[11761] in bugtraq
Re: NSA key in MSFT Crypto API
daemon@ATHENA.MIT.EDU (John Gilmore)
Wed Sep 8 22:43:36 1999
Message-Id: <199909032032.NAA10419@toad.com>
Date: Fri, 3 Sep 1999 13:32:19 -0700
Reply-To: John Gilmore <gnu@TOAD.COM>
From: John Gilmore <gnu@TOAD.COM>
X-To: "Salz, Rich" <SalzR@CertCo.com>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <29E0A6D39ABED111A36000A0C99609CA51D43B@macertco-srv1.ma.certco.com>
> >http://www.cryptonym.com/hottopics/msft-nsa.html
>
> Perhaps more interestingly, the program lets you replace the key, too.
Microsoft prevents third parties from installing un-authorized crypto
code under CAPI by checking the signature on the code. Under their
export deal, they refuse to sign anyone's non-US code that does strong
crypto. So if you want to add your own strong crypto, you need to sign
it with a key that the CAPI recognizes. You could patch out Microsoft's
key but then the Microsoft modules won't load properly. It works
better to patch out NSA's key with your own -- then you can load both
your own crypto code and all the standard MS stuff.
John