HFU HF Underground

General Category => Huh? => Topic started by: ChrisSmolinski on August 10, 2016, 1747 UTC

Title: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: ChrisSmolinski on August 10, 2016, 1747 UTC
Microsoft leaked the golden keys that unlock Windows-powered tablets, phones and other devices sealed by Secure Boot – and is now scrambling to undo the blunder.

These skeleton keys can be used to install non-Redmond operating systems on locked-down computers. In other words, on devices that do not allow you to disable Secure Boot even if you have administrator rights – such as ARM-based Windows RT tablets – it is now possible to sidestep this block and run, say, GNU/Linux or Android.

What's more, it is believed it will be impossible for Microsoft to fully revoke the leaked keys.

And perhaps most importantly: it is a reminder that demands by politicians and crimefighters for special keys, which can be used by investigators to unlock devices in criminal cases, will inevitably jeopardize the security of everyone.

Microsoft's misstep was uncovered by two researchers, MY123 and Slipstream, who documented their findings here in a demoscene-themed writeup published on Tuesday. Slip believes Microsoft will find it impossible to undo its leak.

Full article: http://www.theregister.co.uk/2016/08/10/microsoft_secure_boot_ms16_100/ (http://www.theregister.co.uk/2016/08/10/microsoft_secure_boot_ms16_100/)
Title: Re: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: Pigmeat on August 10, 2016, 2201 UTC
When will people learn sealed clay tablets and coded cuneiform are the only secure form of communications?
Title: Re: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: ChrisSmolinski on August 10, 2016, 2226 UTC
When will people learn sealed clay tablets and coded cuneiform are the only secure form of communications?

Didn't Al get the original patent on the One Time Tablet back in Babylon?
Title: Re: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: Pigmeat on August 10, 2016, 2346 UTC
Try Ur. He's been at this forever.
Title: Re: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: Skipmuck on August 11, 2016, 0000 UTC
Hmmm....
Title: Re: Bungling Microsoft singlehandedly proves that golden backdoor keys are terrible
Post by: Pigmeat on August 11, 2016, 0259 UTC
Real delta blues. Tigris and Euphrates.