6 ms·
My immediate thought is whether researchers or investigative journalists will find cold hard US government backdoors. This is potentially big.
by mindfulhack 6y ago
My immediate thought is whether researchers or investigative journalists will find cold hard US government backdoors. This is potentially big.
- hyperman1 6y agoThat would surprise me. Governements all over the world already received access to the source code to perform audits. Besides, probably the quality was still low enough that you didn't need this, there were plenty of bugs that would grant a big organisation access.
- beagle3 6y agoThey got access to the source code, but not the ability to compile themselves.... my university had such access.
- choeger 6y agoThey won't. Such backdoors would have to be hidden from Joe Average Coder at Microsoft first and foremost. Coding for MS is not a livelong thing, you know? So any backdoor would a) be obfuscated and b) have some form of plausible deniability. If I would have to make them, they would look like strings of two or three bugs.
- mindfulhack 6y agoLikely you're right, but let's see if anything can become plausibly demonstrable after obsessive scrutiny. Like many situations in life, it may depend on whether someone determined / resourceful enough wants to do this. There may be no one with sufficient motivation. Also, it's not just (allegedly) all of XP source that's been leaked: https://www.bleepingcomputer.com/news/microsoft/the-windows-xp-source-code-was-allegedly-leaked-online/ https://www.bleepingcomputer.com/news/microsoft/the-windows-... It's also Windows Server 2003, MS DOS 3.30, MS DOS 6.0, Windows 2000, Windows CE 3, Windows CE 4, Windows CE 5, Windows Embedded 7, Windows Embedded CE, Windows NT 3.5, and Windows NT 4! That's a huge amount of stuff to analyse.
- Answerawake 6y agoDo you know if there is source code for classic Windows apps like the Calculator, Notepad or Paint? Would love to recreate those simple apps and chuck the lousy Linux/Mac equivalents.
- osamagirl69 6y agoI am not sure if it is what you are looking for, but the calculator is now open source under the MIT license https://github.com/Microsoft/calculator https://github.com/Microsoft/calculator As a recall, making notepad is like a homework assignment for a visual basic class. You just drag the text editor window and add the menus, there isn't a whole lot there! Paint would probably be a bit more work, but there are a few clones out there already
- vermilingua 6y agoNotepad is simple to build in Visual Basic because it uses the controls that are inherited from... notepad. What GP meant, is whether the source for those controls is available.
- magicalhippo 6y agoNotepad is simple to build in Visual Basic, Delphi, heck even assembly because the controls are inherited from Windows[1]. [1]: https://docs.microsoft.com/en-us/windows/win32/controls/individual-control-info https://docs.microsoft.com/en-us/windows/win32/controls/indi...
- Answerawake 6y agoThere is no reason to build them for Windows. I just use the ones already available for Windows. I want to build it for Mac so I can get the great simple tools on Windows but on the stability of Mac. For Paint I have resorted to buying a Mac Store app called Paint2 made by some Chinese developer. It is still too complex but is the best I can do now.
- gpvos 6y agoThere's always Ken Thompson's hack of the compiler to insert a backdoor into the login program on Unix. See Reflections on Trusting Trust: https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html .
- cies 6y agoObfuscated like NSAKEY? https://en.wikipedia.org/wiki/NSAKEY https://en.wikipedia.org/wiki/NSAKEY
- tgv 6y agoThere have always been rumors about such back doors, but even the public ones, encryption schemes, have never been proven by pure analysis. As far as back doors in code goes, have a look at this: http://underhanded-c.org/ http://underhanded-c.org/. It's a pity it seems to have been short lived.
- beagle3 6y ago“Never been proved” is correct, but this proof is quite a tall order. Remember, almost everything in the Snowden disclosures was known before snowden - but generally dismissed as “conspiracy theories”. None if it was proved, until it was.
- tgv 6y agoThen it needs some authoritative source, a leak, or result of a raid. Which was my point: analyzing the Windows XP code most likely is not going to prove there's a US mandated backdoor.
- segfaultbuserr 6y agoIf it really does exist, the backdoor can simply be inserted during the last-minute compile before release. It would be invisible in the code repository, the vast majority of internal developers at Microsoft won't even see anything unusual. Also, I heard anecdotes that Microsoft already allowed governments to audit the source code of Windows under NDA on multiple occasions in the past. But if you cannot guarantee the correspondence between source and binary releases, such a review only helps a little. Reproducible build is crucial for auditability.
- mattowen_uk 6y ago> I heard anecdotes that Microsoft already allowed governments to audit the source code of Windows under NDA on multiple occasions in the past. I can confirm that back in the Windows 2000 days, MS let a major global bank have access to the Windows 2000 source code to aid them in coding some low level bespoke software. Back then, if you were a gold customer, you could pretty much get anything out of MS under an NDA.
- hilbert42 6y ago'MS let a major global bank have access to the Windows 2000 source code to aid them in coding some low level bespoke software.' Examples of this are comparatively well known but it seems to me it's really not relevant here. In those instances it's extremely unlikely that said institutions would have access to even the majority of the source code let alone all of it. All they need are API hooks and or various security code that's relevant for their purposes, etc. If I were the Microsoft person responsible for interfacing with these banks, I'd do what I've done with unrelated stuff, which is to tell them just sufficient to do the job (that's to say only on a need-to-know basis).
- unnouinceput 6y agoAnd that's why modern compilers won't have that. It was exactly so the same source, even compiled a second later, it will generate different binary file. I hate it. It was so easy in DOS era - same source, same binary file, easy peasy.
- mindfulhack 6y agoI'll reply with my own doubt myself: There's a possibility the leaked files are tampered from the original code anyway, i.e. backdoors were removed before being initially leaked. Rationale being that Microsoft / government wanted to control the situation long-term by letting something tampered be what leaks out underground instead of the 100% full thing. Torrent poster also discusses that possibility: https://www.reddit.com/r/windowsxp/comments/iz46du/the_windows_xp_source_code_has_been_leaked_on/g6gwcpo/ https://www.reddit.com/r/windowsxp/comments/iz46du/the_windo... Nonetheless, it's interesting if anything plausible is found.
- dx034 6y agoEternalBlue was probably the biggest backdoor used by the US government for years and even Microsoft (at least officially) didn't know about it. Finding and not reporting bugs is much easier than getting a company to put in backdoors without anyone blowing the whistle or objecting.
- beagle3 6y agoPlausible deniability where people can look is a huge thing. Even where people can’t Easily look - e.g. Intel ME “firmware”, it’s likely done as shoddy/buggy coding, so Intel can just look incompetent (and not downright malicious) when it does come out. Russia and China aren’t buying any of this, and are fabricating their own chips. 5-Eyes are likely in on the thing so no reason for them to set up their own fab facilities. But setting up your own software ecosystem is much easier (especially given Linux / BSD), even though it’s still expensive - so intelligence agencies would rather not give countries incentive to do so just because there’s a back door.