SUID:root
Member of Honour
Hallo zusammen,
ich bin durch Zufall auf einen alten Artikel gestossen, dessen Inhalt ich schon lange kenne. Er ist aus dem Jahre 1999 und beschäftigt sich mit der Frage, ob in früheren Windows-Versionen (auch in den heutigen??) eine Backdoor seitens M$ installiert wurde.
Mich hat dieses Thema damals sehr bewegt und ein eindeutiges Ergebnis liegt bis heute nicht vor.
Um einen Fake handelte es sich nicht. Soviel ist sicher. Denn auch M$ räumte die Existienz dieses Keys ein. Allerdings wurde die Existenz mit anders lautenden Argumenten, als denen des Entdeckers, gerechtfertigt.
Auch wenn dies evtl ein alter Hut ist, würde mich doch mal die allgemeine Einschätzung der User auf diesem Board interessieren.
Hier mal ein Auszug:
Quelle: http://www.techweb.com/wire/story/TWB19990903S0014
A careless mistake by Microsoft programmers has shown that special access codes for use by the U.S. National Security Agency (NSA) have been secretly built into all versions of the Windows operating system.
Computer-security specialists have been aware for two years that unusual features are contained inside a standard Windows driver used for security and encryption functions. The driver, called ADVAPI.DLL, enables and controls a range of security functions including the Microsoft Cryptographic API (MS-CAPI). In particular, it authenticates modules signed by Microsoft, letting them run without user intervention.
At last year's Crypto 98 conference, British cryptography specialist Nicko van Someren said he had disassembled the driver and found it contained two different keys. One was used by Microsoft to control the cryptographic functions enabled in Windows, in compliance with U.S. export regulations. But the reason for building in a second key, or who owned it, remained a mystery.
Now, a North Carolina security company has come up with conclusive evidence the second key belongs to the NSA. Like van Someren, Andrew Fernandes, chief scientist with Cryptonym of Morrisville, North Carolina, had been probing the presence and significance of the two keys. Then he checked the latest Service Pack release for Windows NT4, Service Pack 5. He found Microsoft's developers had failed to remove or "strip" the debugging symbols used to test this software before they released it. Inside the code were the labels for the two keys. One was called "KEY." The other was called "NSAKEY."
Fernandes reported his re-discovery of the two CAPI keys, and their secret meaning, to the "Advances in Cryptology, Crypto'99" conference held in Santa Barbara. According to those present at the conference, Windows developers attending the conference did not deny the "NSA" key was built into their software. But they refused to talk about what the key did, or why it had been put there without users' knowledge.
But according to two witnesses attending the conference, even Microsoft's top crypto programmers were stunned to learn that the version of ADVAPI.DLL shipping with Windows 2000 contains not two, but three keys. Brian LaMachia, head of CAPI development at Microsoft was "stunned" to learn of these discoveries, by outsiders. This discovery, by van Someren, was based on advance search methods which test and report on the "entropy" of programming code.
Within Microsoft, access to Windows source code is said to be highly compartmentalized, making it easy for modifications to be inserted without the knowledge of even the respective product managers.
No researchers have yet discovered a programming module which signs itself with the NSA key. Researchers are divided about whether it might be intended to let U.S. government users of Windows run classified cryptosystems on their machines or whether it is intended to open up anyone's and everyone's Windows computer to intelligence gathering techniques deployed by the NSA's burgeoning corps of "information warriors."
Wer jetzt noch weiterlesen möchte:
Stellungnahme M$
http://www.microsoft.com/technet/security/news/backdoor.mspx#ECAA
ausführlicher Bericht:
http://home.hetnet.nl/~bakxm/sections/echelon/articles/windows.html
It der Key nun harmlos oder verbirgt sich mehr dahinter?
Was meint ihr?
ich bin durch Zufall auf einen alten Artikel gestossen, dessen Inhalt ich schon lange kenne. Er ist aus dem Jahre 1999 und beschäftigt sich mit der Frage, ob in früheren Windows-Versionen (auch in den heutigen??) eine Backdoor seitens M$ installiert wurde.
Mich hat dieses Thema damals sehr bewegt und ein eindeutiges Ergebnis liegt bis heute nicht vor.
Um einen Fake handelte es sich nicht. Soviel ist sicher. Denn auch M$ räumte die Existienz dieses Keys ein. Allerdings wurde die Existenz mit anders lautenden Argumenten, als denen des Entdeckers, gerechtfertigt.
Auch wenn dies evtl ein alter Hut ist, würde mich doch mal die allgemeine Einschätzung der User auf diesem Board interessieren.
Hier mal ein Auszug:
Quelle: http://www.techweb.com/wire/story/TWB19990903S0014
A careless mistake by Microsoft programmers has shown that special access codes for use by the U.S. National Security Agency (NSA) have been secretly built into all versions of the Windows operating system.
Computer-security specialists have been aware for two years that unusual features are contained inside a standard Windows driver used for security and encryption functions. The driver, called ADVAPI.DLL, enables and controls a range of security functions including the Microsoft Cryptographic API (MS-CAPI). In particular, it authenticates modules signed by Microsoft, letting them run without user intervention.
At last year's Crypto 98 conference, British cryptography specialist Nicko van Someren said he had disassembled the driver and found it contained two different keys. One was used by Microsoft to control the cryptographic functions enabled in Windows, in compliance with U.S. export regulations. But the reason for building in a second key, or who owned it, remained a mystery.
Now, a North Carolina security company has come up with conclusive evidence the second key belongs to the NSA. Like van Someren, Andrew Fernandes, chief scientist with Cryptonym of Morrisville, North Carolina, had been probing the presence and significance of the two keys. Then he checked the latest Service Pack release for Windows NT4, Service Pack 5. He found Microsoft's developers had failed to remove or "strip" the debugging symbols used to test this software before they released it. Inside the code were the labels for the two keys. One was called "KEY." The other was called "NSAKEY."
Fernandes reported his re-discovery of the two CAPI keys, and their secret meaning, to the "Advances in Cryptology, Crypto'99" conference held in Santa Barbara. According to those present at the conference, Windows developers attending the conference did not deny the "NSA" key was built into their software. But they refused to talk about what the key did, or why it had been put there without users' knowledge.
But according to two witnesses attending the conference, even Microsoft's top crypto programmers were stunned to learn that the version of ADVAPI.DLL shipping with Windows 2000 contains not two, but three keys. Brian LaMachia, head of CAPI development at Microsoft was "stunned" to learn of these discoveries, by outsiders. This discovery, by van Someren, was based on advance search methods which test and report on the "entropy" of programming code.
Within Microsoft, access to Windows source code is said to be highly compartmentalized, making it easy for modifications to be inserted without the knowledge of even the respective product managers.
No researchers have yet discovered a programming module which signs itself with the NSA key. Researchers are divided about whether it might be intended to let U.S. government users of Windows run classified cryptosystems on their machines or whether it is intended to open up anyone's and everyone's Windows computer to intelligence gathering techniques deployed by the NSA's burgeoning corps of "information warriors."
Wer jetzt noch weiterlesen möchte:
Stellungnahme M$
http://www.microsoft.com/technet/security/news/backdoor.mspx#ECAA
ausführlicher Bericht:
http://home.hetnet.nl/~bakxm/sections/echelon/articles/windows.html
It der Key nun harmlos oder verbirgt sich mehr dahinter?
Was meint ihr?