[117440] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: NSA key in MSFT Crypto API

daemon@ATHENA.MIT.EDU (AMP)
Fri Sep 3 09:05:26 1999

Message-ID: <37CFC391.7EC03FA3@pobox.com>
Date: Fri, 03 Sep 1999 07:48:17 -0500
From: AMP <amp@pobox.com>
MIME-Version: 1.0
To: cypherpunks@cyberpass.net
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Reply-To: AMP <amp@pobox.com>

=snip=
> Background: MSFT CAPI comes pre-installed with two keys used to check the
> validity of a Cryptographic Service Provider (CSP). The holder of either key
> can install operating system security services without user authorization.
> The first key is used by MSFT to sign their own security services modules.
> The identity of the second key holder until now been unknown. That is to say
> until MSFT forgot to strip the binary of NT4 SP5 off debugging symbols.
> 
> Perhaps not surprisingly, the debugging symbol for the second key is...
> _NSAKEY,
> 
> For more information and a program to remove the NSA's key from your copy of
> Windows 95, 98, NT, 2000, see
> http://www.cryptonym.com/hottopics/msft-nsa.html
=snip=

hmmm.....

Wouldn't this be an excellent point of failure for a group to hack
against, like say, Distributed.net or some similar group of networked
computers?

Inquiring minds want to know.

-- 
amp@pobox.com
http://zeugma.nu/

What part of "shall not be infringed" do you not understand?

"Come and take it!"


home help back first fref pref prev next nref lref last post