Microsoft Denies It Built Backdoor Into Windows 7
CWmike writes "Microsoft has denied that it has built a backdoor into Windows 7, a concern that surfaced yesterday after a senior National Security Agency (NSA) official testified before Congress that the agency had worked on the operating system. 'Microsoft has not and will not put "backdoors" into Windows,' a company spokeswoman said, reacting to a Computerworld story Wednesday. On Monday, Richard Schaeffer, the NSA's information assurance director, told the Senate's Subcommittee on Terrorism and Homeland Security that the agency had partnered with the developer during the creation of Windows 7 'to enhance Microsoft's operating system security guide.' Thursday's categorical denial by Microsoft was accompanied by further explanation of exactly how the NSA participated in the making of Windows 7. 'The work being discussed here is purely in conjunction with our Security Compliance Management Toolkit,' said the spokeswoman. The company rolled out the Windows 7 version of the toolkit late last month, shortly after it officially launched the operating system."
The NSA, CIA or FBI made the backdoor. And then forced Microsoft to include it in the final build of the OS. Microsoft is technically telling the truth.
Remember this: http://en.wikipedia.org/wiki/Magic_Lantern_(software)
Now count how many ways such a backdoor could bite Microsoft in the ass.
None. They'd just deny it. After all, it would just be one of tens of thousands more security vulnerabilities. It's not like there's a piece of code saying "NSA back door hook HERE". They'd patch it, create a different "vulnerability" with the patch, and pass that on to the NSA, and no one would be any wiser. Security by obscurity. Easy to do in multi-gigabyte resource hogging pigs of an OS.
Seven puppies were harmed during the making of this post.
But I can look if I see anything weird. I'm not beholden to any one supplier, or a monopolist organisation that can blithely say "oh it'll be fixed in the next release" with no conviction whatsoever. I can't be kept out. If I'm not happy with the answer I can check for myself. If I find anything I file a public bug report. The whole world knows, and if it is a security issue the whole fix is posted promptly by trusted people who really care about their work.
Hard to say. You're handwriting is not all that legible.
Perhaps you should sharpen your crayons before you post.
You are welcome on my lawn.