New Vista Random Numbers to Include NSA Backdoor?
Schneier is reporting that Microsoft has added the new Dual_EC-DRBG random-number generator to Vista SP1. This random-number generator is the same one discussed earlier that may have a secret NSA backdoor built into it.
I guess it's not so secret then, is it?
"I'm just here to regulate funkiness."
Wouldn't this go under "Your Rights Online"?
why does the shashdot "The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way. " seem so approperiate for this....
'...if only "Jumping to a Conclusion" was an event in the Olympics.'
"that may have a secret NSA backdoor built into it"
Now begin being paranoid rant about how U.S. is a fascist state and how Vista is the new 'evil'
Rinse, wash, repeat....
To regale us with the myriad ways in which government plots are about to unfold with this. But sincerely, this is ripe for negative speculation. There is no good reason for something of this nature. Sure, some will say it's for the kids and what about the terrorists being thwarted before they can act and all, but I still say this is BS. Closed source buffoonary if you ask me.
My humor is probably your flamebait
This one "feature" should absolutely put them out of business. Trusted computing indeed!
"It's not enabled by default, and my advice is to never enable it. Ever."
Nothing for you to see here. Please move along.
Cretin - a powerful and flexible CD reencoder
Given the known problems of Dual_EC_DRBG, which, from the Bruce Schneier article, include the fact that's slow, that it's got an obvious backdoor, and that it was inexplicably pushed for the NSA for seemingly no reason, why would Microsoft add it to Vista SP1?
Now adding the algorithm itself isn't really a backdoor per se, because no one is forcing you to use that particular random number generator. But it is also interesting to note that this isn't the first time Microsoft has been accused of inserting backdoors for the CIA or the NSA. Of course, Microsoft vehemently denies such allegations, but I would assume that they would. Given what the telcos did for the NSA, would anyone be surprised if it really did come out that the NSA actually forced Microsoft to put backdoors in Office or Windows?
My blog
I worry more about the 0-day backdoors in Vista than I do about the NSA backdoors.
No folly is more costly than the folly of intolerant idealism. - Winston Churchill
Boy, this is getting tiring.
You're concerned about security, and you're using WINDOWS VISTA???
"It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
Are they touting is as secure? Do they mention the NSA backdoor? Do they have a response to it?
Some US government agencies REQUIRE the ability to use this PRNG algorithm, so anyone who wants to sell a product to those agencies (IBM? RedHat? Sun?) is going to have to provide that algorithm.
And, this algorithm is NOT the default.
So... ??? This article is simple FUD.
i seeded the dual_EC-DRBG with the following ASCII strings the and got the following output in ASCII:
missionaccomplished -> LOL
waterboard -> buckshottotheface
osamabinladen -> loofahnotfalafel
iraq -> vietnam
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
No surprise, really. After all, Microsoft did this a long time ago (remember the whole "NSA KEY" fiasco?)
http://en.wikipedia.org/wiki/NSAKEY
Is this "feature" back-ported to XP SP3, too?
SP3 is supposed to have some of Vista's most useful features as well as all previous bug fixes.
Would a shame to ruin a good service pack that speeds up XP by 10%.
Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
I implemented this on my Linux box. Does this mean that all of Linux now has a back door too?
Slashdots anti-Microsoft alarmist bullshit is so boring.
I see what you did there. You implied that anyone who criticizes the US or Vista is a paranoid loony. Now why would you do that? Do you just assume that people will criticize the US? Is the US that worthy of criticism that you have to defend it preemptively? I know that's a popular tactic these days, but is it entirely necessary? Nice how you posted AC, too. You sir are an all-around class act.
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
... can't they just include their own list of secret numbers in order for the generator to be semi-secure? The NSA has the numbers that generate the random numbers in the base code but even they say to make your own reference numbers if you are to use the code. So if Microsoft were to ultimately use the numbers the numbers would probably end up being both random and not known to anyone in the development team if they so wanted.
So . . .
I sat naked on the bench in the health club locker room, staring at the tiles on the floor between my feet, but really looking at nothing. I was waiting for Jamal to decide to come up and talk to me. He was this muscular teenage nigger who frequented the club and had ruined my life in the last few weeks. I was ordered to sit naked on the bench without a towel or anything to cover my nakedness. I had to keep my legs spread and my cock and balls visible for the anyone In the locker room who wanted a look. I knew instantly that it had been a mistake to sign up at the inner city health club which was eighty percent black, but It was near my house and cheap which was even more important.
The harassment had started on my first visit. Dark skinned, muscular black boys bouncing around the locker room with their huge dicks and pendulous sacks of balls swinging, high fiving each other and laughing and rapping, and there I was, this moderately built white guy of thirty two.
I will never forget coming back from the shower and one chocolate skinned thug of about eighteen let out a "weeeeeeeow" kind of sound and then said very loudly to me, loudly enough for all his pals to hear, "White man, how the hell can you fuck wit such a small dick?" They all roared with laughter and I turned bright red. Before I left that first time, I med Jamal. He eased up to me while I was packing my gym bag. He is one good looking darkie, I will say that for him. He flashed me a big white toothed smile and said he hoped I wasn't thinking of quitting the club. He said he was friends with the manager and they had my address and shit, and it would be really unfortunate if I decided to quit. Then he laid one large basketball player sized hand on my shoulder and said that he would see me at the same time the next day.
Well, that's how it started. It got worse each time I went to the club. Jamal and the other niggers got me to get towels for them, had me scrub their backs in the shower, even made me pick their dirty stinking jock straps up off the floor. They sent their filthy jocks and socks home with me to wash for them.
Now let me state here once and for all, that I am in no way at all gay. I don't think I ever even had a gay thought. So all of this really repulsed me. They would brush up against me so their big fat black dicks rubbed my body. They would make constant jokes about me being a faggot.
So I had it out with Jamal. I told him I was married and in no way gay, and I wanted to quit the club. That mention of my wife was the biggest mistake of my life. Jamal demanded to see a photo of her. Her name is Kathleen. After that, all they talked about was "Kathleen the Cunt" in the locker room.
"Da mailman probably shoving his dick in her right now while you is at da club." They would say things like that. Jamal would ask, "Do you suppose she ever took black dick up the ass?" I told them she didn't like anal, and they should keep their foul mouths to themselves. They beat the shit out of me.
I didn't go to the club for a week. All the windows were broken on my car, and my newspaper was stolen, and somebody pissed all over our door. I received a package at work, and when I opened it, there was a pile of shit in a box. I was going nuts with anguish. I thought of going to the police, but I knew I would face even worse if I did. So I went back to the club. That was two months ago. A lot had happened in those two months.
Now I sat waiting for Jamal to speak with me. He walked up, stark naked. The first thing I saw were his huge brown feet next to me. I looked up at his long muscular legs. How could I miss the seven inch flaccid dick, thick as a flashlight and the ball sack that looked like it had oranges in it. It was fucking obscene. His stomach was hard and tight. His ass was one of those round tight nigger bubble butts. His chest well defined with large nipples. He had a killer smile, thick nigger lips, and dark flashing eyes that often looked drugged. He had only recently gotten out of refo
...does every article about Vista make me less likely to ever use it? Aren't things like this supposed to _improve_ with time?
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
So, let's review:
1. Government introduces a new cryptography standard (which it will presumably require for some applications) that requires that systems provide a choice of 4 random number generators, one of which MAY have a flaw.
2. Manufacturers implement the new standard.
3. Grand conspiracy!!!
Come on, could it just possibly be that Microsoft wants to be able to claim to be NIST 800-90 compliant for customers who want that kind of thing and that the NSA likes the idea of there being a variety of random number generators available? The only way that making this function available is a risk is the NSA also has control of the application and can force it to call this random number generator without properly seeding it. If they have that level of control, they have enough control to do whatever else they want in a much more direct way.
I like my beverages with warning labels!
I'm 24 years old. I don't want to go through the next 50 years of my life living in an international air of worry and uncertainty. I don't want to live in a permanent state of fear, generated by a megalomaniacal American government taking advantage of the majority low IQ populous' capacity for being brainwashed.
I don't want to live like Israel, fighting militant Muslims round every corner. The problem of Muslim extremists exists and needs to be dealt with, not encouraged by invading innocent countries and waging war on people who have done nothing to deserve it. I want my children to grow up in a world free from military oppression and I want a government that understands that the wars of the future are guerrilla ones which can never be won, even if they are waged for noble purposes (which theirs never are).
The world is fucked up enough as it is. The food chain has been poisoned so badly the average human is full of chemicals normally found in plastics and toxic waste. I'm sick of global warning and environmental damage to the planet and the fact the all this time the greenies were right. I'm sick of America being the biggest wilful contributor to the pollution of the planet.
I'm sick of an American school system that produces children who are brought up to believe that America IS the world and anything that goes on outside is irrelevant. Children so stupid they think America invented the Internet, computer, motor car, light bulb, telephone etc ad infinitum....
The Internet or it's successor is the future of entertainment and I'm sick of stupid low IQ, ignorant Americans infecting every corner of it with their insular, jingoistic mindsets, their whiny voices and manifestations of their low self esteem driven by the fact that despite it being their turn as the world's super power, no one actually takes them seriously or gives them the respect that the British or the Ancient Greeks got because a superpower best known for producing mass produced crap is never going to get the respect that one who gave the world Shakespeare, culture, philosophy or mathematics will get.
I'm sick of hypocrisy and two facedness. I'm sick of Gangsta Rap and hamburgers, Political Correctness and TV programmes that begin with 'When' and end in 'go bad and attack people'. I'm sick of reality TV and I'm sick of news programmes that are more censored than accurate. I'm sick of tokens, token minorities, token universities, token degrees, token attempts at the truth, tokens. I'm sick of fat people, ugly people, stupid people, gay people, coloured people, female people, whiny people all complaining they don't have the opportunities in life they would like and it must be someone else's fault. I'm sick of women that act like men and femininity being a crime, unless you're a man in which case you're a new man which nobody ever wanted because there was nothing wrong with the old one. I'm sick of people falling over and suing the ground and people watching nipples and suing the TV and I'm sick of coffee cups with 'don't pour over yourself, you may get burnt' on the side to try and counter this.
I'm sick of stupid Americans who don't know the difference between patriotism and jingoism and who think flag waving should be an Olympic event. I'm sick of Americans who cry that people hate them or are jealous of them or who are anti them because someone dares to point out that the America they've been programmed to believe in from birth bears no relation to the one that exists in real life.
What kind of commie doesn't just trust the NSA? I mean, we've got a FISA to protect us from the government and from corporations cooperating with rogue regimes, right?
--
make install -not war
You may not find it particularly funny, but offtopic it isn't.
I assume by not putting in any category, the editors get to bypass a users filtration by preferences selections.
I disagree.
This has absolutely nothing to do with open or closed source. A completely open source random number generator would have precisely the same vulnerability, because the problem isn't potential skulduggery by the vendor, it's potential skulduggery by the people who designed the standard.
What Microsoft has done is to implement a questionable standard. It makes no sense in this case to blame them for its shortcomings, especially since developers have alternative standards they can use.
Now when it comes to application software using a random number generator, then there actually is a closed/open source argument to be made. Do you know which random number generator is used by the software you use? With closed source, almost certainly not. With open source, programmers can undo the choice of the dodgy elliptic curve RNG and replace it with a more solid, equally standards compliance alternative. And get a speed boost too. You also know that you might not want to trust the source for your software if they use the inferior algorithm.
Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
My understanding is that you need 32 bytes of consecutive output.
Why not populate a buffer with the PRNG output.
Create an index to the end of the buffer. (Assuming an array)
Then.
Use as output the byte at this index value.
Decrement the index by one.
Subtract the byte value at the index, from the index value.
Use the byte value at the index as the second output value.
Keep doing this stepping backwards through the buffer in this manner, when you role off the start of the buffer repopulate the buffer with new random data.
Set the index value for the repopulated buffer to the buffers length minus the absolute value of the currently negative index.
Or simply add the buffers length the index.
Have fun.
Maybe the NSA could have thought a little harder at entering a back door code. Secret sources have revealed the NSA back door code to be.
up, up, down, down, left, right, left, right, B, A
..........FULL STOP.
Just as it is untrue that the US used printers (small 68000 series computers) to disrupt the Iraqi networks and sniff traffic, and they are not diverting telephone cable Net traffic at the main connection sites in San Francisco and other locations.
And, I never was in the shack at Yakima, and we never listened to your long-distance phone calls and made fun of you going kissy-kissy with your wife overseas.
Really.
Pay no attention to the curtain, nothing is behind it. Really. And get that dog away from it!
-- Tigger warning: This post may contain tiggers! --
finally, Microsoft is taking it in the backdoor - about freaking time.
ReaLemon is yummy
I hope the NSA thought to put a screen door on their backdoor, what with all the bees in the internet
The NSA touched my junk liberally. They strapped me into a NSAmobile and they couldn't stop exploiting my backdoor. They were performing many red flag touches. I couldnt believe what the fuck was going on. I told Lieutenant General Keith B. Alexander the country would not approve of an intelligence agency touching an underage kid for free. Can you believe it? Lieutenant General Keith B. Alexander did all this. He picked me off the street, strapped my arms and legs down in the NSAmobile's passenger seat, and just wouldn't stop fondling my cock'n'balls.
They definately were red flag touches. The goddamn referee he had in the back seat kept on raising up this red flag every time he touched my junk but did Lieutenant General Keith B. Alexander care? NO WAY! Hejust kept on doing it. I couldn't believe what the fuckwas going on, indeed. I pleaded with Lieutenant General Keith B. Alexander but to no avail. I told him the country would not approve of such a wealthy man touching an underage kid like me (at the time I was 13) without at least compensating me for
the trauma and the use of my body as his own personal plaything.
This got to him, worrying about his image. He continued to fondle me, all the while ignoring the referee's red flags. Then he drove the NSAmobile to my house and ejected the seat I was in! It was amazing. But surprisingly, after I woke up the next morning, my bank account had $150k in it!!! Can you believe it?
...because this one seems too obvious. So, perhaps the NSA crypto folks have a couple of found back doors in some of the other algorithms, and this is a bit of misdirection to keep people from noticing what they really intend to use... :)
Have any expectation of privacy or security in the first place?
IIRC, some of the key SCOTUS decisions regarding the Fourth Amendment have centered around a person's expectation of privacy. They've argued:
That said, the government could persuasively argue that someone who runs Windows, especially Vista, has no expectation of privacy in the first place:
Now the sad thing is that this does come across as a troll, but sadly, it's true. And it needs to be addressed. For some reason, the /. crowd thinks it is acceptable that a majority of the population uses an OS which is horribly less secure than the ones we ourselves use (Linux, Macs, etc...). We're supposed to be the technical ones who have the solution to these problems, and yet, most /.ers just choose to blame the victim and whine about Microsoft being evil. Granted, we already know that.
Is it really acceptable that our collective rights are surrendered because a major corporation finds more profit in insufficient design and testing of its software? I realize that most of you loathe Windows, but unless we actually do something to fix the social barriers to the adoption of Linux, we can expect that, because Windows is so insecure, our government will be able to convince SCOTUS that a computer user has no "reasonable expectation of privacy".
It doesn't matter so much that this PRNG is insecure. A knowledgeable cryptographer isn't going to trust the OS for random numbers, anyway - unless it is in compliance with some standard to which their code must comply. What matters is that Vista is full of holes, and we're talking about a PRNG which no software of cryptographical consequence is going to use anyway.
Instead, we ought to worry that Windows itself is easily compromised by the government. That is the real problem. Why would you break the PRNG when you can rootkit even a fully patched Vista box with an email?.
The society for a thought-free internet welcomes you.
Supporting Information from Original Author:
|Cryptanalytic Attacks on Pseudorandom Number Generators
J. Kelsey, B. Schneier, D. Wagner, and C. Hall
Fast Software Encryption, Fifth International Workshop Proceedings (March 1998), Springer-Verlag, 1998, pp. 168-188.
ABSTRACT: In this paper we discuss PRNGs: the mechanisms used by real-world secure systems to generate cryptographic keys, initialization vectors, "random" nonces, and other values assumed to be random. We argue that PRNGs are their own unique type of cryptographic primitive, and should be analyzed as such. We propose a model for PRNGs, discuss possible attacks against this model, and demonstrate the applicability of this model (and our attacks) to four real-world PRNGs. We close with a discussion of lessons learned about PRNG design and use, and a few open questions. | http://www.schneier.com/paper-prngs.html
If you have been keeping up with computer security, everyone should be aware of the weakness of Random Number generators and it's vast effects over large sections of the computer world. This is not trivial...
The talk referenced by Schneier in his essay as being the one that publicly disclosed the backdoor was given by two Microsoft researchers. So all the "OMG micro$oft iz so stoopid" posts might be a bit .... misdirected.
There is known to be a backdoor, but nobody knows what it is. That's the part that's secret.
Patrick Doyle
I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
The obvious joke here is that its a lot of trouble to go after the 12 people still using Vista. Baddump-bump!
But seriously, this is a continuation of Microsoft's vendor-first, consumer-second approach.
So it "may have" a top-secret magic NSA backdoor. I hear it also "may have" a portal to the magical world of Stupidia, and also "may have" a contest where the winner gets adopted by Bill Gates.
I've also heard any version of Lunix using the GPLv3 "may have" a secret program which will turn us all into robotic mutant drones in the service of Richard Stallinman.
Why, oh why, do teh FOSSies continue posting rumors, speculation, and insane conspiracy theories as news?
I agree that the vulnerability of this particular PRNG has nothing to do with closed vs. open source, but I think there is some relevance to the larger issue. Namely, in a closed source OS it seems (at least naively) that there are lots of ways to insert various sorts of back doors. If one is so worried about the government twisting MS's arm to put in a back door, it seems like a publicly known PRNG algorithm with known vulnerabilities is really the least of your worries.
I'm not one of the people who thinks all software must be open source, but it seems like there are strong arguments in favor of open source as far as avoiding back doors from powerful interests.
"You call it a new way of thinking; I call it regression to ignorance!" -- Operation Ivy
Internet: Only one on the list that is really US made.
Computer: Charles Babbage, England
Motor Car: Karl Benz, Germany
Light Bulb: Lots of people had working but impractical incandecent light bulbs for nearly 100 years before Edison, but Alexander Nikolayevich Lodygin of Russia would be the earliest inventor of "Edison's" style of light bulb, not Edison.
Telephone: Either Bell, a Scot invented it in Canada, or Antonio Meucci, an Italian invented it in the US.
If you have read any recent history about modern US foreign and domestic actions things like this arent conspiracy theories, its just a likely conclusion. The terrorist thing is just a continuation on the soviet angle that was rendered useless for controlling the masses when the cold war ended. Encryption is the biggest threat to big brother society. Its just natural that US govt try to get their own backdoors in.
The thing is, real terrorists arent so stupid that they use the POTS or the internet. Its you and me they are after.
HTTP/1.1 400
how are you gentlemen?
I always use Pi as a random seed and haven't had anyone waste the computer time yet to... whoops
Let's walk through these expert comments one step at a time:
Anybody who is paranoid about this issue
Did you see what just happened there? This is a clever sleight of words used to disparage and marginalize anyone who questions his premise. Disagree? Put on your tin foil hat and go to the psych ward. There's no room for discussion or even consideration of alternatives. Based on my direct, but very distant experience, Bruce is right in calling the backdoor.
The Common Criterial evaluators look for such issues
They do? Really? Anyone that has undergone EAL evaluation knows it's a giant tree-killing documentation project above all. I don't want to bore anyone with the details of CC evaluation, but it's not a creditable rebuttal to the issue. The meat of the matter from wikipedia "Higher EAL levels do not necessarily imply "better security", they only mean that the claimed security assurance of the TOE has been more extensively validated." http://en.wikipedia.org/wiki/Common_Criteria
As another post so insightfully states, there's no reason why, IF some project actually needs the feature, they can't install it as a library. Just like we all do for openssl on windows.
http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
Aren't you the same one who told us that about some security hole that XP wasn't vulnerable to it like 2K was because you knew the "very smart" people working on it? And then we turned around only to find out that it was vulnerable in the next news release? I'm the same AC who didn't really believe you in that Slashdot story, either.
Well, I'll believe that you work for Microsoft. But I won't trust the code until it's been audited.
This kind of reminds me of the old days of computing where random number generators simply cycled through a fixed series of values that would be repeated over and over each time you powered up the computer. One fun exploit of these early random number generators was to place two identical computers on the same circuit, then flip the switch causing both machines to boot simultaneously. Assuming the factors were reasonably identical, you could simultaneously launch any program that used random numbers and use one computer to predict the results of the other with 100% accuracy.
For example, using this technique on a pair of Apple IIs (same series/configuration), you could load up a stock trading game on both machines and play one machine normally to see which companies were going to increase/decrease in value, then pour all the funds into the companies on the first computer that increased into those same companies on the second computer.
Near as I can tell, the random number generator (at least on the Apple II) would only change state when a new value was requested from it... otherwise it simply sat idly by waiting for the next request.
8==8 Bones 8==8
Big deal. Hackers are already reading my emails and trying to steal my identity. Why not the NSA as well? Why don't I just mount a cloned monitor on my front door so people I *do* know can read it too!
Trust us, we're from a multinational corporation!
If true, do you really think Microsoft would 'want' to do this? They have been pretty strong privacy advocates, especially Gates, denying even backdoor access for Bitlocker in a fight several years ago when bitlocker was demonstrated to the FBI.
If the government is FORCING MS to do this, then we should be calling our representatives and not sitting around speculating or smacking on Microsoft.
The whole big brother NSA thing is very much a Republican/Bush/Neo-con era mechanism, and Gates and lots of others at Microsoft vote democrat, even when it was NOT in their best interest as during the DOJ trials of the 90s.
(Look up contributions, MS by far gives to Democratic canidates, and ironically companies that we think are on the side of the little people are ones shoving money toward pro-corporate/authoritarian canidates.)
He's neither informative or interesting since his arguments only consist of shouting and words like holy crap,lol,...
Informative or interesting would be a timeline for each invention.
internet : http://inventors.about.com/od/istartinventions/a/internet.htm
computer : http://inventors.about.com/library/blcoindex.htm
car : http://inventors.about.com/library/inventors/blcar.htm
lightbulb : http://inventors.about.com/od/lstartinventions/a/lighting_2.htm
telephone : http://inventors.about.com/od/bstartinventors/a/telephone.htm
Strictly speaking that gives him a 2 out of 5 (internet+telephone) and
actually confirming the original statement
Now watch how people will start coloring the facts to fit their agenda...
As a cryptographer I've seen the EC-DBRG spec already and immediately dismissed it as completely stupid. From a practical stand point it's too slow to be useful, and from a statistical standpoint it's no better than say a hash in CTR mode (e.g. hmac'ing a counter).
I know why MSFT added it [e.g. blind compliance with some spec, which from MSFT sounds odd to be honest...] but I don't agree with using the design.
As I recall NIST specifies other hash/cipher based PRNGs which are also standard so I don't think that the EC approach is really "required."
Tom
Let us all eat a large slice of humble pie.
Well, let's extend your analogy: Suppose you bought a Jeep. Would you expect the contents in the back to be safe from theft, or inspection by law enforcement? Vista is that Jeep - it exposes your personal life to anyone who wants to have a look, breaks down a lot, costs a lot to maintain, and leaves the user exposed to anything hostile coming its way.
The society for a thought-free internet welcomes you.
lynxcache plain-text mirror: http://lynxcache.com/Did_NSA_Put_a_Secret_Backdoor_in_New_Encryption_Standard_.html
interesting, and I'm very inclined to believe you. I think it's great to hear from someone in MS that has relevant knowledge on these kind of subjects. (ie: I think most of MS related articles on Slashdot have some rather obvious "anti" written all over them.) So my question is, why do you "hang out with the slashdot crowd" so to speak? I know if I were working for MS I would've gone away long ago before I need a daily dose of Prozac. Seriously, I want to know.
"This should be fun, and by fun, I mean a wholly depressing insight into the cognitive ability of some grown adults."
Once I saw a college kid tap into the FSB on his Xbox1 to get some serial number* or what not, I then realize that we as consumers, at least in this very narrow field, have some recourse for the actions of the powers that be... Just imagine how hard it would be for Microsoft to successfully include a back door in its most popular products that would escape the scrutiny of a million not so dumb users along with the actions and specific setups of millions pretty dumb users. It would be the single greatest program ever made. *Honestly I forget the specifics/goals of the project but it was nuts.
I'm sick of following my dreams. I'm just going to ask where they're goin' and hook up with 'em later.
Exactly. This is why it is the NSA and Microsoft involved.
We already know the NSA is spying, it's just the methods are
supposed to be secret. Obviously, they are not really secret,
but they want to maintain the air of plausible deniability.
NSA is doing the spying on everyone with the help of Microsoft.
It is no surprise therefore, that Microsoft is attacking FLOSS.
You are being MICROattacked, from various angles, in a SOFT manner.
> From a more practical demonstration point of view, if there was a backdoor, governments
> would not need to get warrants for inserting hardware keyloggers or custom malware on
> systems to access system information. Governments both in the US and elsewhere do this,
> which suggests that no backdoor is available.
You made a fairly convincing argument until you spouted this idiocy. It is so error filled I'm uncertain where to begin the disection but since I must pick one....
1. A backdoor gives no LEGAL right to collect information from a system thus anything obtained in such a manner would be inadmissable. A court approved keylogger, etc. yields admissable evidence.
2. The existance of such a backdoor, if it existed, would be one of the US government's most treasured secrets, not to be squandered collecting inadmissable evidence on some petty crimelord or terrorist. I doubt it would be considered 'worth it' to bag UBL and his top ten minions. It probably wouldn't be worth giving up (and enduring the shitstorm from the Kostards) to prevent another 9/11 scale attack.
Here one should reflect on history to see how such a resource would be used, and examine the rules that governed actionable intelligence gathered via Ultra. Unless a plausible alternative method can be shown where a piece of intelligence COULD have been obtained (even if they had to use other Ultra derived info to fake things) such that the enemy would not conclude that a break in Enigma was the ONLY way the allies could have known a fact, then it could not be used. England was willing to allow an entire city to be firebombed to preserve the Ultra Secret.
3. Just because the NSA doesn't make public use of things pulled from the ultimate backdoor doesn't mean they aren't using it or wouldn't use it in some future crisis. And it doesn't mean someone else might not discover it and instead of publishing, ferret out a way to themselves activate it. (unlikely given the nature of public key crypto)
Personally I'd like it if we someday learned the NSA had such a backdoor since it would prove they still knew how to 'spy hard' but sadly I doubt they have the chops for that sort of caper anymore, content instead to just sit in their lair and listen to signals.
Democrat delenda est
yes, but hte emphasis is on semi. In this cryptographic application, the number in question must be the product of two primes. There are 2 possibilities --- either the NSA multiplied the two primes, and has a theoretical chance of compromising something that uses the random number generator and poor security, or that they approved the number because they haven't factored it. Since this security standard is used by the US government to protect the US government, the odds of the second are much higher then the first.
The FIPS standards aren't really for other people; they're published so the federal government can buy hardware/software combos that meet the FIPS standards. However, other people are free to use them, as they're one thing that the government hasn't stolen from the people, unlike ANSI and ISO standards, many of which are written by the government, made into an ISO standard, and then you have to pay the copyright fee for something your government wrote. That's a real travesty.
"might know"
Again... baseless and idle speculation. This is why FOSSies always get pwned by Microsoft: because they are always half-baked, and have nothing to present to anyone (especially prospective customers) aside from a whole lot of anti-MS FUD and their never ending hatred of all things MS.
Reality Check: only 0.0000000001% of software customers (and that may be overly generous) will give two shits about being able to see your source code. You would be better off giving them a book written in a foreign language. At least that might look good sitting on their shelf or coffee table.
Software generators, such as one build into Vista are only pseudo random. They rely on clever algorithms to generate sequences that in short series seem to be random but they are not in reality. Only hardware generators based on thermal noise or some other physical random process are capable to produce true random sequences. Therefore Microsoft product has "back door" just like every other software "random" number generator. This is another anti Microsoft FUD.
JAM
The constants were:
4, 8, 15, 16, 23, & 42
Hmmm...
"Why use linux unless you have something to hide?"
Bruce Schneier could produce literally truck loads of evidence, however, I would just deny it all. Sorry, but I can't help myself. I am just mimicking the masses of sheeple who will just cry Baahhhhh Bahhhhh.
Yeah, they're coming for you because you're the special intellectual elite. I'm sure.
Go read Catcher in the Rye and check your perimeter traps again, tinfoil boy.
> What matters is that Vista is full of holes
I don't see any evidence for this. How do you say that? AFAIK OS X has had more security patches than Vista this year. And don't give me BS about "proving that Vista does not have security holes" -- you can't prove a negative.
> you can rootkit even a fully patched Vista box with an email?
I'm not sure exactly what you're talking about. If I send you an email with some sort of file, and you're stupid enough to go ahead and execute it, then I don't see what any OS can do to stop you. So you can basically rootkit even a fully patched OS X/Linux box with an email. User intervention is required in each case.
But what have you done for me lately?
SCROTUMS
From TFA: "It's too slow for anyone to willingly use it. And it makes no sense from a backwards-compatibility perspective"
No wonder why MS is using it...
another reason why no one should upgrade to vista...please just put it out of its misery already.
Bring out behind the shed and shoot it, let the penguin get caught holding the gun!
I really don't think the parent was going for "Informative"....
What's purple and commutes? An Abelian grape.
Anyone who considers arithmetical methods of producing random digits is, of course, in a state of sin.
John Von Neumann, 1951
One CPU cycle wasted on digital restrictions management is ONE TOO MANY.
Deleted my copy of vista ult.set it on fire as to not give it to someone else. The OS I have written are as good as any to surf music movie those are my only needs.
Reliabiliy and Performance Improvements
Hmm... welcome to the operating system of the future, where nothing can *possibliye* go wrong...
EAL is not about security features, it is about assurance levels
Your initial post suggest EAL would magically expose the back door. It will not. That is not how an CC review works.
CC evaluation lab has source level access to the system
As if source code access would expose the back door? It would not. Source code needs to agree with the documentation provided. Period. Back doors to a cryptographic algorithm are way outside the scope of CC certification.
I am running Windows Server 2K8
Don't get me started on Microsoft's elaborate blame-shifting system (Are you sure?) that's difficult to use. Maintaining a mixed environment of 2000/2003/MSSQL is extremely difficult. I can't keep a single cluster node at 99.999 uptime. Meanwhile, my Linux servers are running at 99.999% uptime.
http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
Why not use your own algorithm then?
For example, use an azerty keyboard (or a Dvorak) and encode everything using EBCDIC.
...as if we really NEEDED another reason...