EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

12.06.10

Wikileaks/Cablegate Reveals That Microsoft Gave Windows Source Code to TOPSEC, Which Trains and Employs Chinese Cyberspies

Posted in Microsoft, Security, Windows at 11:56 am by Dr. Roy Schestowitz

Kevin Mitnick
Putting Windows source code in the hands
of the Kevin Mitnicks of China

Summary: Microsoft equips private companies — not just governments — with just what they need to intrude all Windows-running computers, namely a key to potential remote access without liability

NOT just incompetence and negligence [1, 2, 3] are the cause of Microsoft’s security problems. Based on Cablegate leaks, it is possible that Microsoft’s secret (and poorly audited) code is exploited so often in China because Microsoft gives them access to this source code (which security researchers in the West cannot see and scrutinise prior to release in binary form).

Several days ago we showed some Egypt cables (prior to Wikileaks being targeted by censors) and it helped show just how closely Microsoft works with governments on ‘security’. The Guardian noticed this independently from us and highlighted the following block (filed under “US embassy cables: China uses access to Microsoft source code to help plot cyber warfare, US fears”):

56. (S//NF) CTAD comment: Additionally, CNITSEC enterprises has recruited Chinese hackers in support of nationally-funded “network attack scientific research projects.” From June 2002 to March 2003, TOPSEC employed a known Chinese hacker, Lin Yong (a.k.a. Lion and owner of the Honker Union of China), as senior security service engineer to manage security service and training. Venus Tech, another CNITSEC enterprise privy to the GSP, is also known to affiliate with XFocus, one of the few Chinese hacker groups known to develop exploits to new vulnerabilities in a short period of time, as evidenced in the 2003 release of Blaster Worm (See CTAD Daily Read File (DRF) April 4, 2008). 57. (S//NF) CTAD comment: While links between top Chinese companies and the PRC are not uncommon, it illustrates the PRC’s use of its “private sector” in support of governmental information warfare objectives, especially in its ability to gather, process, and exploit information. As evidenced with TOPSEC, there is a strong possibility the PRC is harvesting the talents of its private sector in order to bolster offensive and defensive computer network operations capabilities. (Appendix sources 51-52)

So, not just governments are getting access to source code. The “agreement with Microsoft… allowed select companies such as TOPSEC access to MICROSOFT source code in order to secure the Windows platform.” Here it is in raw form. “TOPSEC that trains most of china cyberspys,” Oiaohm quotes from it. “It’s in that cable,” he says. He then gives another direct quote from the cable: “TOPSEC provides services and training for the PLA and has recruited hackers in the past.” On this one he remarks: “Then latter on in the cable to says they have been granted access to MS source code.” The remainder can be read in our latest IRC logs, which make operation of this Web site entirely transparent, unlike governments. “Security by obscurity is that you don’t give the source code to the people attacking your system,” Oiaohm adds and “[i]If you are not using Security by obscurity you might as well publish the source code for everyone to see… At least then you have a better chance that truful ones will tell you where the flaws are.” (typos corrected)

“Proper obscurity can be done with open source”
      –Oiaohm
He continues: “that cable is a security research document in what the hell has gone wrong… That the USA was being breached so much… Also if you dig deeper the USA side is doing the same thing… Both are trying to use closed source to give them a cyberadvantage while both have access to the source code… Proper obscurity can be done with open source… Each system must be able to have many different combinations in its security system to attacker is not quite sure what he will be walking into… So attacks take longer to develop… MS Windows where most installs have basically the same security config… Basically have a obscurity level of nothing.”

Another cable speaks of an “invitation for a private meeting with a named DoS employee. The attached Microsoft Word document was a malicious”. Microsoft is mostly mentioned negatively (for security reasons) in Cablegate, at least thus far. What will be revealed in the remaining 99% of Cablegate (the part which has not been published yet)?

In actual security news (not leaks of old confidential reports), Vista 7 is being bricked by software which claims to improve Windows security:

THOSE WHO ARE RUNNING 64-bit Windows 7 systems should not download the update for AVG Technologies’ AV software.

AVG has withdrawn the update after complaints that the update completely bricked systems by forcing computers to go into an infinite crash loop.

Users of GNU/Linux and BSD never have such problems. Why won’t the US government encourage adoption of Free software, whose transparency makes it secure? It’s the same fallacy about secrecy which toppled both Windows security and now the US government. It arguably censors Wikileaks more zealously than other governments.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. twitter said,

    December 6, 2010 at 4:09 pm

    Gravatar

    Source code disclosure is not a source of insecurity, it is the exclusive disclosure of insecure code to malicious parties that’s the problem. When software is free it can gain a high degree of both transparency and security like OpenBSD and gnu/linux have. When software is not free, the owners lack resources to fix things. Known problems persist for decades and new problems are constantly found when old, non free code bases are forced together in monstrosities like Microsoft Windows. The absolute worst case is when malicious organizations are given exclusive access to source code that other people use. Sadly, this is always the case when people are using non free software but few have betrayed their users the way Microsoft has.

    It has long been known that sharing code with China and other US enemies was a US national security risk. Microsoft representatives testified to this in the Netscape anti-trust trials. Just a few later they started sharing code with the PRC, the former KGB and many other US hostile organizations. It is nice to see that US diplomats were aware of this betrayal but we have to wonder why the US government has not acted on the knowledge. Windows should be dumped and those responsible at Microsoft should be put on trail for espionage.

What Else is New


  1. IBM's Manny Schecter is Wrong Again and He is Attempting to Justify Patent Trolling

    In yet another dodgy effort to undermine the US Supreme Court and bring back software patents, IBM's "chief patent counsel" (his current job title) expresses views that are bunk or "alternative facts"



  2. EPO Administrative Council Disallows Discussion About Violations of the Law by Benoît Battistelli

    The EPO crisis is not ending for the Administrative Council does not want to tackle any of the obvious problems; Patrick Corcoran is a taboo subject and Ernst is coming across as another protector of Benoît Battistelli, based on today's meeting (the second meeting he chairs)



  3. Links 13/12/2017: GIMP 2.9.8, Fedora 25 End Of Life, AltOS 1.8.3

    Links for the day



  4. Judge Corcoran Got His User ID/Desk Back (as ILO Asked), But Cannot Perform Actual Work

    The latest update regarding Patrick Corcoran, whose 3-year ordeal is far from over in spite of ILO's unambiguous rulings in his favour



  5. The End of Software Patents and PTAB's Role in Enforcing That End

    Software patents are fast becoming a dying breed and the appeal board (PTAB) of the USPTO accelerates this trend, irrespective of patent immunity attempts



  6. No, China Isn't Most Innovative, It's Just Granting a Lot of Low-Quality Patents

    Patent extremists are trying to make China look like a role model or a success story because China grants far too many patents, spurring an explosion in litigation



  7. Battistelli-Campinos Transition Will Be a Smooth One as the Administrative Council Remains the Same and the Boards Still Besieged

    A rather pessimistic (albeit likely realistic) expectation from tomorrow's meeting of the Administrative Council, which continues to show that no lessons were learned and no strategy will be altered to avoid doom (low-quality patents and stocks running out)



  8. Links 12/12/2017: New BlackArch ISO and Stable Kernels

    Links for the day



  9. German Media Helps Cover Up -- Not Cover -- the Latest EPO Scandal

    EPO-Handelsblatt attention diversion tricks may be effective as German media barely shows interest in one of the EPO's biggest scandals to date



  10. PTAB Haters Fail to Guard Bogus Patents, But They Still Try

    Three Affiliated Tribes probably won't enjoy sovereign immunity from PTAB, Dennis Crouch won't manage to slow down PTAB, and patent litigation will stagnate as bad patents perish before they even land in a lawsuit



  11. Team UPC's Tilmann Defends Rogue Vote at 1 AM in the Morning With Just 5% of Politicians (Those With Vested Interests) Attending

    Just when German democracy is being stolen by a legislative coup (in the dead of night when 95% of politicians are absent/asleep) there's someone 'courageous' enough to rear his ugly head and attempt to justify that coup



  12. The Mask Falls: Lobbyist David Kappos Now Composes Pieces for the Patent Trolls' Lobby (IAM)

    David Kappos, a former USPTO Director who is now lobbying for large corporations that derive revenue from patent extortion, is writing for IAM even if his views are significantly biased by his aggressive paymasters (just like IAM's)



  13. The EPO Protest Tomorrow Isn't Just About Judge Corcoran But About the EPO as a Whole

    PO staff is about to protest against the employer, pointing out that "Battistelli is still showing a total and utter lack of respect not only for his staff and their rights but also for the Administrative Council and for the Tribunal"



  14. Claim: Judge Corcoran to Be Put Under Benoît Battistelli's Control in DG1

    Benoît Battistelli, who openly disregards and refuses to obey judges (while intervening in trials and delivering 'royal decrees' whenever it suits him), may soon gain direct control over the judge he hates most



  15. The European Patent Organisation Refrains (For Nearly a Week) From Speaking About Battistelli's Abuses as Judged by ILO Tribunal

    The EPO's silence on the matter of Patrick Corcoran is deafening; to make matters worse, the EPO continues to pollute media and academia with money of stakeholders, with the sole intention of lobbying and misleading news coverage (clearly a disservice to these stakeholders)



  16. Carl Josefsson Lets Judge Patrick Corcoran Come Back to Work at the EPO

    After initial reluctance to obey/respect the rulings from the ILO (security staff declining access) there is official permission for Patrick Corcoran to enter and resume work (following 3 years of injustice against him)



  17. Bristows is Being Hammered With Negative Comments For Its Unitary Patent (UPC) Lies

    The Unified Patent Court (UPC) is practically dead in the UK and Ireland; Bristows, nevertheless, continues with its desperate spin



  18. Links 11/12/2017: Linux 4.15 RC3, Debian 8.10 and Debian 9.3

    Links for the day



  19. Judge Corcoran Turns to His Government for Help and EPO 'House Ban' is Finally Lifted

    Sources that are very reliable say that Patrick Corcoran is coming back to work, however it's now clear when and how long for



  20. Raw: Battistelli's Control/Domination Over the Boards of Appeal

    An old EPO document internally voicing concerns about the lack of independence at the Boards of Appeal



  21. Raw: Conflicts of Interest of EPO Vice-President

    An old EPO concern regarding structural collisions and mixed loyalties



  22. Microsoft-Connected Patent Trolls Are Increasingly Active and Microsoft is Selling 'Protection' (Azure Subscriptions)

    There are several indications that Microsoft-connected shells, which produce no products and are threatening a large number of companies, are inadvertently if not intentionally helping Microsoft sell "indemnification" ("Azure IP Advantage," which echoes the Microsoft/Novell strategy for collecting what they called "patent royalties" one decade ago)



  23. Yes, RPost is Definitely a Patent Troll and Its Software Patents Are at Risk Thanks to Alice

    The latest whitewashing (or reputation-laundering) pieces from Watchtroll, which tries to justify patent-trolling activities with software patents, typically in the Eastern District of Texas



  24. The Latest Scams in the Patent World

    Examples of 'dirty laundry' of the patent microcosm, which it understandably does not like covering (as it harms confidence in their services/advice)



  25. Patents Are Becoming a Welfare System for the Rich and Powerful

    A culture of litigation and more recently the patenting of broad industry standards may mean that multi-billion dollar corporations are cashing in without lifting a finger



  26. Unlike the Mobile Domain, When it Comes to Cars Patent Lawsuits Remain Rare

    An optimistic note regarding the relatively low-temperature legal landscape surrounding advanced automobiles, even though patents are being amassed on software in that domain



  27. The Federal Circuit Rules (Again) in Favour of Section 101/Alice, Koch-Funded CPIP Tries to Overturn Alice at the Supreme Court

    The US Supreme Court's decision on Alice continues to have a profoundly positive impact (except for trolls) and Koch-funded academics try hard to compel the US Supreme Court to reverse/override Alice (so far to no avail)



  28. Next Director of the USPTO Parrots Talking Points of Patent Extremists and Their Lobbyists

    The next USPTO boss (still subject to official confirmation) may be little more than a power grab by the litigation and patenting 'industry', which prioritises not science and technology but its own bottom line



  29. Raw: Three Years for 'Justice' (to be Disregarded by Benoît Battistelli) at ILO and Over a Decade at the EPO

    The delays associated with ‘justice’ at the EPO (usually neither justice nor compliance with rulings) have become so extraordinary that immunity should long ago have been stripped off and Battistelli et al been held accountable



  30. Raw: Scuttling of the General Advisory Committee and Battistelli Stacking the Deck to Have 'Yes Men' as Representatives

    How the EPO broke down resistance to Battistelli’s oppressive policies not only at the Council, disciplinary committees and auditory divisions but also staff representation (symptomatic of Battistelli’s notion of justice)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts