By the way I am not ignorant about these areas nor am I naive either.
Richard, we are talking about the NSA. These guys make the CIA spooks like like angels. They are pure evil. They don’t just spy on other countries. They spy on Americans too.
FACT: Congress gave them that right after 9-11.
FACT: Our government told AT&T and other phone companies that they had no choice to but to hand over phone records to the NSA, and they have been busy ever since.
I am not someone from another country saying that I don’t trust American spies. I am an American and they scare the hell out of me. I don’t trust them at all. They say they are helping Microsoft make Windows more secure. I’m skeptical.
You can point fingers anywhere you want; it is irrelevent to me; my remarks refer only to the original discussion which was are there “NSA backdoors” designed into MS Win. 7 and whether or not the US government has knowledge of these backdoors.
You would have to cite the reference regarding phone records; I recall some discussion about it several years ago and agree with you that I would not want my phone records perused without my knowledge or consent, BUT phone records in and of themselves are technically private transactions between you and the phone company and thus you have no legal right to control what the phone company does with those records because technically you do not own them, the phone company does.
NSA, Microsoft, Telephone companies, CIA, CIS, FBI, RCMP all have varying degrees of infiltration into our lives. I did security software and hardware remedies back in 1990’s which included processing ATM video surveillance on frauds, tracing bank transactions, and remote access video image recognition for law enforcement agencies and courts. I can tell you definitively that all above named agencies have a vast arsenal at their disposal. No person is safe from their prying eyes. If they want to check on you they will have no problem. Convincing the courts that they were warranted and that they didn’t use entrapment is their biggest obstacle. After Linux can out, there was a sniffer program (name escapes me) that was used to sniff on internet traffic that worked pretty good. It really wouldn’t take much to use it to scan peoples emails, twitters, blogs, and even their home systems. Yes it scares me too having seen how the whole thing integrates.
So one half of this argument is that M$ connives with the US government to allow the said government to get access to 80% of the computers on the planet, without the users knowledge. Nah, can’t see that at all…:sarcastic:
Microsoft scares me more than the government, all the data they collect presumably “in aggregate” which “doesn’t identify you personally” is merely a ruse for raiding your machine. All of this is available to government without subpoena thanks to the Patriot Act.
i think its wise to be suspicious of any program that “phones home”.
Does Microsoft really need to incorporate a backdoor if so many holes allow to take over the control of the system (or maybe those bugs/holes are the intended backdoors? )
I guess if NSA would put a backdoor (and they probably did already) then it would be cleverly disguised and would activate only by a specific action(s).
There is a reason every machine has it’s unique ID
The only way to make sure they will not hack us using Windows is to disconnect it from the evil internet
Governments still use Windows, but it’s not a base build. The UK MOD is still using Windows XP, and will continue to use it for some time, because the XP they’re running is completely ripped apart and rebuilt so that someone, even MS/NSA/CIA whoever, can’t just jump into it.
Even if they weren’t government machines are stuck behind custom built firewalls, passports and gateways that simply don’t allow access to people who shouldn’t have it (I’m not saying they’re hack proof, just that a Windows backdoor is irrelevant).
You’d think so, but yet there are all these incidents of laptops being taken home to do work, and then they get lost or stolen.
And viruses prove that you don’t need to provide access into the machine to steal information from it. The malware can just upload the stolen information to a puppet website.
Ya know, I’ll come out and say it. Ok? Microsoft has been doing backdoors since at least XP, if not earlier. You can find evidence in at least the registry.
Back then Microsoft did it in at least 2 ways or more ways. 1 was the wpa (Windows Product Activation). It sent a thumbprint of your hardware with the Windows serial number to a Windows server. 2 When an application crashes, you have an option to send or don’t send. Often times when you send, it sends not just the bug report, but all the information. Lastly, Microsoft can, and does force updates. There was a news article on this a couple years ago.
This “news” does not surprise me in the least.
If you think DHCP and a router will save you, then think again. Microsoft forced those updates even on companies computers, and we’re not talking mom and pop businesses either.
The registry can be accessed over a network connection for remote management/support, including from scripts, using the standard set of APIs, as long as the Remote Registry service is running and firewall rules permit this. Windows Registry - Wikipedia, the free encyclopedia
Laptop drives are encrypted, you can’t even boot it without the user name and password. The drive itself registers as empty if you try to look at it without the encryption software.
Well the Virus has to be on the machine before it can upload anything, so yeah you do need access on to the machine before you can steal information from it. That also means the outside security has to allow the virus through in the first place, and then allow the information it uploads back out. I would be fairly trivial for a proxy server to deny upload access to the puppet website.
As I have found over the years, less than 1/10th of hospitals, Universities, municipal governments, banks, law enforcement, pharmacies, and the list goes on actually encrypt the harddrives or even ensure any form of security on their Laptops. They are NOT encrypted right from the factory, the end user must do this or have their vendor/IT Dept do it. To talk with them, they aren’t interested as it adds an extra layer to linking the device into their networks.
You’d be surprised at just how many used laptops with sensitive info on them find their way to exchange sites.
I was talking directly about the UK MOD in the quote. Some of your examples aren’t governments departments either. I’ve yet to come across a single government agency where work-use laptops aren’t encrypted if they’re to have access to secure information.
No, of course not. But if the machine is business use it will be going through the IT department to be given the organisations standard build before it ever reaches the user.
I wouldn’t begin to think I can talk for every organisation in the world, but I will say this is completely counter to every situation I’ve ever come across.
I doubt I’d be surprised at all. I’m sure many users sell their personal laptops without clearing the hdd, in fact I’d suspect most do. I doubt that has any bearing on the practice of government agencies, which is what I was talking about, though.
There is a big difference between theory and practice. Also, there is a big difference between what really happens and what really documented and audited.
Also, there were reports about stolen laptops last year too from the Govt departments and I am sure that all the harddisk were not encrypted.
The mechanisms used to send out information from the machines to the outside world when an OS such as Windows is used, are too complex and misleading that most of the defending mechanisms may not detect them as backdoors.
Examples given are businesses and agencies and departments that handle our sensitive information. I’ve seen hundreds of drives not wiped, hundreds of working laptops still with private supposedly secure info on them without encryption.
No, of course not. But if the machine is business use it will be going through the IT department to be given the organisations standard build before it ever reaches the user.
Even IT depts fail to encrypt drives. In a perfect world yes, but we live in a world where people will skip steps until they smacked down hard.
I wouldn’t begin to think I can talk for every organisation in the world, but I will say this is completely counter to every situation I’ve ever come across.
I don’t presume to claim to talk to every business or organization. You’ve never seen it so your lucky I guess
I doubt I’d be surprised at all. I’m sure many users sell their personal laptops without clearing the hdd, in fact I’d suspect most do. I doubt that has any bearing on the practice of government agencies, which is what I was talking about, though.
But ok, I’ll modify what I said. Being from the UK, and having worked for many years in government IT, I can say categorically that back doors in windows are really no problem to any UK government department that would care about it. Using that example, I’d say any government worrying about back doors in Windows, should be more worried by their evidently shocking failure of security policy that makes a Windows back door relevant.
What makes you so sure, just out of curiosity.
It’s fairly trivial to stop a machine communicating with the outside world if you want to. I mean you can just unplug it, and you’ll find where security is a high issue the machines will be isolated from the outside world. In situations where you have machines that can go on the internet, they’re behind proxies, and although it can be non-trivial to tell good requests from bad, remember who’s building these systems. They’re not amateurs, they’re people who are well aware that others are trying to break into their systems, and most of those people are a hell of a lot more cunning than Microsoft. In short I stand by my original statement, if any government is worried about Microsoft back doors, it’s their own security they should be worried about.
To Add:
I didn’t mean to imply you were, just that I wasn’t, in case there was any misunderstanding.
If there’s ever an IT department that should be encrypting laptops and don’t, they should all be dismissed on the spot. Obviously things are different in the private sector, but over here such negligence within a secure government department would be subject to prosecution.