NSA has built-in backdoor to all Windows software

Windows-NSA-logo.jpg


NSA has built-in backdoor to all Windows software. If this revelation doesn’t send Microsoft sales into a tailspin then Al Gore isn’t fat.

J.P. Travis: Born and raised in Grand Rapids, Michigan, 1976 graduate of University of Michigan, father, grandfather, husband, founder and CEO of Travelyn Publishing (http://www.travelynpublishing.com/), and passionate anti-government believer in individual liberty.

View Comments (14)

  • If Microsoft wrote the software it is most likely so full of bugs that NSA wont get anything other than a 404 error out of it anyway. Test software??? Who?? Microsoft? Hahahahaha. That'll be the day.

  • Crap, J.P., this means I'll have to buy another computer and more useless software. NSA, more than likely, has their evil lunch hooks into everybody's software these days.

    • Good point. If they have a backdoor into Windows they probably have a backdoor into Apple computers... BUT, with Windows we know.

      Open source Linux?

      • Don't waste your money.. This NSAKEY "story" is older then my children.. The public keys found were meant only to verify signatures on cryptographic components present in windows at the time

        Public keys (the public half of an asymmetric keypair) don't have magical backdoor powers. They are used to verify signatures and to exchange cryptographic material with the bearer of the private key (meaning, you can communicate securely with another party, but not impersonate them). MS wouldn't have been able to sell millions of copies of this software to the Chinese, if this were actually true.

        • Yes, the story is from 1999, but your explanation doesn't explain why one key was labeled NSAKEY and why the third key was unknown to Miscrosoft itself.

          • As I understand it, MS security guy had reasonable remarks on both matters:

            NSAKEY was a variable name or some other symbol chosen because the keys were required by NSA for verification of crypto export controls (considerably relaxed since..). So they were just colloquially known as the "nsa keys" around the office

            The 3rd key was just a test key.. probably one of several ad-hoc used over years of development. Signing the crypto software with the production keys would have been a foolish breach..

            I've worked on a certification authority. The production keys were verboten. During dev, you use test keys. And we used the stupidest names for objects in code.

            With those serving as rough explanations, the public keys being in NSA's hands would make sense, if their aim was to verify code-signings generated by MS held private keys. Handing the NSA those private keys would only have allowed the NSA to sign code itself.. so that its own auditors could be fooled into verifying..?

            Or, as I see this shaping up, the contention is that the NSA would be able to drop in software on a Windows machine, that serviced CryptoAPI, and passed validation. CryptoAPI facilitated cryptographic services for various software vendors, and enforced the module signatures, using the keys under discussion (or, at least, enforced for modules with cipher strengths beyond that allowed by export controls at the time).

            So the only reason for NSA to set this up would be to defeat its own auditors (honestly no idea how much actual auditing involved), or--more importantly--defeat CryptoAPI validation. Perhaps they'd install an imposter crypto provider, get invoked by CryptoAPI for all manner of tasks, and snoop on the plaintext before encryption?

            It seems spotty strategy, and there's no guarantee that any encryption task would run through such imposter code anyway. A keystroke or filesystem monitor would be far more effective. Besides, CryptoAPI can't stop/intercept all encryption on a windows machine. Its just a broker for modules that make software developers jobs easier. Think Visual Basic guys. But anyone with a mind for the math can write their own. I've used AES implemented in javascript.

            I didn't write it.. I'm not that diligent or smart.. Google did, if i recall (or they hosted the project at least)

            That's the gist i got, but i could be missing some big piece

  • 0bama hates the Constitution because IIRC "It says what the government can't do to you." 0 wants a proactive Constitution that explains what the government CAN DO TO YOU. This has been a dream for fascist progressives since Wilson was president. Right behind the First and Second, the Fourth is much hated by the neofascists in control of the government.