[117443] in Cypherpunks
RE: NSA key in MSFT Crypto API
daemon@ATHENA.MIT.EDU (Lucky Green)
Fri Sep 3 10:24:53 1999
Date: Fri, 03 Sep 1999 07:11:22 -0700
From: Lucky Green <shamrock@cypherpunks.to>
In-reply-to: <37CFC391.7EC03FA3@pobox.com>
To: amp@pobox.com, cypherpunks@cyberpass.net
Message-id: <NDBBIFGOKODBCKDGJDKLAEDKCFAA.shamrock@cypherpunks.to>
MIME-version: 1.0
Content-type: text/plain; charset="iso-8859-1"
Content-transfer-encoding: 7bit
Reply-To: Lucky Green <shamrock@cypherpunks.to>
NSAKEY is 1024 bits RSA. D.net does not stand a chance of breaking it.
--Lucky Green <shamrock@cypherpunks.to>
> -----Original Message-----
> From: owner-cypherpunks@Algebra.COM
> [mailto:owner-cypherpunks@Algebra.COM]On Behalf Of AMP
> Sent: Friday, September 03, 1999 05:48
> To: cypherpunks@cyberpass.net
> Subject: Re: NSA key in MSFT Crypto API
>
>
>
> =snip=
> > Background: MSFT CAPI comes pre-installed with two keys used to
> check the
> > validity of a Cryptographic Service Provider (CSP). The holder
> of either key
> > can install operating system security services without user
> authorization.
> > The first key is used by MSFT to sign their own security
> services modules.
> > The identity of the second key holder until now been unknown.
> That is to say
> > until MSFT forgot to strip the binary of NT4 SP5 off debugging symbols.
> >
> > Perhaps not surprisingly, the debugging symbol for the second key is...
> > _NSAKEY,
> >
> > For more information and a program to remove the NSA's key from
> your copy of
> > Windows 95, 98, NT, 2000, see
> > http://www.cryptonym.com/hottopics/msft-nsa.html
> =snip=
>
> hmmm.....
>
> Wouldn't this be an excellent point of failure for a group to hack
> against, like say, Distributed.net or some similar group of networked
> computers?
>
> Inquiring minds want to know.
>
> --
> amp@pobox.com
> http://zeugma.nu/
>
> What part of "shall not be infringed" do you not understand?
>
> "Come and take it!"
>
>