7 ms·
German Government Warns Key Entities Not To Use Windows 8 – Links The NSA
- RDeckard 13y agoCan't tell fact from fiction these days. What is the credibility of investmentwatchblog.com ?
- adamnemecek 13y agoThe sentence "Microsoft [...] informs the US government of security holes in its products well before it issues fixes so that government agencies take advantage of the holes and get what they’re looking for." kind of suggests how credible the source is.
- maxden 13y agoThat was reported in a bloomberg story also: http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... It obviously gives the Govt time to protect themselves, but could also exploit it on other systems.
- adamnemecek 13y agoI'm aware of the fact that they were informed first but I'm not aware of instances of gov't agencies using these exploits to get 'what they are looking for'.
- levosmetalo 13y ago> I'm aware of the fact that they were informed first but I'm not aware of instances of gov't agencies using these exploits to get 'what they are looking for'. Were you aware of NSA surveilance before Snowden? It all comes down to trust, and once there is no more trust (like in case of US gov) then the burden of proof they are not doing anything wrong is on them.
- adamnemecek 13y agoSure. At the same time, even if trust was broken does not imply that NSA was using <0 day exploits which is what the article was saying. Or can I start posting blog posts about NSA developing super-AIDS since it has not proven that it is not?
- MisterWebz 13y agoPretty sure I've read somewhere in the HBGary email leaks about a company that bought and developed exploits and sold them to the government.
- adamnemecek 13y agoThat's a pretty common practice yeah. Your point being?
- levosmetalo 13y agoNo need to pull up AIDS "conspiracy"/conspiracy theories. NSA has been already caught spying on everyone in the world. The method explained allows them more spying. Would you risk your country security, or your own business relying on a piece of technology that NSA or anyone else can use for spying on you? Given a choice between multiple platforms why would you choose one vulnerable to spying and inherently unsecure?
- adamnemecek 13y agoYour comment if off-topic. Article said, "Microsoft gives NSA exploits which they then use to spy on people". I pointed out that there is not a single recorded instance of that.
- yardie 13y ago> Or can I start posting blog posts about NSA developing super-AIDS since it has not proven that it is not? I don't see why not. The same logic is used by the governments' war on terror. "We're going to detain you and put you on a 'no fly' list until you prove you aren't a terrorist".
- myhf 13y agoInvestmentWatch is just translating a story published in Die Zeit.
- mtgx 13y agoThe source of the story is this, but it was in German: http://translate.google.co.uk/translate?sl=de&tl=en&js=n&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fwww.zeit.de%2Fdigital%2Fdatenschutz%2F2013-08%2Ftrusted-computing-microsoft-windows-8-nsa http://translate.google.co.uk/translate?sl=de&tl=en&js=n&pre...
- mpweiher 13y agoOriginal article is here (German): http://www.zeit.de/digital/datenschutz/2013-08/trusted-computing-microsoft-windows-8-nsa http://www.zeit.de/digital/datenschutz/2013-08/trusted-compu... Die Zeit is probably the most highly regarded weekly in Germany, see http://en.wikipedia.org/wiki/Die_Zeit http://en.wikipedia.org/wiki/Die_Zeit
- alimbada 13y agoSeems very sensational. Where in my 6 year old Core2Quad machine would I find these fabled chips? Or for that matter, where on a modern motherboard would I find one?
- mtgx 13y agoThis is what the "trusted environments" on chips can be used for, which are currently at least used for DRM (but who knows what else). This is something people like Richard Stallman and Cory Doctorow have warned for years - that allowing them to DRM your machine at the hardware level, inevitably means the machines will eventually be used against you for different purposes, including surveillance or censorship. This is exactly what the NSA is implying when they say they want to be the "anti-virus of the Internet". TPM will allow Microsoft and/or NSA to remotely disable viruses from every computer - and course anything else they want - anywhere in the world, and that's how they will promote it to normal people: "It will make you safe".
- ds9 13y agoAll that is correct, but it needs (a) support in software and (b) the outside party having secret values mathematically related to the "attestation key" embedded in the TPM. The OS designed for this kind of system then uses the TPM to verify the signature, hash or whatever of software, and would either shut down any unapproved software or deny access to the DRM'd data. I don't know whether Windows 8 is like that, but anyway you can opt out of it by using an OS that doesn't support any remote control. In many BIOS's you can turn TC support off. Here is the formerly canonical, maybe dated now, overview of TC http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
- harrytuttle 13y agoGoogle images for "TPM module". It's built in on some laptops and desktops (usually pre-built ones). Others it's a plugin module that can be inserted into a header on the board.
- guardian5x 13y agoThe story is false, and the BSI (Federal Office for Information Security) has declined the rumours and explicitly does NOT warn of Windows 8: https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2013/Windows_TPM_Pl_21082013.html https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2... it was just a story made up by a german site (zeit.de)
- mtgx 13y agoThe story seems to be from leaked internal documents. Haven't we learned better over the past 2 months than trusting the "official statements" afterwards, that inevitably deny it whether it's true or not? At the very least, I think this deserves more exploring. It's not the first time I saw the Germans weren't happy with Windows 8 and its "secure boot". This is from last November: http://www.linuxbsdos.com/2012/11/21/german-govt-comes-out-against-trusted-computing-and-secure-boot/ http://www.linuxbsdos.com/2012/11/21/german-govt-comes-out-a... And it seems the source for that is your source. So are they contradicting themselves now? http://www.bmi.bund.de/SharedDocs/Downloads/DE/Themen/OED_Verwaltung/Informationsgesellschaft/trusted_computing_eng.html http://www.bmi.bund.de/SharedDocs/Downloads/DE/Themen/OED_Ve...
- arnehormann 13y agoThose are different sources. BMI = "Bundesministerium des Inneren", interior ministry. BSI = "Bundesamt für Sicherheit in der Informationstechnik", federal office of IT security. And they are not contradicting themselves. The statement they just issued reiterated Windows 8 is not safe for government and critical infrastructures.
- moreentropy 13y agoYou might want to read that linked statement again. The BSI criticizes the sensationalist wording and generalization ("bad for all users") in the Die Zeit story, but emphasizes the key point that it's unacceptable for critical infrastructures to give up full control over your own systems by being forced to use TPM 2.0.
- tty 13y agoPrevious discussion https://news.ycombinator.com/item?id=6248010 https://news.ycombinator.com/item?id=6248010
- throwawaykf02 13y agoAnd the most important comment on that thread, which is unfortunately not at the top: https://news.ycombinator.com/item?id=6249933 https://news.ycombinator.com/item?id=6249933
- frank_boyd 13y agoI still don't know why people limit the scope of surveillance products/services to Microsoft. There are a handful of companies to avoid that work with the NSA. If you have missed the list, check out the slides: http://www.theguardian.com/world/2013/jun/08/nsa-prism-server-collection-facebook-google http://www.theguardian.com/world/2013/jun/08/nsa-prism-serve...
- tehabe 13y agoIt is not about Windows 8 but about TPM 2.0. Which basically limits the control over your computer, it might be mostly harmless for private users but for governments and critical infrastructure it is not.
- thomasz 13y agoWrong. http://www.heise.de/newsticker/meldung/BSI-Trotz-kritischer-Aspekte-keine-Warnung-vor-Windows-8-1940081.html http://www.heise.de/newsticker/meldung/BSI-Trotz-kritischer-...
- sdfjkl 13y agoFrom that article: However, this means no all clear in terms of Trusted Computing. While the publicly available TPM 2.0 specification includes no back-doors, any implementation might do so, either by malicious intent, due to implementation errors or government pressure. This risk can be met only if implementations are scrupulously tested and certified by independent bodies. This is not the case with the integrated TPM of current Windows 8 tablets, to name just one example.
- deleted 13y ago[deleted]
- rainsford 13y agoThis is among the sillier NSA stories I've read. First of all, the "link to NSA" was basically invented out of thin air. The original article in Die Zeit as well as this one are basically just reporting that TPM COULD be a "backdoor" for the NSA but not actually supporting the idea that it IS. And beyond the issue of baseless speculation as a replacement for journalism, it's a little hard to understand why NSA (or anyone else) controlling TPM is a special threat to users. Despite what the article claims, I don't think TPM is a "backdoor" and it certainly isn't a "surveillance chip". And the articles don't explain how control over TPM gives someone a special advantage over computers with TPM support, an explanation I'm not holding my breath for.
- walshemj 13y agoAnd you dont have to use a TPM module in a pc all the consumer motherboards i have looked at for my latest hazwell build dont have them just a header in case you want to add one.
- forgottenpaswrd 13y agoExcuse moi, man, but TPM IS a backdoor. How would you define that when MS wants it could enter your computer and control it without you ever realizing. Then if something is proven is that if Microsoft can, then NSA can too. Why Microsoft controlling the crypto keys to your computers is a problem? Are you serious? Why American companies controlling all the computers of the rest of the world is an issue? Europe for one should not depend on American companies for basic use of their computers. This is obvious, if you are not American.
- shortcj 13y agowhat about 'Intel inside' do you not understand?
- jister 13y agoif hackers wants to hack your server it doesn't matter what OS your using.
- rbanffy 13y agoTrue. But you don't have to provide a nice backdoor for them to use, do you? Every system has a set of exploitable vulnerabilities. Each of those vulnerabilities is known by a set of parties other than you. With Windows you can be sure those sets have at least one element each.
- mrt0mat0 13y agoSo.... Linux everyone?
- rdtsc 13y agoThis would be the time for Canonical to move in and pitch Ubuntu.
- Zoomla 13y ago"It allows Microsoft to control the computer remotely through a built-in backdoor." Like every other mobile OSes...