is more insightful than funny)
\u262D = \u5350
It wouldn't surprise me in the least if the US govt has had a back-door inserted into Vista. The problem for the UK govt is that clearly the US govt doesn't want to share it with them. And would the uS govt want to allow any other govt to have their own back-doors, with the potential to remotely access PCs running Vista in the US? Somehow I doubt it.
Laziness, ignorance; the same that prevents them from using encryption now.
-- Sorry, I can't think of anything funny to say here.
If governments force a backdoor to be installed, it'll be for sale to crackers before the gold masters are pressed, and common knowledge a few weeks later. So "trusted computing" can be subverted using the govt master key. And anyone who actually wants to keep secrets will install somethng that works while not requiring a magic dongle on the mobo. The govt will be able to read data from clueless suspects as they do now. So a win all round. And who doesn't suspect MS would leave backdoors anyway?
You should not be able to read the files without logging into the computer with your password and/or other identification token.
After logging in, the files are accessable. But not before. Someone who just swipes your PC would boot into Windows but would be unable to read any data files, even with a seperate boot CD. That's the whole idea.
But if the government adds a backdoor, you can bet that a hacker (white or black hat) would find it as well, probably within a few weeks of the OS being out. Thus making the encryption useless.
The whole government complaint is useless anyway because for all they know people can be using deniable encryptionn schemes *today* and they'd never even know about it.
Since when does the government have a right to all evidence in any case? One aspect of English law that I thought existed, is that the people should be protected from the government (particularly from self-incrimination). One could reasonably argue that the average citizen needs the availability of government-inaccessible encryption, due to the decreased cost (in terms of time and manpower) required to search through computer records vs. paper records. Current computers, and the massive amounts of data that they store (internet cookies, browsing history, cache data, registry entries, etc.) make fishing expeditions much, much, easier on law enforcement than sifting through physical documents and interviewing co-workers and family.
Sorry, cheap jibe.
This is amazing - especially when the idea is being promoted by a 'Professor of Security Engineering' at a reputable university. How can adding a backdoor to security systems be anything other than a massive weakness just waiting to be exploited?
Imagine if this went ahead - the British government would want access to versions of Windows sold in this country, the American government to US copies of Windows, the German government ... and so on and so on... Would Microsoft allow the Chinese government access to their citizens' disks? The Chinese government are signed-up members of The War Against Terror - so they could claim they need access, and besides recent experience says that big businesses will always accommodate governments no matter how repressive.
And it gets worse. Microsoft would either have to make a single key that would open every machine in the World; or they would have to issue copies of all the keys to every government - the British government won't accept not being allowed into a suspected terrorist's (and we have a splendidly wide definition of 'terrorist' in this country) computer purely because the suspect happens to be foreign.
But it will all supposedly remain secure and not fall into the hands of wrong-doers.
The Home Office, IT and Microsoft - what an unholy trinity we have there. With this level of stupidity the legislation can't be far off.
...the TrueCrypt binaries alone in your possession then every piece of digital media you own that appears to contain random bytes will be accused of holding an encrypted volume and they will torture out of you whatever they want to hear you say.
Oh wait, I forgot... civilized Western nations never commit torture upon their subjects.
> The point is that they might use some obscure algorithm nobody knows
But they don't (invalid point).
> They can also implement standard algorithms such as AES
Which they did.
> but were they correctly implemented?
Yes. Ever heard of test vectors? It's easy to verify if a cipher is correctly implemented using official test vector sets.
> One minor thing - NIST certification is expensive, I doubt TrueCrypt will pass it, unless some company pays for this.
Now, I bet you are the developer or seller of the commercial encryption software you mentioned. Your message basically is: "Look, without money they are worse than us. Commercial stuff is better. Free software sucks." You are just a troll.
The most important point is, however, that being open source is a _premise_ of any security software that is to be trusted by general public. Closed source security is not real security.
Sounds to me more like the good guy is making a really smart play. Note that it looks like he sort of slipped this in as an aside, since he was really giving evidence about "holding terrorist suspects without charge". Talk about pushing all the right buttons on the govt. machine.
If you are an opponent of TCG / TPM / DRM it is really quite beautiful. As far as I can see it is something like:
"Hey Mr. Government Committee, while you're asking me about terrorist suspects you might want to note that this new TPM / DRM stuff coming real soon from MS/**AA now will make it virtually impossible for you to get info off suspects' PCs. Oh, and the PCs are setup that way by default so no chance of using that fact against suspect. Also, you know that law you fought so hard for where you can jail people for not handing over encryption keys ? - well with this new stuff the key's in hardware and the suspect never has it. If you're worried by this, then maybe you should speak to these guys about crippling the tech..."
Aim big nasty government machine at big nasty corporate machine, stand well back...
Sweet.