[117440] in Cypherpunks
Re: NSA key in MSFT Crypto API
daemon@ATHENA.MIT.EDU (AMP)
Fri Sep 3 09:05:26 1999
Message-ID: <37CFC391.7EC03FA3@pobox.com>
Date: Fri, 03 Sep 1999 07:48:17 -0500
From: AMP <amp@pobox.com>
MIME-Version: 1.0
To: cypherpunks@cyberpass.net
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Reply-To: AMP <amp@pobox.com>
=snip=
> Background: MSFT CAPI comes pre-installed with two keys used to check the
> validity of a Cryptographic Service Provider (CSP). The holder of either key
> can install operating system security services without user authorization.
> The first key is used by MSFT to sign their own security services modules.
> The identity of the second key holder until now been unknown. That is to say
> until MSFT forgot to strip the binary of NT4 SP5 off debugging symbols.
>
> Perhaps not surprisingly, the debugging symbol for the second key is...
> _NSAKEY,
>
> For more information and a program to remove the NSA's key from your copy of
> Windows 95, 98, NT, 2000, see
> http://www.cryptonym.com/hottopics/msft-nsa.html
=snip=
hmmm.....
Wouldn't this be an excellent point of failure for a group to hack
against, like say, Distributed.net or some similar group of networked
computers?
Inquiring minds want to know.
--
amp@pobox.com
http://zeugma.nu/
What part of "shall not be infringed" do you not understand?
"Come and take it!"