RINF.COM: THE BREAKING NEWS ALTERNATIVE

Thursday, July 3rd, 2008
RINF Forum
Breaking News | Forum | UK News | USA News | World News | Political News | Sci-Tech News | War & Terrorism News | Sports News | Multimedia | Set Homepage
BREAKING NEWS
NEW RINF FORUM!

NSA Had Access Built into Microsoft Windows

Friday, March 28th, 2008

Heiss - A CARELESS mistake by Microsoft programmers has revealed that special access codes prepared by the US National Security Agency have been secretly built into Windows. The NSA access system is built into every version of the Windows operating system now in use, except early releases of Windows 95 (and its predecessors). The discovery comes close on the heels of the revelations earlier this year that another US software giant, Lotus, had built an NSA “help information” trapdoor into its Notes system, and that security functions on other software systems had been deliberately crippled.

The first discovery of the new NSA access system was made two years ago by British researcher Dr Nicko van Someren. But it was only a few weeks ago when a second researcher rediscovered the access system. With it, he found the evidence linking it to NSA.

Computer security specialists have been aware for two years that unusual features are contained inside a standard Windows software “driver” used for security and encryption functions. The driver, called ADVAPI.DLL, enables and controls a range of security functions. If you use Windows, you will find it in the C:Windowssystem directory of your computer.

ADVAPI.DLL works closely with Microsoft Internet Explorer, but will only run cryptographic functions that the US governments allows Microsoft to export. That information is bad enough news, from a European point of view. Now, it turns out that ADVAPI will run special programmes inserted and controlled by NSA. As yet, no-one knows what these programmes are, or what they do.

Dr Nicko van Someren reported at last year’s Crypto 98 conference that he had disassembled the ADVADPI driver. He found it contained two different keys. One was used by Microsoft to control the cryptographic functions enabled in Windows, in compliance with US export regulations. But the reason for building in a second key, or who owned it, remained a mystery.

A second key

Two weeks ago, a US security company came up with conclusive evidence that the second key belongs to NSA. Like Dr van Someren, Andrew Fernandez, chief scientist with Cryptonym of Morrisville, North Carolina, had been probing the presence and significance of the two keys. Then he checked the latest Service Pack release for Windows NT4, Service Pack 5. He found that Microsoft’s developers had failed to remove or “strip” the debugging symbols used to test this software before they released it. Inside the code were the labels for the two keys. One was called “KEY”. The other was called “NSAKEY”.

Fernandes reported his re-discovery of the two CAPI keys, and their secret meaning, to “Advances in Cryptology, Crypto’99″ conference held in Santa Barbara. According to those present at the conference, Windows developers attending the conference did not deny that the “NSA” key was built into their software. But they refused to talk about what the key did, or why it had been put there without users’ knowledge.

A third key?!

But according to two witnesses attending the conference, even Microsoft’s top crypto programmers were astonished to learn that the version of ADVAPI.DLL shipping with Windows 2000 contains not two, but three keys. Brian LaMachia, head of CAPI development at Microsoft was “stunned” to learn of these discoveries, by outsiders. The latest discovery by Dr van Someren is based on advanced search methods which test and report on the “entropy” of programming code.

Within the Microsoft organisation, access to Windows source code is said to be highly compartmentalized, making it easy for modifications to be inserted without the knowledge of even the respective product managers.

Researchers are divided about whether the NSA key could be intended to let US government users of Windows run classified cryptosystems on their machines or whether it is intended to open up anyone’s and everyone’s Windows computer to intelligence gathering techniques deployed by NSA’s burgeoning corps of “information warriors”.

According to Fernandez of Cryptonym, the result of having the secret key inside your Windows operating system “is that it is tremendously easier for the NSA to load unauthorized security services on all copies of Microsoft Windows, and once these security services are loaded, they can effectively compromise your entire operating system”. The NSA key is contained inside all versions of Windows from Windows 95 OSR2 onwards.

“For non-American IT managers relying on Windows NT to operate highly secure data centres, this find is worrying”, he added. “The US government is currently making it as difficult as possible for “strong” crypto to be used outside of the US. That they have also installed a cryptographic back-door in the world’s most abundant operating system should send a strong message to foreign IT managers”.

“How is an IT manager to feel when they learn that in every copy of Windows sold, Microsoft has a ‘back door’ for NSA - making it orders of magnitude easier for the US government to access your computer?” he asked.

Can the loophole be turned round against the snoopers?

Dr van Someren feels that the primary purpose of the NSA key inside Windows may be for legitimate US government use. But he says that there cannot be a legitimate explanation for the third key in Windows 2000 CAPI. “It looks more fishy”, he said.

Fernandez believes that NSA’s built-in loophole can be turned round against the snoopers. The NSA key inside CAPI can be replaced by your own key, and used to sign cryptographic security modules from overseas or unauthorised third parties, unapproved by Microsoft or the NSA. This is exactly what the US government has been trying to prevent. A demonstration “how to do it” program that replaces the NSA key can be found on Cryptonym’s website.

According to one leading US cryptographer, the IT world should be thankful that the subversion of Windows by NSA has come to light before the arrival of CPUs that handles encrypted instruction sets. These would make the type of discoveries made this month impossible. “Had the next-generation CPU’s with encrypted instruction sets already been deployed, we would have never found out about NSAKEY.”

See More:  

Have Your Say: NSA Had Access Built into Microsoft Windows
Please note, only selected comments will be published.

Or discuss this report in our new forums

One Response to “NSA Had Access Built into Microsoft Windows”

  1. Jose Lanz
    Posted: Mar 29th, 2008 at 12:14 pm

    Not found the URL about Cryptonym website NSA key
    they work very fast and maybe there is an automatic bypass when the search is done by known search engines!!!!

    Reply | Quote selected text | Link to this

RSS TrackBack URL

This entry was posted on Friday, March 28th, 2008 at 9:32 am and is filed under Science & Technology News, Surveillance, Civil Liberties & Human Rights News . You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
Translations
Translate to EnglishÜbersetzen Sie zum Deutsch/GermanПереведите к русскому/RussianΜεταφράστε στα ελληνικά/GreekVertaal aan het Nederlands/Dutchترجمة الى العربية/Arabic中文翻译/Chinese Traditional中文翻译/Chinese Simplified한국어에게 번역하십시오/Korean日本語に翻訳しなさい /JapaneseTraduza ao Português/PortugueseTraduca ad Italiano/ItalianTraduisez au Français/FrenchTraduzca al Español/Spanish Free Newsletter

Related News

Network This Report

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • Technorati
  • Digg
  • StumbleUpon
  • Slashdot
  • Reddit
  • YahooMyWeb
  • Spurl
  • Fark
  • Netscape

Email This Page To A Friend
Latest Headlines

Archive
TOP NEWS DISCUSSIONS
LATEST NEWS DISCUSSIONS
LATEST FORUM TOPICS
Bill Clinton says Barack Obama must 'kiss my ass' for his support

RINF Launches Web Hosting Service

The 'W.' Stands for 'War Criminal'

U.S. escalating covert operations against Iran: report

Pretending That Bush is Not a Tyrant

UK government fined for violation of right to privacy

Ex-Agent Says CIA Ignored Iran Facts

Secret U.S. operation kills Iraqi, strains relations

MEP Tries to Certify Bloggers

Nine held in ID card demo

Iraq Criticizes Attacks by American Troops

ID scheme: the truths, half-truths and deceptions

Brussels To Sign Away Your Private Details To US

Is Britain moving to the right?

Jesus commented on:
Military Doctors Infect Gitmo Detainee With HIV
Are you crazy? “neo-con Jewish dual citizens… play for world domination&#...
Continue Reading & Reply

3 year old kid commented on:
New Police “Sneak and Peak” Technology Exclusive
Rochdale, what is Shithole!
Continue Reading & Reply

Alistair Dark commented on:
Cannabis lowers greenhouse emissions
Many suprising things about hemp here. I knew it was cheap and tough - but all the amino acids?...
Continue Reading & Reply

3 year old kid commented on:
Over 60% of People Do Not Trust the Government
To learn what is really going on and how we are being made into economic slaves -...
Continue Reading & Reply

RSS Forum Posts Temp Offline - See Latest Forum Posts
Activism & Protest News | Business News | Civil & Human Rights News | Environmental News | Media News | Globalisation News | Web Development News
ADVERTISEMENTS
SITE MAPS
Web Desing & Hosting UK , USA, Europe

WOWEB - Web Design

FAST GATEWAY - Web Hosting

INFOTX - Web Hosting Guides and Resources


ASHLEY GUEST HOUSE - Morecambe Guest House

Linux Web Hosting

Never Be Lied To Again!

Subliminal Secrets Exposed

Holographic Creation: Your Own Reality


Masonic Secrets Revealed


What You Aren't Supposed To Know
7/7 Afghanistan Alternative Energy Art BBC Big Brother Bilderberg Biometrics Bush CIA Climate Change Cover Up Cults Culture Database State David Hicks David Ray Griffin Democrats Demos Drugs Education EU False Flag FBI Fraud Free Speech Freemasons G8 Globalization Guantanamo Health News History ID Cards Internet Iran Iraq Israel Law Marches MI5 MI6 Microsoft Military MoD Money Music NASA Neocons NSA Oil Pakistan Podcast Police State Propaganda RFID RINF Rumsfeld Science Secrecy Security Slavery Space Sports Spying Stephen Lendman Technology Terrorism Tony Blair Torture TV UK News UN USA News Video Voting Warfare White House Wolfowitz World News Yahoo
2003 - 2005 Archives | 2005 - 2007 Archives | 2007 - 2008 Archives | Current Archives | Past Version
About | DVD Store | Opinion | Reviews | Special Guests | Webmasters
The views expressed in the RINF news wire and newsletter are the sole responsibility of the author (s) and do not necessarily reflect the views of the webmaster.
RINF.COM: Breaking News & Alternative Media is Copyleft - Copy & Distribute Freely. News Forum