UK wants backdoor into Windows Vista

Open discussion about any topic, as long as you abide by the rules of course!
User avatar
Eraser
Posts: 19181
Joined: Fri Dec 01, 2000 8:00 am

UK wants backdoor into Windows Vista

Post by Eraser »

http://yro.slashdot.org/yro/06/02/15/131222.shtml
he BBC is reporting that the British Government is working with Microsoft in order to gain backdoor access to hard drives encrypted by the forthcoming Windows Vista file system. Professor Anderson, professor of security engineering at Cambridge University, urged the Government to contact Microsoft over fears that evidence could be lost by suspects claiming to have forgotten their encryption key.
Great. Now that hackers know this they won't sleep before they've located and abused it.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

I hope they do, so it isn't attempted again.

Encryption has benefits and drawbacks, and it's not possible to seperate them.

Give individuals data security and you lose the ability to snoop on them.

Give users anonymity and you lose the ability to track them.

Seems pretty straightforwards.
Grudge
Posts: 8587
Joined: Mon Jan 28, 2002 8:00 am

Post by Grudge »

lol, how stupid, it's never going to work
DiscoDave
Posts: 1645
Joined: Wed Feb 09, 2005 4:33 pm

Post by DiscoDave »

I know of many people who will get Vista as soon, and possibly for free (including myself) as its released, but this is kinda why I'm going to wait for it to mature a bit before screwing up my computer.
Grudge
Posts: 8587
Joined: Mon Jan 28, 2002 8:00 am

Post by Grudge »

why would you need to encrypt your HDD in the first place, and why would anyone want to hack you?

lol @ average joe worrying about being H4XX0r3d
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

Grudge wrote:
lol @ average joe worrying about being H4XX0r3d
exactly.
User avatar
MKJ
Posts: 32582
Joined: Fri Nov 24, 2000 8:00 am

Post by MKJ »

true grudge

so vista uses yet another file system?
[url=http://profile.mygamercard.net/Emka+Jee][img]http://card.mygamercard.net/sig/Emka+Jee.jpg[/img][/url]
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

That's what I'm wondering. WinFS has been delayed, so are they talking about it in the future tense, or are has MS included an updated encrypted file system in the current version of Vista?
Dave
Posts: 6986
Joined: Sat Jan 15, 2000 8:00 am

Post by Dave »

+JuggerNaut+ wrote:
Grudge wrote:
lol @ average joe worrying about being H4XX0r3d
exactly.
laff.. not the response I would have expected from a security guy unless you're being sarcastic
D'Artagnan
Posts: 468
Joined: Sun May 14, 2000 7:00 am

Post by D'Artagnan »

Does someone has a date on when this VISTA will come out, not beta...the full version of course...
[url=http://powerquebec.forumpro.fr/][color=red][b]Fast and furious_[/b][/color]That's what it's all about...[/url][img]http://pages.infinit.net/oldman/rank14.gif[/img]
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

Dave wrote:
+JuggerNaut+ wrote:
Grudge wrote:
lol @ average joe worrying about being H4XX0r3d
exactly.
laff.. not the response I would have expected from a security guy unless you're being sarcastic
:D

the avg joe is actually NOT worried enough considering the amount of open wifi networks in ANY given suburb or apt complexes.

it boils down to getting them educated. i've yet to run across a wifi router's setup wizard that says "hey, you might want to secure you're network. here are the different algorithms and what they do. we recommend you use one of them" or something along those lines. nope. hook it up, give it an SSID to broadcast to your neighbors and you're good to go.

of course that's one of a just few things your avg joe will need to learn along with not storing sensitive information on your pc, strong passwords, knowing which sites are secure, etc.
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

My biggest peeve is when users think that since they have a router, they don't need to use any firewall software. :smirk:

Granted, cable is worse than DSL, but you're always getting slammed with broadcasts, port scans and such. Even with no activity on my LAN, my internet connection on the router is almost constantly blinking.
dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

Well a good router should take care of all port trafficing for you, and most software firewalls are resource pigs on midrange systems. >:E
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

dzjepp wrote:Well a good router should take care of all port trafficing for you, and most software firewalls are resource pigs on midrange systems. >:E
for your average user, that's not good enough, sorry.
dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

Well I've noticed Sygate PFP is one of the rare firewall packages that runs pretty fast performance wise (and almost idles when minimized to the taskbar)
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

kerio PF was also very very well behaved. point is, a user SHOULD have both a router and a software firewall for the sheer fact that people LOVE to click. the software firewall is not so much for "hacking intrusions" but to keep an eye on spyware/malware and browser hijacking.
Grudge
Posts: 8587
Joined: Mon Jan 28, 2002 8:00 am

Post by Grudge »

Everyone with SP2 have one.
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

i've not checked recent updates, but sp2's firewall was only monitoring inbound connections, not outbound. correct me if i'm wrong, kthx.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

yup no egress packet filtering AFAIk
Grudge
Posts: 8587
Joined: Mon Jan 28, 2002 8:00 am

Post by Grudge »

well, that's dumb
dzjepp
Posts: 12839
Joined: Wed Mar 28, 2001 8:00 am

Post by dzjepp »

Yeah, and imagine all the average users that are actually using the built-in firewall (there are tons), getting a false-sense of security in that regard.
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

dzjepp wrote:Well a good router should take care of all port trafficing for you, and most software firewalls are resource pigs on midrange systems. >:E
I've got a pretty good Netgear router, and my Kerio PF is constantly blocking portscans, ping/dos attacks, etc.

Having just a router is not enough. Unless you have a top of the line industrial product, they can't detect all kinds of pc-directed attacks that you might get.
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

Really, only $650 to get a router for my home network?

Are you kidding man?
R00k
Posts: 15188
Joined: Mon Dec 18, 2000 8:00 am

Post by R00k »

riddla wrote:get a fortigate 50A bundle then piss on using a software firewall

regardless, if you have a good router/firewall with access lists and know how to configure it, software firewalls aren't all that necessary.
If you have a normal, decent home router (Netgear, Linksys, etc), and you are on a cable modem, you need a firewall.

I get dozens of hits a day from random addresses all over the internet, port scans, ping attacks, dos attempts, activity from people running trojans, everything.

If you don't think you need a firewall in that situation, you're in denial man.

And telling users/clients they don't need a firewall because they have a router is irresponsible.
Dave
Posts: 6986
Joined: Sat Jan 15, 2000 8:00 am

Post by Dave »

I don't use a software firewall... it's a waste of resources when I have a hardware box sitting out in front of everything.
Post Reply