EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.18.13

NSA-Created Malware Used Politically and Relied on Microsoft-Provided Back Doors/Weak Encryption

Posted in Action, Microsoft at 5:11 am by Dr. Roy Schestowitz

Hardware

Summary: A roundup of privacy-related news, with special focus on the role played by proprietary software in political espionage

SINCE Microsoft and the NSA are so close and we already know about NSA attempts to put back doors in operating systems, it should not be surprising that Microsoft Windows has a back door (more likely sevral) and Stuxnet was made possible to devise/deploy on Windows. Based on some news from Ars Technica [1], now that a lot of this shocking information is out there, Microsoft is trying to shift away from weak encryption (or breakable encryption), but it’s likely to be too late because Microsoft made such weakness a standard. “Microsoft is retiring two widely used cryptographic technologies that are growing increasingly vulnerable to attacks,” the article says. Further down the article notes: “The state-sponsored Flame malware that targeted Iran pulled off the only known in-the-wild collision attack earlier this decade. Using a never-before seen technique to subvert the MD5 algorithm, Flame-infected computers were able to pose as official servers belonging to Microsoft. By forging Microsoft’s digital signatures, the infected machines were able to trick uninfected computers into installing highly malicious software they otherwise would have refused. Microsoft has since decommissioned MD5 in its update system. Tuesday’s advisory indicates that the company is aiming to learn from that past incident by retiring SHA1 before it falls to the same type of attack.”

But why not assume that this weakness was the result of complicity (with the NSA) rather than an “incident” or some kind of accident? There are other bits of Microsoft software which gleefully invite the NSA in, e.g. Skype (incidentally, the researcher who showed it could be maliciously exploited has just died in an accident [2]).

We need to accept the fact that a lot of software is insecure by design. It’s designed to give power to particular parties, not the users. It’s an important distinction which helps show why proprietary software oughtn’t be trusted.

In other news, the United States’ “Internet Kill Switch” is back in the headlines [3] and countries like Germany are expected to have something to say [4]. Snowden’s E-mail provider is taking privacy up a notch [5] and Snowden’s leaks are said to be having an impact on privacy perceptions [6] because companies like Facebook [7], Google [8], and of course Microsoft do not protect users’ privacy at all. Facebook is notably worse because it helps the government train face recognition classifiers for people whose friends tag them [9]. In case of protests, for example, activists can be identified and named (which helps those who crush protests or intimidate protesters [10]).

There seems to be a shift motivating encryption of the Web [11] and rejection of proprietary software [12] because privacy rights are being misused [13-16], only making privacy advocates stronger and more popular [17]. In the UK, privacy abuses against foreign leaders [18] have been damaging, but not as damaging as the Streisand Effect caused by the attack on the press and on privacy advocates [19].

Related/contextual items from the news:

  1. Hoping to avert “collision” with disaster, Microsoft retires SHA1
  2. Security researcher Cédric ‘Sid’ Blancher dead at 37

    In 2006, while working for the EADS Corporate Research centre, he also put together a paper on how to exploit Skype to act as a botnet.

  3. EPIC Prevails in FOIA Case About “Internet Kill Switch”

    In a Freedom of Information Act case brought by EPIC against the Department of Homeland Security, a federal court has ruled that the DHS may not withhold the agency’s plan to deactivate wireless communications networks in a crisis. EPIC had sought “Standard Operating Procedure 303,” also known as the “internet Kill Switch,” to determine whether the agency’s plan could adversely impact free speech or public safety.

  4. Germany struggling to respond to NSA revelations
  5. DarkMail Alliance Wants To Upgrade Gmail’s Security
  6. Snowden effect: young people now care about privacy
  7. Friday Shame: Facebook reminds you that your posts are also its ads

    “Ads work the same way and just as with all of the content on Facebook, we show you which of your friends have interacted with something to make it more relevant to you,” Facebook chief privacy officer Erin Egan write in a post posted at 12:05PM ET on Friday

    While Facebook made a point to clarify the new privacy policy, it’s actually changing very little about it — despite all the backlash the changes caused when they were initially introduced.

  8. Google will soon display your Google+ photo when you call an Android phone
  9. US intelligence wants to radically advance facial recognition software

    Identifying people from video streams or boatloads of images can be a daunting task for humans and computers.

  10. EFF Appeals Chevron’s Speech-Chilling Subpoena

    On Halloween of this year, EFF and EarthRights International (ERI) filed an appeal in the Second Circuit (PDF) to protect the rights of dozens of environmental activists, journalists, and attorneys from a sweeping subpoena issued by the Chevron Corporation. And just last week, both the Republic of Ecuador (PDF) and a group consisting of Human Rights Watch, Automattic, a pair of anonymous bloggers, and academics Ethan Zuckerman and Rebecca McKinnon (PDF) filed amicus briefs in support of our appeal.

  11. Internet architects propose encrypting all the world’s web traffic

    A vastly larger percentage of the world’s web traffic will be encrypted under a near-final recommendation to revise the Hypertext Transfer Protocol (HTTP) that serves as the foundation for all communications between websites and end users.

  12. Revenge of the Dragon

    This could spawn migration to GNU/Linux on client and server in governments globally not just a few early adopters like Europe, China, India, Brazil and Russia. By next year there could be dozens of governments making the move. I advised Canada to do that years ago. They might have another idea now that USA is the biggest threat in the world to cybersecurity with documented attacks.

  13. Government Refusing To Say Whether Phone Tracking Evidence Came From Mass Surveillance

    In criminal cases, defendants have a right to know what evidence the government plans to use against them and how the government gathered that evidence. This basic due process principle is essential: it allows defendants to test in court whether law enforcement officers obtained evidence in violation of the Fourth Amendment. But in a new legal brief, the government has refused to confirm or deny whether it relied on constitutionally questionable mass surveillance programs to gather evidence for a criminal prosecution.

  14. Watch live: “They’re watching us: So what?” featuring Greenwald, Schneier, Bamford, Dorfman

    From Pen America, cosponsored by the ACLU and the Fordham Law School Center on National Security, a talk on surveillance with James Bamford, Ariel Dorfman, Glenn Greenwald, and Bruce Schneier.

  15. The Biggest Little CIA Shop You’ve Never Heard Of

    The CIA’s main business is sending operatives abroad to recruit spies and, especially since 9/11, chasing down terrorists for its target-hungry drone pilots. But NR, as it’s known, is the agency’s stay-at-home division. It’s nothing like Homeland, however, with operatives running about with guns in the D.C. suburbs (though its 1960s-era predecessors once spied on antiwar and civil rights activists and recruited Cuban exiles to harass Fidel Castro). It also works with the FBI and NSA in bugging foreign diplomatic missions there.

  16. The Importance of Free Websites

    For me, this has been a perfect illustration of the positive aspects of the web. With the rampart commercialization of the Internet and issues such as advertisers tracking users surfing habits, the NSA’s gathering data on nearly everything that happens online and crackers trying to break into computers at every turn, it’s easy to come to the conclusion that the public network is nothing but a virtual space fraught with danger. But it’s also a place of great promise, as Charlie’s story so aptly demonstrates.

    Twenty years ago, my roommate and her family would not be able to follow the progress being made by Charlie nearly so closely. They would’ve had to rely on bits and pieces of often unreliable, certainly incomplete, information picked up by word of mouth through phone calls. They would not have felt as involved with the situation as they now do either, which is also important.

  17. Silent Mail, FreedomMail or Lavamail. Whatever it’s called, it will offer the same benefits

    Dark Mail alliance is the non-profit group formed by the leaders of Silent Circle and Lavabit.

    Silent Circle offers a suite of secure, communication services, while Lavabit is the secure email provider used by Edward Snowden, the ex-CIA contractor now living in Russia.

  18. GCHQ Monitors Hotel Reservations to Track Diplomats

    Britain’s GCHQ intelligence service monitors diplomats’ travels using a sophisticated automated system that tracks hotel bookings. Once a room has been identified, it opens the door to a variety of spying options.

  19. UK’s reputation is damaged by reaction to Edward Snowden, says UN official
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. As Electronic Frontier Foundation (EFF) Ramps Up Its Campaign Against Software Patent Trolls the Patent Microcosm Attacks the Messenger (EFF)

    In an effort to thwart Alice and the EFF (two birds, one stone) the patent microcosm goes behind the scenes and saturates the media with misleading articles, including attacks on the EFF itself



  2. In Sandoz v Amgen, the Federal Circuit is Again Found to Have Delivered Patent Injustice

    SCOTUS continues to disagree with CAFC on everything that it decides to reconsider, even the very latest decision (formally delivered earlier this month)



  3. The Supreme Court Can Reassert the Legitimacy of the Patent Trial and Appeal Board (PTAB) Later This Year or Next Year

    What lawyers-centric media characterises as a risk to PTAB may actually be an opportunity to silence critics of PTAB and help it carry on squashing bogus patents



  4. The US Patent Office (USPTO) Should Now be Headed by Drew Hirshfeld, a Patent Examiner Who Rose to the Top, Not a Lawyer Like Joseph Matal

    Donald Trump's Secretary of Commerce, Wilbur Ross, pushes to the top the patent microcosm rather than technical people who are equipped with the knowledge and experience to run the Office as well as Michelle Lee did



  5. After Latest Supreme Court Rulings on Patents, Including Impression v Lexmark, the Federal Circuit is Left Disgraced

    Hostility towards the patent microcosm's patent maximalism, as witnessed at the US Supreme Court (SCOTUS), culminated in another decision and will soon result in yet more decisions, as SCOTUS has since then picked more patent cases to look at



  6. IBM, Apple and Facebook Pursue Software Patents in India in Defiance of the Ban

    Multinationals from the United States, or digital colonisers with ambitions to spy on and control finance, continue to behave as though Indian law is not applicable to their operations in India and repeatedly attempt to patent software anyway



  7. Wouter Pors Under Fire for Lying or Manipulating in the Name of the Unitary Patent (UPC)

    The argument between Team UPC and other patent professionals (without a lot of eggs in the UPC basket) heats up as Wouter Pors resorts to desperate measures and Bristows belatedly admits constitutional problems in the UK



  8. Systemic Injustice at the International Labour Organisation (ILO) Causes Serious Harm to Complainants' Health, Including EPO Complainants

    The high human cost of ILO's failure to fulfill its stated mission while pretending that it has things under control (that is clearly no longer the case, especially as far as EPO cases go)



  9. Links 24/6/2017: GNOME Music Improves, FreeBSD 11.1 Beta 3

    Links for the day



  10. Microsoft and Bill Gates Become More Actively Involved in Their Biggest Patent Troll (and World's Biggest Troll), Intellectual Ventures

    The world's largest patent troll, which reportedly operates (litigates) through literally thousands of shells, has received yet more financial aid from Microsoft and Bill Gates



  11. The STRONGER Patents Act is One Among Several New Pushes for Patent Chaos in the United States

    US patent law is being 'massaged' again, with bills being pushed forth that propose a return to Armageddon, undoing much of the progress made possible by the Leahy-Smith America Invents Act (AIA)



  12. SUEPO and the EPO's Central Staff Committee Condemn Battistelli's Latest Attempt to Change the Rules in Defiance of Laws

    Staff representatives at the EPO voice opposition to so-called 'reforms' which are neither desirable nor legal



  13. The Tide Has Turned Against the Unified Patent Court (UPC) and It Finally Looks as 'Alive' as TPP

    The UPC is now stuck if not dead because officials are realising -- however belatedly -- that this entire charade was from start to finish just a coup d'état of the patent 'industry'



  14. Potential Targets of European Patent Office (EPO) Whistleblowing

    Priorities for whistleblowing at the European Patent Office (EPO), which operates secretly and occasionally illegally, too



  15. Links 23/6/2017: Wine 2.11 Released, HPC Domination by GNU/Linux

    Links for the day



  16. Primer to the Crisis and Scandals at the European Patent Office (EPO)

    An introduction to the chaotic state of what used to be the world's leading patent office and quickly became Europe's biggest embarrassment



  17. Workers of the European Patent Office (EPO) Are Going on Strike Again, Almost 90% Voted in Favour

    Thousands of brave EPO employees chose to cast a vote and make it known that they are in favour of another strike



  18. Benoît Battistelli Has Lost the Election at the EPO

    FFPE candidates (or moles from the yellow union) failed to enter the Central Staff Committee in spite of Battistelli's attempt to help them get in



  19. Emerging Threat to Patent Reforms at the USPTO

    Our plan of returning to coverage of US patent affairs in the wake of powerful lobbies that pursue patent maximalism



  20. You Know That the Unitary Patent (UPC) is in Huge Peril When Its Biggest Fans Admit It's Unlikely to Happen Even Next Year

    The tactics of Team UPC turn ugly as they personally target anyone who stands in their way, even a professor/judge who is courageous enough to state the obvious



  21. More Than Six Human Casualties Under Battistelli at the EPO, But the Human Toll Can Become a Lot Worse

    The bigger or much broader picture detailing the high cost of autocracy and mental torture at the EPO, where lives are ruined not only when these are ended and some key buildings pose severe threat to a lot of workers



  22. EPO's Elodie Bergot Calls Staff Suicide Just 'Passing Away', Pretends to Care

    How the EPO continues to mislead if not lie to staff, even when staff commits suicide -- a growing problem for Team Battistelli, whom some insiders hold accountable for these deaths



  23. The Administrative Tribunal of ILO Will Deliver EPO Judgments in Six Days

    Despite its old age (nearly a century), ILO's tradition when it comes to enforcing the law is anything but sterling, yet one can hope that it will stop its unproductive cat-and-mouse game with the EPO, where compliance is rare and actual judgments (not deferrals/referrals) are even rarer



  24. Links 21/6/2017: Red Hat's Numbers Are Up, New Debian Being Studied

    Links for the day



  25. Another Suicide Reported at the EPO While the Paid-for Media Focuses on 'European Inventor Award' Charade

    Puff pieces for Benoît Battistelli published aplenty while the European media refuses to deal with the reality -- not paid-for illusions -- at the European Patent Office



  26. Links 20/6/2017: Chuwi Lapbook, Linux 4.12 RC6, Mesa 17.1.3

    Links for the day



  27. At the European Inventor Award Ceremony Benoît Battistelli Lied to a Lot of Scientists and “Media Partners” About the UPC

    The Liar in Chief, Benoît Battistelli, still lives in a fantasy world or simply lies intentionally, which would be worse



  28. Contact Details for the EPO's Administrative Council Delegations

    List of Heads of Delegation and their E-mail addresses (used to be public information before Benoît Battistelli's oppressive regime or coup)



  29. Don't Forget to Vote for EPO Strike This Week (Thursday)

    A reminder that there's a vote on a strike at the European Patent Office later this week, giving an opportunity to rebut the "vocal minority" myth which Benoît Battistelli likes to spread



  30. European Patent Office (EPO) Whistleblowing Guidelines: Motivation and Impact of Leaks

    Advice on when to leak and what to leak for the desired effect, which is reformatory (though transparency and accountability)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts