Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Occulus

(20,599 posts)
Sun Jun 16, 2013, 10:11 PM Jun 2013

Confirmed: Microsoft Tells the NSA About Back Doors in Windows

Posted in Microsoft at 7:22 am by Dr. Roy Schestowitz

Half a decade ago I put together some links about backdoors in Windows. I had accumulated those links for years. Now that we know how corrupt and aggressive the NSA can be (common knowledge after the latest leak), with cracking attacks on China, espionage, and unlimited mass surveillance in a fascistic manner (with corporations fully complicit), it all seems far less improbable and hardly far-fetched.

According to a new report from the corporate press (as corporate as it can get, being Bloomberg), Microsoft tells NSA staff about universal unpatched holes before they are being addressed:

Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes.

Redmond, Washington-based Microsoft (MSFT) and other software or Internet security companies have been aware that this type of early alert allowed the U.S. to exploit vulnerabilities in software sold to foreign governments, according to two U.S. officials. Microsoft doesn’t ask and can’t be told how the government uses such tip-offs, said the officials, who asked not to be identified because the matter is confidential.

Frank Shaw, a spokesman for Microsoft, said those releases occur in cooperation with multiple agencies and are designed to be give government “an early start” on risk assessment and mitigation.

[font size="1"]http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html[/font]


Glyn Moody asked, “why would anyone ever trust Microsoft again…?”

Frank Shaw is not a technical man. His job is to lie, e.g. about sales of Vista 8 (quite famously and most recently). He came from Waggener Edstrom, a lying and AstroTurfing company. The above should be read as follows: when new holes exist which permit remote hijacking the unaccountable, cracking-happy NSA is being notified. What can possibly go wrong now that we have proof that the NSA is cracking PCs abroad with impunity? Germany, are you paying attention?

---

Much, much more in the articles at the Microsoft link that begins this post (ex.: Skype is fully compromised, too), as well as in the references and cross-references. Ladies and gentlemen, this is an even worse situation than the most "hair on fire paranoids" (to coin a phrase) are warning us about. To put it simply:

Somebody set us up the bomb.

Main screen turn on.

All your base are belong to us.
5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Confirmed: Microsoft Tells the NSA About Back Doors in Windows (Original Post) Occulus Jun 2013 OP
Indeed! Newest Reality Jun 2013 #1
It would appear that the use of open-source software is a solution, Occulus Jun 2013 #2
I know. Newest Reality Jun 2013 #3
It's not hopeless yet cypherpunks Jun 2013 #4
Two words: LAGC Jun 2013 #5

Newest Reality

(12,712 posts)
1. Indeed!
Sun Jun 16, 2013, 10:23 PM
Jun 2013

All your base are belong to us!

That's the name of the game. There is no other game that matches it and it is a play for keeps, no holds barred one.

Anybody who lives in this world and thinks that the game is not being played and they are not being played is really living in the land of the naive. I mean, that's okay, but at least put a sign at the entrance so that everyone who falls for it knows where they live.

The intellect as mind is nothing other than a game of oneupmanship. Even though we love reason and thinking and have put it on high now, above the higher orders of abstraction that the usurpers of religion once held, it is also a two-edged sword and that sword is now slicing us from the side we don't want to accept and cannot seem to like.

If I have some knowledge or information that you do not have access to, I can use it in a skillful and adept way to control you in various ways, from overt to covert. That's the ultimate name of this game and it has been since somebody figured out that pulling leaves over their body was a way to keep warm while others froze to death. Now, it is, "I can send my kids to college in hopes that they can tell your kids what to do while making grossly more amounts of money, (which equals more power, control and choice in an intellect-based capitalistic system).

So, while we extol the reasoning, intellect, technology and information side of life, it spits daggers in our faces, (even with religion on the sidelines now) because we don't seem to get the general gist of how this works in a more transcendent sense when it comes to the sequestration of information and the expertise of involving nothing more than symbols.

If you understand that, then maybe you can get a good intuition of both what is wrong with this game when it comes to winners and losers and where the exit point from being totally bound by concepts and beliefs comes in.

If not, then we return you to your regularly scheduled channels and your conditioned action/reaction indoctrinations which will reveal both the same old thing plus new versions of it where you end-up losing your true nature and any power that is rightfully yours in the way it correlates with the whole of experience as it is.

Yup!

Occulus

(20,599 posts)
2. It would appear that the use of open-source software is a solution,
Sun Jun 16, 2013, 10:31 PM
Jun 2013

but you can't really say that unless you can:

1) examine the code that the compiler is compiled with to compile the code you're using

2) access the hardware instructions on the CPU etc

3) examine the code in the BIOS of the machine upon which the CPU etc. is installed

4) examine the code that compiled the compiler that built the BIOS

etc., and etc.

In other words, you can't ever know that your own computer is compromised unless you have end-to-end control over every single element of the entire machine, software and hardware, including the software and hardware that built the machine you're using to build your own software.

Fuck me running.

Newest Reality

(12,712 posts)
3. I know.
Sun Jun 16, 2013, 10:36 PM
Jun 2013

What you have just described is called the wisdom of insecurity.

I won't go into it here, but if you search, you may find out that that dilemma has already been covered and is nothing new, of course. Knowing the details of how that works though, is, at least, a philosophical consolation and adds some useful lines of code to your conceptual database.

cypherpunks

(1 post)
4. It's not hopeless yet
Sat Jun 22, 2013, 02:20 PM
Jun 2013

People are working on end-to-end open source computing:
http://www.bunniestudios.com/blog/?p=2686

Also, your points about the compiler trust are important, but there are ways to validate open source compilers and compiled code against tampering and backdoors.

To validate against tampering in the specific compiler/build machine that compiled your code, a technique called "deterministic building" is required. Basically, two or more independent machines use the same compiler to produce identical binaries. This technique can be extended to ensure against OS-level backdoors through the use of the same compiler source code on multiple Linux distributions.

To validate against the "Trusting trust"-style compiler backdoors, you get two or more compilers to compile eachother twice, and compare the resulting binaries (this is called Diverse Double-Compiling):
http://www.schneier.com/blog/archives/2006/01/countering_trus.html

Very few open source software projects do all of this yet, but hopefully this recent news will wake more people up!

Latest Discussions»General Discussion»Confirmed: Microsoft Tell...