• [^] # Re: Comment oser?

    Posté par . En réponse à la dépêche Open Bar Microsoft/Défense : des documents confirment les jeux de pouvoir et la décision politique. Évalué à -10.

    Personne dans la sécurité n'a jamais cru une seconde aux explications (fort peu techniques d'ailleurs) de Microsoft sur la raison d'être de cette clef (une clef de sauvegarde, en cas de compromission de la première, wtf ?!?).

    https://www.schneier.com/crypto-gram-9909.html

    I see two possibilities. One, that the backup key is just as Microsoft says, a backup key. It's called "NSAKEY" for some dumb reason, and that's that.

    Two, that it is actually an NSA key. If the NSA is going to use Microsoft products for classified traffic, they're going to install their own cryptography. They're not going to want to show it to anyone, not even Microsoft. They are going to want to sign their own modules. So the backup key could also be an NSA internal key, so that they could install strong cryptography on Microsoft products for their own internal use.

    But it's not an NSA key so they can secretly inflict weak cryptography on the unsuspecting masses. There are just too many smarter things they can do to the unsuspecting masses.

    Tu veux que je t'apprennes qui est Bruce Schneier aussi ?