[117468] in Cypherpunks
Re: NSA key in MSFT Crypto API
daemon@ATHENA.MIT.EDU (Benjamin T. Love)
Fri Sep 3 17:51:06 1999
Message-ID: <37D058CF.F996B5BA@means.net>
Date: Fri, 03 Sep 1999 16:25:03 -0700
From: "Benjamin T. Love" <benlove@means.net>
MIME-Version: 1.0
To: "William H. Geiger III" <whgiii@openpgp.net>
CC: "Trei, Peter" <ptrei@securitydynamics.com>,
"'Lucky Green'" <shamrock@cypherpunks.to>,
"cypherpunks@Algebra. COM" <cypherpunks@Algebra.COM>,
"'Salz,Rich'" <SalzR@CertCo.com>,
"Cryptography@C2. Net" <cryptography@c2.net>,
bugtraq@securityfocus.com
Content-Type: multipart/alternative; boundary="------------5C29FDF84C5242E3B2D68ACD"
Reply-To: "Benjamin T. Love" <benlove@means.net>
--------------5C29FDF84C5242E3B2D68ACD
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Surely there's an attorney out there who would love to file a class action
suit against Microsoft that it would be allowed to settle by replacing all
existing Windows operating systems with systems without these flaws.
William H. Geiger III wrote:
> In <D104150098E6D111B7830000F8D90AE8E62A42@exna02.securitydynamics.com>,
> on 09/03/99
> at 11:49 AM, "Trei, Peter" <ptrei@securitydynamics.com> said:
>
> >The ability to replace the NSA key with another
> >is an extremely serious vulnerability. This means that
> >*anyone* - not just the NSA - can write a compromised
> >module and install it on the target, as long as they
> >also replace the NSA key with the one they used to
> >sign the weakened module.
>
> >Tripwire, anyone?
>
> It's very simple, DO NOT USE WINDOWS!!
>
> This is a compromise in only one API. God only knows what they have done
> to compromise security in the millions of lines of code that no one
> outside of Redmond has ever seen.
>
> Windows is compromised!! Microsoft is in bed with the Federal Government.
> There is *no* security on a system running their software. Those who
> continue to do so get exactly what they deserve.
>
> --
> ---------------------------------------------------------------
> William H. Geiger III http://www.openpgp.net
> Geiger Consulting Cooking With Warp 4.0
>
> Author of E-Secure - PGP Front End for MR/2 Ice
> PGP & MR/2 the only way for secure e-mail.
> OS/2 PGP 5.0 at: http://www.openpgp.net/pgp.html
> Talk About PGP on IRC EFNet Channel: #pgp Nick: whgiii
>
> Hi Jeff!! :)
> ---------------------------------------------------------------
--
Benjamin T. Love / benlove@means.net / http://www.ncrypt.com
--------------5C29FDF84C5242E3B2D68ACD
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML>
Surely there's an attorney out there who would love to file a class action
suit against Microsoft that it would be allowed to settle by <U>replacing</U>
<U>all</U> existing Windows operating systems with systems without these
flaws.
<P>William H. Geiger III wrote:
<BLOCKQUOTE TYPE=CITE>In <D104150098E6D111B7830000F8D90AE8E62A42@exna02.securitydynamics.com>,
<BR>on 09/03/99
<BR> at 11:49 AM, "Trei, Peter" <ptrei@securitydynamics.com>
said:
<P>>The ability to replace the NSA key with another
<BR>>is an extremely serious vulnerability. This means that
<BR>>*anyone* - not just the NSA - can write a compromised
<BR>>module and install it on the target, as long as they
<BR>>also replace the NSA key with the one they used to
<BR>>sign the weakened module.
<P>>Tripwire, anyone?
<P>It's very simple, DO NOT USE WINDOWS!!
<P>This is a compromise in only one API. God only knows what they have
done
<BR>to compromise security in the millions of lines of code that no one
<BR>outside of Redmond has ever seen.
<P>Windows is compromised!! Microsoft is in bed with the Federal Government.
<BR>There is *no* security on a system running their software. Those who
<BR>continue to do so get exactly what they deserve.
<P>--
<BR>---------------------------------------------------------------
<BR>William H. Geiger III <A HREF="http://www.openpgp.net">http://www.openpgp.net</A>
<BR>Geiger Consulting Cooking With Warp 4.0
<P>Author of E-Secure - PGP Front End for MR/2 Ice
<BR>PGP & MR/2 the only way for secure e-mail.
<BR>OS/2 PGP 5.0 at: <A HREF="http://www.openpgp.net/pgp.html">http://www.openpgp.net/pgp.html</A>
<BR>Talk About PGP on IRC EFNet Channel: #pgp Nick: whgiii
<P>Hi Jeff!! :)
<BR>---------------------------------------------------------------</BLOCKQUOTE>
--
<BR>Benjamin T. Love / benlove@means.net / <A HREF="http://www.ncrypt.com">http://www.ncrypt.com</A>
<BR> </HTML>
--------------5C29FDF84C5242E3B2D68ACD--