Microsoft Announces 'Windows 10 China Government Edition', Lets Country Use Its Own Encryption (windows.com)
At an event in China on Tuesday, Microsoft announced yet another new version of Windows 10. Called Windows 10 China Government Edition, the new edition is meant to be used by the Chinese government and state-owned enterprises, ending a standoff over the operating system by meeting the government's requests for increased security and data control. In a blog post, Windows chief Terry Myerson writes: The Windows 10 China Government Edition is based on Windows 10 Enterprise Edition, which already includes many of the security, identity, deployment, and manageability features governments and enterprises need. The China Government Edition will use these manageability features to remove features that are not needed by Chinese government employees like OneDrive, to manage all telemetry and updates, and to enable the government to use its own encryption algorithms within its computer systems.
Doing business with totalitarian governments is all good as long as the money keeps pouring in.
I think windows have already most of the what they need, they can probably grab even more stuff like url visited, app running time but the whole concept of reporting data to a server is built-in Windows 10 and that's save a lots of time for Chinese Gov.
Controlled updates, managing all telemetry, and rolling your own encryption? Where can I buy this magical product?!?
"remove features that are not needed by Chinese government employees like OneDrive, to manage all telemetry and updates"
Excellent! Where can I get a copy?
In the U.S. It's already legal for ISP's to sell web history, and since Micro$oft wants as many purchases on their App Store as possible, they probably already know software usage too. Intelligence agencies can just purchase your unencrypted web traffic without a need for a warrant. I guess China just wants to do it for free. I thought Window$ 10 was the worst OS, but I guess the Chinese version would be on another level of its own.
"enable the government to use its own encryption algorithms"
It should be easier to determine what Chinese servers to block at the firewall than to play Microsoft's game of obfuscating where the telemetry data is being sent to.
Everyone else continues to use Microsoft Windows 10 US Government Edition.
Could be both.
Fear of US back doors, wants Chinese back doors.
I suspect though that it will end up being less secure wither way. Less tested for attack however they implement it.
Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
> It's funny that people don't realize that
> MS's holds the master encryption key,
> which they'll happily share with whomever pays the most ... or any court that orders them to.
That said, Microsoft has UNQUESTIONABLY taken steps to limit the scope of any one court's or government's ability to compromise that master key by using it to encrypt sub-keys used to encrypt sub-sub-keys used to encrypt the *actual* key they'd have to reveal.
Example: a new installation of Windows generates a 256-bit salt (probably derived from the license key or GUID) & stores it locally, then communicates it to Microsoft (who also discerns the country). Microsoft computes the sha256 hash of that salt plus their own sub-sub-key, then repeats it a million times with the output of the previous hash in place of their sub-sub-key. They then communicate the final hash back to the newly-installed Windows, which securely stores a copy & uses IT as its master key going forward. If a future court demands the key, MS obtains the salt from the computer in question, re-derives the key, and shares THAT with the court. Salt unobtainable? Mathematically-impossible to re-derive the key in any sane amount of time. Key revealed? The court can now decrypt THAT computer, but no other. If push came to shove, Microsoft shares the sub-sub-key(s) for that jurisdiction plus the algorithm, and tells them to have fun.
The important point: the master key ITSELF is stored in pieces distributed across multiple jurisdictions, INCLUDING Russia and China... the likelihood that they'd ever act in union is approximately zero. So the US might be able to compel Microsoft to disclose their "US" sub-key(s), and the pieces of the master key that US courts can order the disclosure of, but it would NEVER be able to obtain the complete global master key.
It sounds like in this case, Microsoft has basically generated a new master key for the China-Government edition, delegated responsibility for its safeguarding to China, and washed its hands. It has no implications for non-Chinese users, unless you're using a pirated Chinese-Government copy (which, in all likelihood, will have so much malware added by whomever made the pirated copy available, the theoretical ability of China's government to decrypt it would be the LEAST of your real-world problems).
I have to remind you that "totalitarianism" is not a synonym for "a government I don't like", nor even "a government that does despicable things."
It is "a system of government that is centralized and dictatorial and requires complete subservience to the state."
The US does not (yet) assert total control over its citizens, although some political factions might like to go in that direction.
Okay, if the Chinese Government required a special version of this Windows to run in their country, then something stinks about it. Like the data collection and invasive controls that windows 10 possessed from the get go. Doctors, Lawyers, Accountants or virtually anyone handling confidential information need to be paying attention. The very use of Windows 10 in their work violates client/patient confidentiality. (as it sends file header + other potential information possibly not revealed yet) to MS and from their to the US Government. IIn the movie "Bridge of Spies" I remember Hank's line to the CIA agent "We are not having this conversation" concerning a spy he was representing.
People may brush this off in the USA but countries in other countries potentially doing international business, scientific research, or many other things may not their information going to a foreign power. We weren't exactly thrilled when NASA emails wound up being copied to China with a simple DNS availability message boost (we have since corrected, THAT was scary). Windows 10 is and has always been a trojan in it's very conception and we all need to say "No". Windows 7 or Linux, possibly Apple (but I'm not sure I trust them with their iron grip policies particularly on their Iphones) are perfectly user friend/usable solutions.
Those In the Medical profession, I know many hospitals/doctors are stuck with Windows-only drivers/software packages but the medical industry is going to have to make some serious choices: either publicly tell the world their information will go the US Government/Microsoft (for possibly sale) or the medical community will have to demand drivers//software versions that are Linux or Mac compatible. Some are staying on Widows 7 for this reason, but MS had is trying to pressure everyone to go to Windows 10 either by withholding critical updates (they did patch XP for the NSA contributed ransomware so clearly some mandates there) or possibly through other means. (remember, they did start by force feeding which got a public stick) There could even be legal implications for lawyers and medical professions that could be violated here. Hopefully we'll start getting the message soon. It's becoming a not so brave new world.
"Imagination is more important than knowledge" - Einstein
Microsoft Announces 'Windows 10 China Government Backdoor Edition'
Does it still contain NSAKEY?
How's that "alternative" in Win10?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
That's bad enough if it's MY computer.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
You have literally no idea what you are talking about.
None of those words go together.
I wonder what happened to the EU version with that window thing that let you get another browser, or that other EU version without the media player (rofl).
Trump should remove there H1B's from china for this. This IS THE USA WE DO NOT BOW TO RED CHINA!!!
Assuming that it will have a specific version identifier, this could have the side-effect of clearly identifying Chinese government computers, marking them as prime targets for their foes, but conversely also eliminating the risk of friendly-fire.
Man, the chinese government just gets all the good things.... wait what?
Encryption isn't an insurmountable barrier... it's just a speed bump. Hopefully, a really big one that can't easily be driven around... but a speed bump nonetheless.
Realistically, if you encrypt a 128-bit AES key using a 2048-bit RSA key and follow all current best practices for padding & implementation, you can feel 99.9% confident that an attacker with the resources of a state espionage agency won't be able to defeat it within 5 years... 99% confident they won't be able to defeat it within 10 years, about 95% confident they wouldn't be able to defeat it within 20... and about 10% confident they wouldn't be able to do it within 100 years.
For a good example of how you can end up with an implementation that "works", but has compromised strength, Google "textbook RSA" (RSA is *notoriously* hard to "get right" if you try treating its basic algorithm as a cookbook without paying attention to OTHER details like padding & format of the plaintext).
Lately, Elliptic Curve has gotten more attention, because more than a few people have been getting nervous about our current de-facto RSA monoculture (for asymmetric-key encryption). RSA itself has no immediate threats, but we need to have a credible "Plan B" in case some horrific exploit that can't be mitigated by longer keys gets discovered. At this point, using ElGamal or some other alternative would be a bad idea (RSA is better-understood & not demonstrably worse than alternatives), but that could literally change almost overnight.
M$ selling out to the PRC? How si this even news?
M$ has done anything the CPC has asked of them.
Yet, the CPC does nothing about software piracy so M$ continues to lose revenue.
“Compromise is a stalling between two fools.” - Stephen Fry
The backdoors this software is going to have?