Feeds

No backdoor for Vista - MS

'Nonsense', scoffs developer

3 Big data security analytics techniques

Microsoft developers have stepped forward to dismiss suggestions that the next versions of Windows might feature backdoor features to allow police access to encrypted files which might other be impossible to access.

A BBC report last month suggested the Home Office was in talks with Microsoft over ways to overcome any obstacles Windows Vista's wider use of encryption might pose to criminal investigations. Vista is due to feature hardware-based encryption, called BitLocker Drive Encryption, which acts as a repository to protect sensitive data in the event of a PC being either lost or stolen.

Speaking before a Commons home affairs select committee hearing, Professor Ross Anderson reportedly urged the government "to look at establishing 'back door' ways of getting around encryptions". Pro-active stuff but, as previously reported, a careful review of the rest of Anderson's comments reveal he has talking about the challenge posed to police forensic investigations by hard disk encryption. Not too much should be read into one particular phrase.

A Microsoft spokeswoman told The Register: "Windows Vista is engineered to be the most secure version of Windows yet. It is our goal to ensure enterprise users have full control over information on their PCs Microsoft has not and will not put 'backdoors' into Windows, its BitLocker feature, or any other Microsoft Products."

Just to make assurance twice sure, a Microsoft developer has waded into the debate. The idea that Microsoft is working with governments to create a back door into BitLocker-encrypted data would only happen "over my dead body", Niels Ferguson writes on the Microsoft System Integrity Team Blog titled Back-door nonsense.

"In the unlikely situation that we are forced to by {include a back door] law we'll either announce it publicly or withdraw the entire feature. Back doors are simply not acceptable. Besides, they wouldn't find anybody on this team willing to implement and test the back door," he added.

Microsoft is talking to various governments about Vista, but only in the context of becoming end users of the technology. It is also helping law enforcement organisations in preparing for the introduction of the technology. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.