I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.
I'm finding your line of argument across multiple comments increasingly disingenuous. You're hurting your argument far more than you're helping.
I ask this because I'm still rather unclear about the argument that the original article is trying to make. I'm even more confused about what conclusions slipstream would have us draw from his web-post. Some comments here say that it's not an exploit, that instead its a lesson about why you shouldn't, as a matter of policy, include backdoors. Others say that it is a backdoor/security hole, and are appropriately up in arms over it. The only thing I'm confessing is confusion.
I understand that you think I'm being disingenuous, and the nice thing is that we really don't need to continue this conversation. If it is as bad as some are suggesting, than wouldn't an exploit be out in the near future? I'd expect such an exploit, or even evidence of a backdoor, to make further news, and if I see it then I'll obviously have my answer.
I don't think they were trying to make any particular point rather than generate pageviews with a combination of "haha M$" and righteous anti-backdoor anger.
That said, I myself agree with other commenters that your stance "this isn't a backdoor because it requires physical access; if you've given up physical access you're already screwed" is beyond disingenuous. Disregarding a login screen bypass by the same logic would be rightly pilloried. Yes, physical security is the hardest to improve, but that's exactly the carrot Microsoft has used to try and convince the world Secure Boot isn't a pure anti-consumer move.
Ok, I'm open to the possibility that my views might be dated on this.
But, to be fair:
1) the 'physical access' rule was an absolute given in training that I've taken. (I'll let you draw your own conclusions since that the training was hosted by Microsoft). I guess I've had it drilled into my head for so long that I didn't even think the assertion would be controversial here.
2)Schneier commented on here (https://www.schneier.com/blog/archives/2009/10/evil_maid_att...) stating: "As soon as you give up physical control of your computer, all bets are off."
Granted, Schneier's comment was in 2009, and it's possible that expectations on security have changed since then, but
3) this stackexchange question (http://security.stackexchange.com/questions/19334/what-can-a...) is a bit more recent. Some quotes:
"Physical security is a critical (arguably the most critical) part of IT Security. At the end of the day, almost anything can be overridden with local access to the hardware."
"If a "hacker" with any real experience or skill has physical access to a PC, I would just throw away the hard drive and start fresh."
4) even some other comments in this thread (https://news.ycombinator.com/item?id=12264137) don't paint my notion as disingenuous as you might.
Again, I'm not a security expert, but do you think I could be forgiven for making such an assertion?
> Again, I'm not a security expert, but do you think I could be forgiven for making such an assertion?
Yeah, I forgive you.
Spaghetti to a wall as well.
You're not arguing coherently, effectively, logically, or using terms defined as they're commonly understood.