German Government Warns Key Entities Not To Use Windows 8 – Links The NSA
investmentwatchblog.com
investmentwatchblog.com
And beyond the issue of baseless speculation as a replacement for journalism, it's a little hard to understand why NSA (or anyone else) controlling TPM is a special threat to users. Despite what the article claims, I don't think TPM is a "backdoor" and it certainly isn't a "surveillance chip". And the articles don't explain how control over TPM gives someone a special advantage over computers with TPM support, an explanation I'm not holding my breath for.
How would you define that when MS wants it could enter your computer and control it without you ever realizing.
Then if something is proven is that if Microsoft can, then NSA can too.
Why Microsoft controlling the crypto keys to your computers is a problem? Are you serious?
Why American companies controlling all the computers of the rest of the world is an issue?
Europe for one should not depend on American companies for basic use of their computers. This is obvious, if you are not American.
This should be obvious, regardless of nationality.
Is it even possible?
It could be implemented in such a way that removing it would cause problems but it shouldn't be too hard to work around it.
Worst case you would you would replace it with something that imitates its response when the UEFI searches for it.
Since a lot of motherboards have spaces for it but seem to function just fine without it leads me to believe it should work just by removing it.
it was just a story made up by a german site (zeit.de)
At the very least, I think this deserves more exploring. It's not the first time I saw the Germans weren't happy with Windows 8 and its "secure boot". This is from last November:
http://www.linuxbsdos.com/2012/11/21/german-govt-comes-out-a...
And it seems the source for that is your source. So are they contradicting themselves now?
http://www.bmi.bund.de/SharedDocs/Downloads/DE/Themen/OED_Ve...
However, this means no all clear in terms of Trusted Computing. While the publicly available TPM 2.0 specification includes no back-doors, any implementation might do so, either by malicious intent, due to implementation errors or government pressure. This risk can be met only if implementations are scrupulously tested and certified by independent bodies. This is not the case with the integrated TPM of current Windows 8 tablets, to name just one example.
It obviously gives the Govt time to protect themselves, but could also exploit it on other systems.
Were you aware of NSA surveilance before Snowden?
It all comes down to trust, and once there is no more trust (like in case of US gov) then the burden of proof they are not doing anything wrong is on them.
NSA has been already caught spying on everyone in the world. The method explained allows them more spying. Would you risk your country security, or your own business relying on a piece of technology that NSA or anyone else can use for spying on you? Given a choice between multiple platforms why would you choose one vulnerable to spying and inherently unsecure?
I don't see why not. The same logic is used by the governments' war on terror. "We're going to detain you and put you on a 'no fly' list until you prove you aren't a terrorist".
http://translate.google.co.uk/translate?sl=de&tl=en&js=n&pre...
http://www.zeit.de/digital/datenschutz/2013-08/trusted-compu...
Die Zeit is probably the most highly regarded weekly in Germany, see http://en.wikipedia.org/wiki/Die_Zeit
This is exactly what the NSA is implying when they say they want to be the "anti-virus of the Internet". TPM will allow Microsoft and/or NSA to remotely disable viruses from every computer - and course anything else they want - anywhere in the world, and that's how they will promote it to normal people: "It will make you safe".
I don't know whether Windows 8 is like that, but anyway you can opt out of it by using an OS that doesn't support any remote control. In many BIOS's you can turn TC support off.
Here is the formerly canonical, maybe dated now, overview of TC http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
It's built in on some laptops and desktops (usually pre-built ones). Others it's a plugin module that can be inserted into a header on the board.
There are a handful of companies to avoid that work with the NSA.
If you have missed the list, check out the slides: http://www.theguardian.com/world/2013/jun/08/nsa-prism-serve...
Every system has a set of exploitable vulnerabilities. Each of those vulnerabilities is known by a set of parties other than you. With Windows you can be sure those sets have at least one element each.