• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

NSA Helping with Windows 7 Security?

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
You know those recent reports saying Windows is more secure than OS X and IE is more secure than Firefox and Safari? I think I know why now. ;)

The National Security Agency has been working with Microsoft Corp. to help improve security measures for its new Windows 7 operating system, a senior NSA official said on Tuesday. The confirmation of the NSA's role, which began during the development of the software, is a sign of the agency's deepening involvement with the private sector when it comes to building defenses against cyberattacks.
 
So the NSA knows all the back doors....


Hope they keep their people happy. No need to have rogue NSA agents turning all us early adopters into bunch of zombie boxes.
 
That's... pretty cool actually.

I like to imagine the NSA has some of the worlds most elite hackers... who would be better at making an OS more secure?
 
"Helping." Sure.

I'm sure MS didn't return the favor by building in some convenient back doors, riiiiiight? :rolleyes:
 
"Helping." Sure.

I'm sure MS didn't return the favor by building in some convenient back doors, riiiiiight? :rolleyes:

Kind of what I was thinking. Im all for better, more secure OS's. Im just hoping that my privacy isnt affected in any "under-the-table" sort of ways.
 
Why are people so hyper sensitive to everything. Why would Microsoft even need to give anyone "back door" access. It makes no sense in this context.

The gubment's watching every move you make! Didn't you know??
 
Schaeffer said that the NSA is also working to engage other companies, including Apple, Sun, and RedHat, on security standards for their products. The agency also works with computer security firms such as Symantec, McAfee, and Intel.

So be careful how you judge this. Even LINUX is mixed up in this. Personally I think the threat from non-governmental agents is a much BIGGER risk and if the NSA is doing its job it should know things that aren't readily known to anyone else.

And honestly, why is this so bad? With an Open Source whose to say that the NSA doesn't work on hacking those as well? I mean they have the source code.
 
Yeah, anyone with minimal common sense knows this.

Don't be so sure about this. Remember, Microsoft works with a LOT of governments and agencies and businesses around the world, many who do have access to source code and they have walk a fine line on security as most would want Windows to be secure but not accessible through a back door by their enemies and competitors.
 
"In 2007, NSA officials acknowledged working with Microsoft during the development of Windows Vista to help boost its defenses against computer viruses, worms and other attacks."

ROFL! that explains soooooo much and makes the 'I'm a Mac" ad with the Man In Black providing security requests for PC all the funnier :D
 
"Helping." Sure.

I'm sure MS didn't return the favor by building in some convenient back doors, riiiiiight? :rolleyes:
Right... and if the "evil gubement" did nothing and a cyber attack happened that America to somewhere 1900, people would be whining about "WHY isn't the government doing it's job?"
 
article said:
The NSA, which is best known for its electronic eavesdropping operations, is charged with protecting the nation's national security computing infrastructure from online assaults.

Isn't that a case of giving the keys to the hen house to the fox? :eek:

Patriot act spying anyone?
 
And here's the NSA doing its job again. http://www.wired.com/threatlevel/2009/11/cyber-attacks-preventable

Senate Panel: 80 Percent of Cyber Attacks Preventable

If network administrators simply instituted proper configuration policies and conducted good network monitoring, about 80 percent of commonly known cyber attacks could be prevented, a Senate committee heard Tuesday.

The remark was made by Richard Schaeffer, the NSA’s information assurance director, who added that simply adhering to already known best practices would sufficiently raise the security bar so that attackers would have to take more risks to breach a network, “thereby raising [their] risk of detection.”.....

As for corporate and government entities that collect and store the public data, they “do not understand themselves to be responsible for the defense of the data,” said Clinton, whose group represents banks, telecoms, defense and technology companies and other industries that rely on the internet. “The marketing department has data, the finance department has data, etc, but they think the security of the data is the responsibility of the IT guys at the end of the hall.”

Just another example of why corporate "talent" and "managers" are not as smart as they believe themselves to be.
 
Don't be so sure about this. Remember, Microsoft works with a LOT of governments and agencies and businesses around the world, many who do have access to source code and they have walk a fine line on security as most would want Windows to be secure but not accessible through a back door by their enemies and competitors.

backdoors can be very complex and hidden very very well even in openly visible sourcecode. You can store executable binary/data in a resource file that can not be easily read in most development studios.
 
backdoors can be very complex and hidden very very well even in openly visible sourcecode. You can store executable binary/data in a resource file that can not be easily read in most development studios.

For example, you could have a malformed resource (bad mp3, .wav, .mpg, even a .bmp) that loads and works properly, but also causes a non fatal buffer overflow exploit, thereby opening a backdoor.

This kind of explot is VERY VERY difficult to track down because you have to look at memory frames/execution stacks, or HAND CHECK the data flags in the resource file. Now who has the time to do that on a .mpg?
 
The long timers here might remember when Win 2000 came out and their was talk about a back door key for encryption because their was a file with the extension .NSA.:eek: Never did read an update on that one. Some times I think (H) should do follow up stories.;)
 
It seems that most people reading this thread are going to be donning their aluminum foil hats..
 
The tin foil in this thread is amazing:

tin_foil.jpg
 
The article is a good read and very interesting since around 2005 there has not been any new large-scale worms targeting Windows services. The article mentions NSA involvement started at least around 2005.
 
for those that think this is a good thing

point 1: have you never seen public housing, public anything? Administratium ring a bell?

point 2: the people citing tin foil and such don't remember there history well. sorry but the government having low level access to our communications, in other words a new way to spy on, is just not a good thing. no public threat is as dangerous to us. The founding fathers understood that as well a lot of other higher minded people. when has the government ever gained a power and not used it?
 
backdoors can be very complex and hidden very very well even in openly visible sourcecode. You can store executable binary/data in a resource file that can not be easily read in most development studios.

Agreed, that's why I wouldn't think that any platform would be immune to this but Windows does go through a GREAT deal of inspection.
 
I know when I think about great computer security the first thing that comes to mind is... Government. :rolleyes:
 
Warfare in the 21st century will incorporate cyber attacks. Windows is no longer just an operating system it is also a weapons system. If 90% of the worlds computers are Windows platforms it would be the height of stupidity to not be closely involved in crafting defenses as well as methods of attacking it. Think just how dependent we really are on computers for our daily life. If the U.S. has an achilles heel this is it.
Just imagine a cyber 9/11. No more internet, or e-mail. How would that affect our already shaky economy? Warfare is moving beyond the battlefield, and I am glad to see our government taking the threat seriously.
 
Because our every cyber move is now snooped upon by the government, I was right by saying:

"Windows XP x64 and x86 forever!"

Sucks to be one of you Windows 7 purchasers. Threw away your rights without even realizing it.
 
The tin foil in this thread is amazing:

tin_foil.jpg

The system sure has a way of shutting people up or trying to.
1. Don't be talking about other Races or Nationalities in any negitive way, Shut the F*ckup your a racist or Bigot.
2. Don't be talking about possible scenarios about Government or Companies. Shut the F*ckup your a Conspiracy Theorist, put your tin hat on.
What comes to mind is the story about the last person to be taken away by the Thought Control Police, and he asks "Why is nobody speaking out on my behalf".
 
The system sure has a way of shutting people up or trying to.
1. Don't be talking about other Races or Nationalities in any negitive way, Shut the F*ckup your a racist or Bigot.
2. Don't be talking about possible scenarios about Government or Companies. Shut the F*ckup your a Conspiracy Theorist, put your tin hat on.
What comes to mind is the story about the last person to be taken away by the Thought Control Police, and he asks "Why is nobody speaking out on my behalf".

You forgot 3. Who the hell cares what the government thinks of me. They can go jump in the lake.
 
It seems that most people reading this thread are going to be donning their aluminum foil hats..

Why? Most of the comments didn't say it was a bad thing; we just know this is a cover-up. In principle it's fine. Terrorists do use and prefer Windows, and sophisticated encryption is becoming easier than ever even for the brainwashed morons to use effectively. That's why I said it was like giving the keys to a donut shop to the cops. In principle it's nice for the good guys to have a shortcut to catch a crook who sneaks in to the locked store. In practice though...
 
Why? Most of the comments didn't say it was a bad thing; we just know this is a cover-up. In principle it's fine. Terrorists do use and prefer Windows, and sophisticated encryption is becoming easier than ever even for the brainwashed morons to use effectively. That's why I said it was like giving the keys to a donut shop to the cops. In principle it's nice for the good guys to have a shortcut to catch a crook who sneaks in to the locked store. In practice though...

I think some of us like me are a little skeptical as to the very EXISTENCE of a back door to Windows. Maybe there is but at the same time Windows is deployed across the globe on a billion plus computers are to this day I've never heard anything concrete about it.

If such a backdoor does exist, why has NO ONE seemed to have found it. Think of the power would give hackers. Indeed, such a back door would I think have a lot more risk than upside to it. If the government could use it, then couldn't terrorists and crooks?
 
I think some of us like me are a little skeptical as to the very EXISTENCE of a back door to Windows. Maybe there is but at the same time Windows is deployed across the globe on a billion plus computers are to this day I've never heard anything concrete about it.

If such a backdoor does exist, why has NO ONE seemed to have found it. Think of the power would give hackers. Indeed, such a back door would I think have a lot more risk than upside to it. If the government could use it, then couldn't terrorists and crooks?

This. My god makes me wonder if some of you guys wear tin foil hats every day.
 
http://en.wikipedia.org/wiki/Dual_EC_DRBG

Details from my memory of when this all just broke into the news a few years back -

The NIST (read NSA indirectly) promoted heavily the inclusion of a new pseudo random number generator, and sucessfully lobbied its inclusion into Windows (XP SP3+), Mac, and even on Linux. It was discovered that there appeared to be "backdoor" in that if you knew the key, the random numbers would be weighted heavily in a given direction and thus easily guessed. For those not familiar with how encryption works, without random numbers, your encryption won't be very effective. The amount of data it turns out (as it was guessed) was only 32 bytes before the random numbers used could be guessed if you knew the "key". That is less than it takes to do an SSL handshake. Keep in mind, the algorithm used for encryption does not matter if you can guess the random numbers.

In other words, with a very small amount of data, it could EASILY be decrypted - if only you knew the key.

To me the biggest threat is not necessarily that if the NSA wants to it can know every bit of my data. My fear is that someone else could figure out the key and have free reign on all data encrypted using this prng. That would not be just an invasion of privacy, but a genuine (inter)national security threat.
 
Why doesnt everyone who is freaking out.. unplug your internet connection.. go back to MS-DOS.. and play Doom1 then you have nothing to worry about.

If there is a back door.. the government really could care less about average joe. It would never affect you. If you are doing some terrorist shit then yea.. be worried (if it exists)

For everyone else.. enjoy windows 7.. log into facebook daily.. surf pr0n and live your life...

People sometimes forget there are billions of people on this earth. That's a ton of data to sift through.. Nobody cares that you stalk your ex on facebook... Stop thinking you are the center of this world and entire governments are going through your hard drive..
 
Why doesnt everyone who is freaking out.. unplug your internet connection.. go back to MS-DOS.. and play Doom1 then you have nothing to worry about.

If there is a back door.. the government really could care less about average joe. It would never affect you. If you are doing some terrorist shit then yea.. be worried (if it exists)

For everyone else.. enjoy windows 7.. log into facebook daily.. surf pr0n and live your life...

People sometimes forget there are billions of people on this earth. That's a ton of data to sift through.. Nobody cares that you stalk your ex on facebook... Stop thinking you are the center of this world and entire governments are going through your hard drive..


+1

People also seem to forget that NSA has nothing to do with spying on US citizens (Or any citizens of second party countries, the 'FIVE EYES'). The only caveat to that statement is if you are working with / communication with terrorists.

If anything, you should be worrying about the FBI seeing as how they aren't legally restrained from spying on you (Or local law enforcement in cooperation with the FBI).

Keep in mind, part of the reason the NSA has to have some word in Windows is because the government uses Windows heavily. I don't, and should not need to expand on the reasons why the government should be able to do this. Obviously, I'm thankful the government has such a heavy hand with it - I'd rather it be our government then the people's republic of China.
 
Back
Top