RSS



Go Back   bit-tech.net Forums > bit-tech.net > Article Discussion

Reply
 
Thread Tools
Old 19th Dec 2007, 11:57   #1
CardJoe
Player Character
bit-tech Staff
 
CardJoe's Avatar
 
Join Date: Apr 2007
Posts: 7,940
CardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to beholdCardJoe is a splendid one to behold
Crypto 'backdoor' in Vista SP1

http://www.bit-tech.net/news/2007/12...or_vista_sp1/1

Microsoft is due to ship a flawed random number generator with the latest Windows Vista service pack, which has the potential to put your encrypted data at risk.

__________________
CardJoe is offline   Reply With Quote
Old 19th Dec 2007, 18:46   #2
Cupboard
I'm not a modder.
 
Cupboard's Avatar
 
Join Date: Jan 2007
Location: Bury St Edmunds/Durham Uni
Posts: 1,840
Cupboard has a spectacular aura aboutCupboard has a spectacular aura about
Even including it is a bad idea - someone will use it, either accidentally or being secure only for the pretence of being innocent while some data is nicked. It is a broken feature, with no legit use that I can see, that just serves to increase the bloat.

Silly MS... oh well.

Do we know why they didn't just forget about it and quietly remove it?
__________________
i7 920, 8800GTS 512, 6GB Corsair all in an Intel DX58SO; 3*320GB RAID5; CM Stacker
Samsung Q45.
Cupboard is offline   Reply With Quote
Old 19th Dec 2007, 20:22   #3
Starfighter
Multimodder
 
Join Date: Apr 2004
Location: Manchester, UK
Posts: 152
Starfighter is on a distinguished road
So, in order to organise an attack on a computer, a malicious user would have to somehow alter the code of an application, so that it used this flawed PRNG?

This is hardly an issue, as if a malicious user is changing program code, surely he could just make it use his MAGIC_PRNG, which always returns ... 2?

But that would hardly generate a front page story eh?
__________________
Rob - sennir.co.uk | Photography Guide
Starfighter is offline   Reply With Quote
Old 19th Dec 2007, 21:55   #4
sendrome
the whole #!/bin/sh
 
Join Date: Dec 2007
Location: Houston, TX
Posts: 3
sendrome is on a distinguished road
I don't think this makes Vista less secure.

OK sure the Dual_EC_DRNG has a potential back door, but no one knows for sure who has this second set of secret numbers. We do know that no one has published this "Skeleton Key" yet and there is a chance no one ever will. Also, because it is off by default, average users most likely won't ever enable this setting on purpose or by accident.

But yes, it does make one wonder why MS wouldn't just exclude this flawed encryption.... Conspiracy?
sendrome is offline   Reply With Quote
Old 20th Dec 2007, 10:53   #5
DeXtmL
Modder
 
DeXtmL's Avatar
 
Join Date: Sep 2007
Posts: 50
DeXtmL is on a distinguished road
Quote:
Originally Posted by sendrome
But yes, it does make one wonder why MS wouldn't just exclude this flawed encryption.... Conspiracy?
Indeed, why keep this flawed version of random generator in the not-yet published sp1? What difficulty makes microsoft think it's necessary to ship the potential backdoor to us endusers?
__________________
We are "netted" together!
DeXtmL is offline   Reply With Quote
Old 25th Dec 2007, 00:51   #6
completemadness
Hypermodder
 
Join Date: May 2007
Posts: 887
completemadness is on a distinguished road
Its already in Vista (and all other NT based OS's)

I'm guessing its not because they've put it in, but because they haven't taken it out
It might actually be difficult to remove it in a Service pack
completemadness is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 19:34.
Powered by: vBulletin Version 3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.