Technology Industry
Industry: Email Alert RSS FeedMicrosoft Denies Spying Charges
Computergram International, Sept 7, 1999
Microsoft Corp has dismissed as "inaccurate and unfounded" rumors that it provided the US National Security Agency (NSA) with a back door key to the encryption framework in its Windows operating system. The key, which was discovered by the chief cryptographer of a Canadian software firm on Friday, would enable the agency to read private e-mails and documents within all post-1995 versions of the Windows OS.
Andrew Fernandes, chief scientist at the Cryptonym Corporation in Ontario said he found the key, which gives back door access to Windows 9X, Windows NT and Windows 2000, while investigating NT4 security breaches. The company published the security hole on its web site Friday.
Most RecentTechnology Articles
- The Google Manifesto: Dr. Open and Mr. Closed
- RIM Is Getting Too Successful for Its Customers' Good
- Tech Law: Google Loses in France, GPL Suits Target Many, IBM Sued, More
- Microsoft Moves Fast, Already Has Custom XML Patch for Word
- Microsoft Might Get Advantage or Pain from Order To Not Sell Word
- More »
While dissecting release 5.0 of the service pack for NT 4, Fernandes said he discovered symbolic information about an encryption key labeled "NSA key," which would enable the agency to read confidential communications in any version of the Windows OS after 1995. Fernandes said the findings prove what security specialists have long believed, namely that two types of Windows keys exist, one held by Microsoft and one by another, third party organization.
But Microsoft denied the claims. "This report is inaccurate and unfounded," said spokesperson Jim Cullinan. "The key in question is a Microsoft key. It is maintained and safeguarded by Microsoft, and we have not shared this key with the NSA or any other party."
Microsoft said the key is labeled "NSA key" because NSA is the technical review authority for US export controls, and the key ensures compliance with US export laws.
Cullinan added that the speculation was ironic since Microsoft has consistently opposed the various key escrow proposals suggested by the government "because we don't believe they are good for consumers, the industry or national security."
Microsoft provides encryption to Windows applications via the Microsoft CryptoAPI, which allows applications to take advantage of the security provided by cryptographic services from independent software vendors. Microsoft says it only possesses the key which certifies the encryption tool kits.
However, in a statement published on Cryptonym's web site, Fernandes said the NSA key would enable the agency to securely load CryptoAPI services on a user's machine without his or her authorization. "The result is that it is tremendously easier for the NSA to load authorization security services on all copies of Microsoft Windows," he said, "and once these security services are loaded, they can effectively compromise your entire operating system."
The publication of the security flaw on Friday fuelled a wave of speculation over the weekend. Despite Microsoft's denial's security experts said it would be easy for the firm to modify its software at the NSA's request without product managers finding out.
They were also keen to point out the NSA's history of rigging software in order to gain access to confidential data. According to an article in the UK's Observer newspaper, in the 1970's, the agency had de-encryption software inserted into systems sold to Swiss software manufacturer Crypto AG, to enable it to read coded diplomatic and military traffic from 130 countries. And in Lotus Corp's products imported to Sweden, the NSA's so-called "help information" trapdoor was found to have compromised confidential mail of Swedish MPs and tax office staff.
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Technology Articles
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Speed control of separately excited DC motor
- Effects of creative, educational drama activities on developing oral skills in primary school children
- Political stability and economic growth in Asia
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market




