EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

11.04.14

Cryptome Reveals How Microsoft Gives the FBI and the NSA Back Doors to Crack Encryption

Posted in Microsoft, Security at 3:06 pm by Dr. Roy Schestowitz

Cryptome

Summary: Cryptome has an article, comprised/composed of hard evidence, revealing ways in which Microsoft enables aggressive spies to break encryption

The FBI does not even pretend not to be pursuing back doors; quite the contrary! It demands them and now insists on legislation that would make them mandatory. The same goes for the NSA, Microsoft’s very special partner. Anyone who still thinks that back doors in encryption are within the realm of “conspiracy theory” must not have paid attention. We wrote about such issues more than half a decade ago. At this stage, judging by thousands of articles on the topic, these factual observations are very commonplace in the press, even in the corporate media.

“Anyone who still thinks that back doors in encryption are within the realm of “conspiracy theory” must not have paid attention.”“Microsoft backdoor bitlocker key escrow for the FBI & NSA,” writes to us David Sugar ‏from GNU Telephony. “From the OS that loves to spy on you,” he added.

Some months ago we showed that a former Microsoft engineer working on Windows BitLocker confirmed that the US government asks Microsoft for back doors and now we have more details on how this is done, courtesy of cryptology enthusiasts in Cryptome:

Microsoft OneDrive in NSA PRISM

A sends:

1) Bitlocker keys are uploaded to OneDrive by ‘device encryption’.

“Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected.

If the device is not domain-joined a Microsoft Account that has been granted administrative privileges on the device is required. When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to online Microsoft account and TPM protector is created.”

http://technet.microsoft.com/en-us/library/dn306081.aspx

2) Device encryption is supported by Bitlocker for all SKUs that support connected standby. This would include Windows phones.

“BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices.”

http://technet.microsoft.com/en-us/library/dn306081.aspx#BKM…

3) The tech media and feature articles recognise this.

“… because the recovery key is automatically stored in SkyDrive for you.”

http://www.zdnet.com/surface-bitlocker-and-the-future-of-encryption-7000024613/

4) Here’s how to recover your key from Sky/OneDrive.

“Your Microsoft account online. This option is only available on non-domain-joined PCs. To get your recovery key, go to …onedrive.com…”

http://windows.microsoft.com/en-us/windows-8/bitlocker-recovery-keys-faq

5) SkyDrive (now named OneDrive) is onboarded to PRISM. (pg 26/27)

http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPlaceToHide-

Documents-Uncompressed.pdf

When Microsoft speaks about security it usually means “national security”, i.e. the ability of the state to break security of software. It’s about interception, not security. When Microsoft speaks about ‘secure boot’ it speaks about an antifeature in UEFI that enables the state to remotely brick computers, too.

The sad thing is that amid many BSD milestones as of recently (FreeBSD, OpenBSD, PC-BSD and others) there are those who fall for the false promise of UEFI, which does more harm than good to security. OpenBSD, which takes security very seriously, has already blasted UEFI 'secure boot' and blasted those who support it (including Red Hat), whereas FreeBSD got bamboozled into UEFI 'secure boot' and with it, the FreeBSD-derived PC-BSD gets bamboozled too:

Marking the twenty-first birthday of FreeBSD was the release of FreeBSD 10.1-RC4 and separately was the FreeBSD-derived PC-BSD 10.1 RC2 release.

FreeBSD 10.1-RC4 is expected to be the final RC build of FreeBSD 10.1 and brought fixes for ATA CF ERASE breakage and a race fix that could cause an EPT misconfiguration VM-exit.

More details on FreeBSD 10.1-RC4 can be found via its Sunday release announcement. The official release of FreeBSD 10.1 is now hopefully a few days out with its many new features and changes.

This is not a good idea at all. PC-BSD needs to follow the example set by OpenBSD, not FreeBSD (with its codebase). It sure starts looking like not only Microsoft but Red Hat too is bending over to its lucrative clients and contracts with the Deep State. Based on established observations from one decade ago, including more recent developments that Red Hat refuses to comment on, it seems possible that back doors in encryption (by default) is the de facto standard among large corporations. When they speak about “security” there must be fine prints and they’re omitted from the advertising. At risk of breaking the silence about systemd (because we don’t want to inflame ‘civil wars’), systemd replaces/obviates so much highly mature software that it certainly increases the likelihood of bug doors being introduced in RHEL/Red Hat (systemd‘s patron) and by extension/inheritance many other distributions of GNU/Linux.

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Rumour: EPO in Berlin the Next Casualty of Battistelli's 'Reform' (Organisational Suicide Plan)

    Months after we learned that a former staff representative in Berlin had been dismissed we come across an anonymous claim that Berlin's 'branch' of the EPO will be folded onto Munich's



  2. Caricature: the Maas App

    The failure of Maas to even bother with regulation of Battistelli (among others) earns him this cartoon



  3. Links 5/12/2016: Linux 4.9 RC 8, DeepMind as FOSS

    Links for the day



  4. Leaked: Battistelli Acknowledges Bunk 'Justice' in About 100 Cases at the Internal Appeals Committee of the EPO

    A look at Battistelli's response to the latest from the International Labour Organisation (ILO), exceptionally delivering two decisions at the very end of last month



  5. The UPC Scam Part V: Unitary Patent Regime a Fantasy of Patent Trolls

    "Good for trolls" is a good way to sum up the Unitary Patent, which would give litigators plenty of business (defendants and plaintiffs, plus commissions on high claims of damages) if it ever became a reality



  6. EPO at a Tipping Point: Battistelli Quarrelling With French Politicians, Administrative Council Urged to Act, Staff Unrest Peaking

    The latest messages about Battistelli's regime at the EPO, which faces growing opposition from more directions than ever before



  7. Quality of Patents at the EPO Dependent on the Appeal Boards When Battistelli Assesses Performance Using the Wrong 'Production' Yardstick

    A look at some recent articles regarding patent quality in the US and in Europe, in particular because of growing trouble at today's EPO, which marginalises the appeal boards



  8. Microsoft's Push for Software Patents Another Reminder That There is No 'New' Microsoft

    Microsoft's continued fascination with and participation in the effort to undermine Alice so as to make software patents, which the company uses to blackmail GNU/Linux vendors, widely acceptable and applicable again



  9. Links 5/12/2016: SparkyLinux 4.5 Released, Kondik Exits Cyanogen (Destroyed After Microsoft Deal)

    Links for the day



  10. Software Patents Continue Their Invalidation Process, But Patent Law Firms Try to Deny This in Order to Attract Misinformed (or Poorly-Informed) Clients

    A roundup of news about software patents and demonstration of the sheer bias in the media, which is mostly controlled or steered by the patent microcosm rather than actual inventors



  11. Patent Trolls of Microsoft and Ericsson Are Trying to Tax Everything, Especially Linux Devices

    An update on Intellectual Ventures and Unwired Planet, whose operations pose a growing problem for Free software and Linux-based products (e.g. Android)



  12. Asia's Patent Litigation Chaos Getting Worse, Reaching Countries in the West, and Sites Like IAM Actively Promote This

    The race to the bottom (of patent quality) in China, the growth of patent trolls in the region, and the ruinous litigation strategy which now spills over even to the US -- through the Eastern District of Texas -- and may inevitably come to Europe (especially if the UPC ever becomes a reality)



  13. More French Politicians Are Complaining That Benoît Battistelli is a Disgrace to France and Urge for Action

    The backlash against Battistelli spills well outside the EPO and is now apparent even at the French National Assembly



  14. Links 3/12/2016: Mageia 5.1 Released, Mozilla Revenue at $421.3M

    Links for the day



  15. Canadian Intellectual Property Office (CIPO) Sees Decline in Patent Applications and It May Actually be a Good Thing

    Challenging the false belief that the more patents society has the better off it will be, citing examples and news from north America



  16. Blockchain Domain Infested With Software Patents, MasterCard Among the Culprits

    Worrying signs that an area of Free/Open Source software innovation is getting impacted by the plague of software patents



  17. Dutch Media Covers Latest EPO Scandals, German Media Totally Absent (a Media Blackout of Convenience)

    Our observations regarding the apparent media disinterest in EPO scandals, especially at the very core of the EPO (principal host country)



  18. Relocating the Boards of Appeal to Haar is a Poisonous Priority at Battistelli's EPO

    Revisiting Battistelli's effort to chop off the appeal boards that are necessary for ensuring patent quality at the EPO



  19. Links 2/12/2016: Mint Betas, Chrome 55, KDevelop 5.0.3, PHP 7.1.0

    Links for the day



  20. The Rule of Law and Justice Don't Exist Inside the EPO, Confirms the International Labour Organisation (ILO)

    Further analysis of the latest rulings from the ILO -- decisions that were long expected



  21. A Day in the Life of... Battistelli's Banana Republic

    This is part 5 of a fictional diary from the EPO



  22. Links 1/12/2016: Devuan Beta, R3 Liberates Code

    Links for the day



  23. Two ILO Decisions on EPO Cases Are Released, at Least One Judgment is Considered Good for Staff

    Years later (as justice is too slow, partly because of the EPO, being the principal culprit that clogs up the ILO's tribunal system) there is a couple of new judgments about EPO abuses against staff



  24. Dutch and French Politicians Complain About the European Patent Office, British Media Coverage Regular Now

    Pressure from the political systems, the scientific community and from the media is growing, as it becomes abundantly apparent that the EPO cannot go on like this



  25. Links 30/11/2016: Git 2.11, GOG Surprise Tomorrow

    Links for the day



  26. The UPC Scam Part IV: Bumps Along the Road for UPC, With or Without the UK and Brexit

    A sobering reality check regarding the UPC, no matter what Lucy Neville-Rolfe says under pressure from Battistelli and some selfish law firms that are based in London



  27. The UPC Scam Part III: The “Patent Mafia”

    Bigwigs like Lucy Neville-Rolfe and Benoît Battistelli, together with Team UPC and its tiny minority interests (self enrichment), are conspiring to hijack the laws of Europe, doing so across many national borders with unique and locally-steered patent policy in one fell swoop



  28. The UPC Scam Part II: The Patent Echo Chamber at Work, Prematurely Congratulating Itself in Its 'News' Sites





  29. The UPC Scam Part I: EPO-Bribed Media Outlets Lie to Brits (and to Europeans) About the UPC

    An introductory article in a multi-part series about UPC at times of Brexit and Lucy Neville-Rolfe's bizarre sellout to Battistelli



  30. European Public Service Union Asks EPO Administrative Council “to Re-establish the Rule of Law at the European Patent Office”

    The chinchillas of the Administrative Council are assertively asked to tackle the abusive management of the EPO, which gets condemned not only by CERN but also EPSU, which is working with the Dutch government to end lawlessness at the EPO


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts