10 ms·
_NSAKEY
- londons_explore 7y ago20 years on, and nobody has ever found anything signed with this "NSAKEY". That means either the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks, or Microsofts explanation was correct. I doubt anyone will ever know.
- imdsm 7y agoThey probably decided to rename the variable to something unfamiliar and legit sounding like _winsysdg or _realtek2100m
- deleted 7y ago[deleted]
- mapcars 7y ago>20 years on, and nobody has ever found anything signed with this "NSAKEY". Hm, wouldn't Microsoft make a proof by singing something publically with a private key?
- EvanAnderson 7y agoIn the scenario where NSA gave Microsoft a public key to include in the product Microsoft doesn't have the private key. That's the point-- NSA would want their own root-of-trust in the product.
- tribaal 7y agoI think that's the point the comment you are replying to made: if it was legitimately a microsoft key that just serves a different purpose, it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. The fact that they haven't reinforces the argument that they don't own the private key (likely, the NSA does as the conspiracy goes)
- ziftface 7y agoWell I don't know if that would necessarily prove anything, since in this scenario, microsoft and the nsa are working closely enough together to modify one of their drivers. In that case, couldn't the point of contact at microsoft simply send the message to the nsa to have it signed, and then show it as proof that the key is owned by microsoft?
- mlyle 7y ago> it would be trivial for microsoft to prove it by just signing a message or anything with the corresponding private key. It would also be trivial for Microsoft to call up the NSA and say "they're ON TO US and it looks bad to our customers, can you please sign this message?" That is, the test you suggest proves nothing-- you can't prove that only you hold a private key.
- ta999999171 7y agoFISA orders only work one way.
- smolder 7y ago> (likely, the NSA does as the conspiracy goes) Pardon my pedantry but I think you meant conspiracy theory. Conspiracies happen all the time, and by itself the word doesn't imply anything far-fetched or unproven, just plotting to do harm.
- ta999999171 7y agoAt least someone's allowed to point it out. Maybe next time I'll write a paragraph shrugs Time for me to find another community.
- smolder 7y agoI don't understand this post.
- 7y ago
- sterlind 7y agoAFAIK, NSAKEY was a mechanism where the NSA could install their own cipher suites on their Windows machines, without needing to know or trust Microsoft's signing key (and vice-versa.) DoD and IC use Suite A algorithms, which are classified. So they needed NSAKEY, or a private build of Windows that would let them do what they wanted. I think all they could do maliciously with this key is install backdoored crypto suites on victims' computers, which would require Administrator access anyway. Disclaimer: work at MS, this is well before my time, I have no inside knowledge.
- piracy1 7y agoMS said: "the key ensures compliance with U.S. export laws" "the conspiracy theorists were right, but the NSA only used it for hyper targeted attacks" Why not both?
- ryanlol 7y agoBecause nobody has managed to demonstrate a possible attack in the past 20 years.
- ryanlol 7y agoThis seems like a pretty easy conspiracy theory to prove with a debugger. Nobody has ever been able to do so!
- praptak 7y agoHow so? I don't think there's a controversy around the semantics of this key. What is not known is who has the private key and what they sign with it.
- ryanlol 7y ago>Microsoft claimed the third key was only in beta builds of Windows 2000 and that its purpose was for signing Cryptographic Service Providers. So it’s not controversial that this was utterly unexploitable without pre-existing local access? Nobody has ever described how this purported backdoor would be used.
- Sean1708 7y agoThat's a seperate key, which doesn't seem to have an interesting name, not _NSAKEY: > In addition, Dr. Nicko van Someren found a third key in Windows 2000, which he doubted had a legitimate purpose, and declared that "It looks more fishy".
- peter_d_sherman 7y agohttps://en.wikipedia.org/wiki/Nicko_van_Someren https://en.wikipedia.org/wiki/Nicko_van_Someren Excerpt: "Van Someren has published numerous papers in the field of computer security. In 1998 he co-authored a paper[13] with Adi Shamir introducing the concept of key finding attacks. A statistical key finding attack was used by van Someren to locate the signature verification keys used by Microsoft to validate the signatures on MS-CAPI plug-ins. One of these key was later discovered to be referred to as the NSAKEY by Microsoft, sparking some controversy.[14]" https://en.wikipedia.org/wiki/Microsoft_CryptoAPI https://en.wikipedia.org/wiki/Microsoft_CryptoAPI Excerpt: "The Microsoft Windows platform specific Cryptographic Application Programming Interface (also known variously as CryptoAPI, Microsoft Cryptography API, MS-CAPI or simply CAPI) is an application programming interface included with Microsoft Windows operating systems that provides services to enable developers to secure Windows-based applications using cryptography. It is a set of dynamically linked libraries that provides an abstraction layer which isolates programmers from the code used to encrypt the data." ===End Excerpt=== Observation: MS-CAPI -- would seem to be, prima facie, similar to Linux's OpenSSL...
- john37386 7y agoDoes it have anything to do with today's Windows update and this cryptic rumbling ahead of time? https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/ https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-...
- wolfgke 7y agoWe will soon see what this Windows update is about - but I seriously doubt that there exists any relationship.
- alakrit 7y agoIf you mean the relationship between NSA and the vulnerability, then no, there actually is: it was NSA who discovered the vulnerability and it has not been used in the wild (according to NSA themselves; source: https://twitter.com/briankrebs/status/1217082363391377408 https://twitter.com/briankrebs/status/1217082363391377408)
- JackRabbitSlim 7y ago"we lost the backdoor key and its in the wild" constitutes the NSA "discovering" and "informing" MS.
- jaimex2 7y agoIf it looks and sounds like a duck then its probably a duck. I can't see MS admitting to giving out a backdoor key. In any case it's irrelevant as you should always assume everything you don't have source to is compromised.
- xg15 7y agoNormally, I'd agree with you, but this seems a bit too on-the-nose for me. When people have to talk about a shady or immoral activity or put mentions of it in writing, they usually get very creative in finding an inconspicuous name for it. As such, if this were really a backdoor, I'd expect it's identifiers to look maximally boring and no direct reference to the NSA given anywhere.
- ethanbond 7y agoConspiracy theories tend to hinge on the idea that the conspirators are simultaneously 5-dimensional chess playing lizard people from the future and, at the end of the day, dumb as a rock.
- arminiusreturns 7y agoCoincidence theories tend to hinge on the idea that everyone is incompetent and that nobody could ever collude together in secret for any sort of malicious or self interested purpose.
- wahern 7y agoThey hinge on the idea that the greater the value of T or N, the less likely a conspiracy will remain a secret, where T is time and N is the number of conspirators. N is usually the dominate factor.
- arminiusreturns 7y agoI think there are many obvious weaknesses to this line of logic. There is some merit there, but it oversimplifies the subject in the extreme.
- 112 7y agoIt's only fitting that for recurring posts we have recurring comments. Oh wow, there's an `nsagate` subdomain on `apple.com`! https://www.robtex.com/dns-lookup/nsagate.apple.com https://www.robtex.com/dns-lookup/nsagate.apple.com
- andy_ppp 7y agoEven if this _NSAKEY thing is not to do with an actual NSA backdoor(s) into Windows, does anyone here really believe the NSA hasn't leveraged their position to suggest Microsoft (and others) give them ways to access things (or else)? If not it suggests that through software defects they have complete access anyway?
- IAmEveryone 7y agoThis is sort of circular, or tautological: “I believe in it because it’s so believable “ FWIW, I am rather skeptic. And I even have reasons: if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones. Cooperating with the NSA is also clearly not in the companies’ interests. If (when) it comes out, they’d be at risk to lose a lot of business in other countries. In any case, my usual argument about cynicism applies: spreading such theories becomes self-fulfilling, because why should MS work for the NSA/every politician take bribes/every cook spit in your food, if that’s what the people believe anyway, no matter what you actually do?
- SturgeonsLaw 7y agoMicrosoft is listed as a provider in the NSA's Prism program in Powerpoint slides released in the Snowden leak. In fact, the timeline indicates that they were the first on board. https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_slide_5.jpg https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...
- lern_too_spel 7y agoNo, they give data for specific accounts being wiretapped to the FBI. The FBI is a participant in the PRISM program.
- deleted 7y ago[deleted]
- cameronbrown 7y ago> if the NSA has the power to coerce, Apple wouldn’t repeatedly gotten into fights with the US government to unlock iPhones The FBI is not the NSA.
- auiya 7y ago"Microsoft said that the key's symbol was '_NSAKEY' because the NSA is the technical review authority for U.S. crypography export controls, and the key ensures compliance with U.S. export laws" Occam's Razor.
- mapcars 7y agoI'm trying to understand what it means - does it mean your code have to have a symbol called `_NSAKEY`? Or how does it affect compliance?
- CrazyStat 7y agoThe entire signing system, of which these keys were part, was required to comply with US export controls.
- sehugg 7y agoOccam's Glomar
- CrazyStat 7y agoIn that case, why was it the backup key that was named after the NSA, and not the key that was actually used for this purpose in practice?
- Jonnax 7y agoI remember that part of the Windows 2000 source code leaked years ago. I'm presuming people looked at it for dubious keys.
- vips7L 7y agohttps://github.com/Zer0Mem0ry/ntoskrnl https://github.com/Zer0Mem0ry/ntoskrnl
- kstenerud 7y agoEveryone loves a good conspiracy. It distracts us from the real world of carelessness, incompetence, laziness, and lowpriorityness.
- mattigames 7y agoPlus there is so much problems, corruption, conflicts of interest in plain sight with little to no accountability that is laughable someone is going the extra mile to hide their steps.
- justaman 7y agoIf I was trying to hide my presence, I wouldn't name something after myself. $0.02
- IanSanders 7y agoIt was MS who named it, probably
- ziftface 7y agoMaybe that was the incompetence you guys are talking about.
- yohanzw 7y agoThe real world is far more complicated than simply carelessness, incompetence, laziness, and lowpriorityness. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-... https://www.npr.org/sections/thetwo-way/2009/11/nsa_microsoft_windows_7.html?t=1579010193774 https://www.npr.org/sections/thetwo-way/2009/11/nsa_microsof...
- apexalpha 7y agoYes because the NSA snooping in everyone's data turned out to be a conspiracy...
- Someone1234 7y ago
- doesnotexist 7y agoWell, it does seem remarkable that you never hear the DOJ or Attorney General complaining loudly about how MSFT refused to decrypt something for them.
- bb88 7y agoThis was Bruce Schneier's take on it at the time: http://www.cnn.com/TECH/computing/9909/13/backdoor.idg/ http://www.cnn.com/TECH/computing/9909/13/backdoor.idg/ As he pointed out, Back Orifice didn't need a special key.
- an_d_rew 7y agoOne thing to remember is the fear that surrounded the export of cryptographic technology from the US and ITAR and all the rest of it at the time. And then there was the whole key escrow fiasco with Lotus Notes. So just be careful viewing the incident from 2020 with the purported benefit of decades of hindsight. Disclaimer: I’m the guy who first found it and announced it at the rump session of the Crypto conference in Santa Barbara that year...