4 ms·
That's a seperate key, which doesn't seem to have an interesting name, not _NSAKEY: > In addition, Dr. Nicko van Someren found a third key in Windows 2000, whi
by Sean1708 7y ago
That's a seperate key, which doesn't seem to have an interesting name, not _NSAKEY:
> In addition, Dr. Nicko van Someren found a third key in Windows 2000, which he doubted had a legitimate purpose, and declared that "It looks more fishy".
- peter_d_sherman 7y agohttps://en.wikipedia.org/wiki/Nicko_van_Someren https://en.wikipedia.org/wiki/Nicko_van_Someren Excerpt: "Van Someren has published numerous papers in the field of computer security. In 1998 he co-authored a paper[13] with Adi Shamir introducing the concept of key finding attacks. A statistical key finding attack was used by van Someren to locate the signature verification keys used by Microsoft to validate the signatures on MS-CAPI plug-ins. One of these key was later discovered to be referred to as the NSAKEY by Microsoft, sparking some controversy.[14]" https://en.wikipedia.org/wiki/Microsoft_CryptoAPI https://en.wikipedia.org/wiki/Microsoft_CryptoAPI Excerpt: "The Microsoft Windows platform specific Cryptographic Application Programming Interface (also known variously as CryptoAPI, Microsoft Cryptography API, MS-CAPI or simply CAPI) is an application programming interface included with Microsoft Windows operating systems that provides services to enable developers to secure Windows-based applications using cryptography. It is a set of dynamically linked libraries that provides an abstraction layer which isolates programmers from the code used to encrypt the data." ===End Excerpt=== Observation: MS-CAPI -- would seem to be, prima facie, similar to Linux's OpenSSL...
- Sean1708 7y agoI'm not entirely sure what your point is here, but the fact of the matter remains that the key that is being referred to in ryanlol's quote is not _NSAKEY.
- ryanlol 7y agoSo what is _NSAKEY for then? Does anybody know?
- Sean1708 7y agoFrom the Wikipedia page: > Microsoft said that the key's symbol was "_NSAKEY" because the NSA is the technical review authority for U.S. cryptography export controls, and the key ensures compliance with U.S. export laws. People have speculated elsewhere in the thread about why they need a second key to be compliant, but as far as I'm aware we don't actually know.
- ryanlol 7y agoI wonder if this just suggests that there’s nothing interesting to know. “the _NSAKEY backdoor” would still make an excellent blackhat/defcon talk today if someone could actually demonstrate its existence and explain practical exploitation. On the other hand “I looked and couldn’t find anything” isn’t really a very meaningful or interesting statement.