7 ms·
It may be widely believe in cryptography circles, but this release wipes away the plausible deniability that governments and American corporations have always d
by gamble 13y ago
It may be widely believe in cryptography circles, but this release wipes away the plausible deniability that governments and American corporations have always depended on. Just last week, the German government was pooh-pooh'ing claims that Windows and TPM chips had backdoors inserted by the NSA.[1] These documents all but confirm it.
[1] http://www.zdnet.com/german-government-refutes-windows-backdoor-claims-7000019739/ http://www.zdnet.com/german-government-refutes-windows-backd...
- tptacek 13y agoWhat? Which documents confirm backdoors in TPM chips?
- gamble 13y agoEven without naming the companies involved, it's very hard to imagine they are inserting backdoors in less-valued products while somehow missing the crown jewels of Windows and TPM.
- tptacek 13y agoAh, so if we can imagine it, it must be true.
- betterunix 13y agoNo, but now we cannot just assume that cryptosystems are being developed in good faith or that mistakes are not actually covert sabotage. We need to check these systems before we put our trust in them.
- anigbrowl 13y agoBut why would you ever have assumed this? I mean, I don't really care whether something was a mistake in good faith or covert sabotage; the useful question is whether something is secure or not as far as I can tell. Assessing the motivations is a complete waste of my time as an individual.
- betterunix 13y agoIt does matter if the NSA is actively sabotaging our cryptosystems. If people are making mistakes we can solve the problem as a community by improving the techniques we use to develop, document, and test cryptosystems. If we are dealing with people who are deliberately weakening our cryptosystems, it will be harder to push better techniques because our adversary will push back against them, or sabotage the techniques themselves.
- anigbrowl 13y agoIn my view this was true anyway, since any mistake could be the result of foolishness or malice - if not on the part of the NSA, on that of the Russian, Chinese, British, Israeli, (etc.) security services. Crypto is an arms race between people with conflicting interests, and always has been; I don't mean to be rude, but I think your former view of the way things operated was a bit naive.
- coldtea 13y agoWell, that's what happens when they lose the "good faith".
- m0nastic 13y agoI keep finding myself in the awkward position of trying to refute conspiracy theories, but not being at liberty to share everything I know about these scenarios (I really need to work somewhere besides DC), so I'll tread lightly. Taking for granted that the NSA actually backdoored TPM's (which I can assert professionally is very unlikely, but I don't expect anyone to take my word for it), they are far from "crown jewels". The only "meaningful" large scale use of TPMs is actually within the department of defense. It's been a pretty uphill battle getting them deployed and used in other environments.
- gamble 13y agoYou realize that these are exactly the same arguments that were brought up to argue against the details revealed in these documents, so perhaps appeals to authority and use of the words 'conspiracy theories' may be taken with a few more grains of salt. NSA backdoors have been alleged for decades now, and the response is always that they're a 'conspiracy theory'.
- m0nastic 13y agoMy argument isn't that the NSA hasn't backdoored TPM's (which I freely admit I can't convince you of), it's that TPM's are not "The Crown Jewels".
- gamble 13y agoTPM 2.0 is a crown jewel for the NSA. Windows 8 full-disk encryption is based on TPM, and Windows 8.1 certification requires a TPM 2.0 module. It already is or soon will be universal in PC hardware. The NSA was involved its creation, and resisted changes to the standard. At the same time the German government was claiming there were no backdoors in Windows or TPM, privately they had already concluded it was compromised. Source: http://news.techworld.com/security/3465259/is-windows-8-a-trojan-horse-for-the-nsa-the-german-government-thinks-so/ http://news.techworld.com/security/3465259/is-windows-8-a-tr...
- 13y ago