The Register® — Biting the hand that feeds IT

Feeds

Germany warns: You just CAN'T TRUST some Windows 8 PCs

Microsoft: You can still buy an 'insecure' Win 8 machine sans TPM chip

Supercharge your infrastructure

Microsoft's new touchy Windows 8 operating system is so vulnerable to prying hackers that Germany's businesses and government should not use it, the country's authorities have warned in a series of leaked documents.

According to files published in German weekly Die Zeit, the Euro nation's officials fear Germans' data is not secure thanks to the OS's Trusted Computing technology – a set of specifications and protocols that relies on every computer having a unique cryptographic key built into the hardware that's used to dictate what software can be run.

Authorities at Germany's Federal Office for Information Security (BSI) later clarified that it was the Trusted Computing specs in Windows 8 in conjunction with the Trusted Platform Module (TPM) chip embedded in the hardware that creates the alleged security issue. BSI released a statement that backtracked slightly, insisting that using Windows 8 in combination with a TPM may make a system safer, but noting that it is investigating "some critical aspects related to specific scenarios in which Windows 8 is operated in combination with a hardware that has a TPM 2.0".

Trusted Computing is a controversial bunch of specifications developed by a group of companies including AMD, Cisco, Fujitsu, Hewlett-Packard, IBM, Intel, Microsoft and Wave Systems Corp.

The tech is designed to stop the use of software and files which do not contain the correct digital rights permissions (thus protecting the property of vendors behind the protocols), including "unauthorised operating systems" (a specific function of the much-maligned Secure Boot). Microsoft argues that Secure Boot protects users from rootkits and other malware attacks. The set of permissions is automatically updated online, outside of the control of the user.

A machine that contains a Trusted Platform Module and runs software adhering to the Trusted Computing specifications is, arguably, under the control of the vendor – in this case Microsoft. It also identifies the machine to the vendor, meaning that users' identities can be linked to their machines as well as their online activities. As Redmond is a US firm, opponents to the protocols argue, users' data is theoretically accessible to US spooks in the National Security Agency via the Foreign Intelligence Surveillance Act, as Die Zeit points out.

A TPM 2.0 chip is being built into more and more computers running Windows 8.

The newspaper obtained an internal document from Germany's Ministry of Economic Affairs written at the beginning of 2012. It warned of "the loss of full sovereignty over information technology" and that "the security objectives of confidentiality' and integrity are no longer guaranteed".

It continued: "The use of 'Trusted Computing'... in this form ... is unacceptable for the federal administration and the operators of critical infrastructure."

Trusted Platform Module 2.0 is considerably more invasive than older versions. Once this is rolled out across all Windows-using PCS, the Germans fear, there will be "simply no way to tell what exactly Microsoft does to its system through remote updates".

"From the perspective of the BSI, the use of Windows 8 in combination with a TPM 2.0 is accompanied by a loss of control over the operating system and the hardware used. This results in new risks for the user, especially for the federal government and critical infrastructure."

The Register previously described Trusted Computing as the "widely derided idea of computing secured for, and against, its users".

The leaked documents advised that Windows 7 is still safe to use, at least until 2020. Windows 8, on the other hand, is so tied up with Trusted Computing protocols that it is already "unfit for use".

Microsoft denied there was any backdoor. In a lengthy statement, a spokeswoman insisted that users cannot expect "privacy without good security". Redmond argued that users could purchase machines whose manufacturers had disabled the TPMs. Presumably this will one day become a selling point, although Microsoft argues this will actually make the hardware less "secure".

She said:

TPM 2.0 is designed to be on by default with no user interaction required. Since most users accept defaults, requiring the user to enable the TPM will lead to IT users being less secure by default and increase the risk that their privacy will be violated. We believe that government policies promoting this result are ill-advised."

It is also important to note that any user concerns about TPM 2.0 are addressable. The first concern, generally expressed as “lack of user control,” is not correct as OEMs have the ability to turn off the TPM in x86 machines; thus, purchasers can purchase machines with TPMs disabled (of course, they will also be unable to utilize the security features enabled by the technology). The second concern, generally expressed as “lack of user control over choice of operating system,” is also incorrect. In fact, Windows has been designed so that users can clear/reset the TPM for ownership by another OS if they wish. Many TPM functions can also be used by multiple OSes (including Linux) concurrently.

Rumours about a backdoor in Windows are almost as old as Microsoft itself. In 2009, El Reg reported on the NSA's admission that it had worked with developers on Windows 7's operating system security, forcing Redmond to deny there was a backdoor left open to spooks. ®

5 ways to reduce advertising network latency

Whitepapers

5 ways to reduce advertising network latency
Implementing the tactics laid out in this whitepaper can help reduce your overall advertising network latency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Email delivery: 4 steps to get more email to the inbox
This whitepaper lists some steps and information that will give you the best opportunity to achieve an amazing sender reputation.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
5 ways to prepare your advertising infrastructure for disaster
Being prepared allows your brand to greatly improve your advertising infrastructure performance and reliability that, in the end, will boost confidence in your brand.

More from The Register

next story
Chaos Computer Club: iPhone 5S finger-sniffer COMPROMISED
Anyone can touch your phone and make it give up its all
NSA in new SHOCK 'can see public data' SCANDAL!
What you say on Twitter doesn't stay on Twitter
Hundreds of hackers sought for new £500m UK cyber-bomber strike force
Britain must rm -rf its enemies or be rm -rf'ed, declares defence secretary
UK's Get Safe Online? 'No one cares' - run the blockbuster ads instead
Something like Jack Bauer's 24 ... whatever it'll take to teach kids how to bat away hackers
Would you hire a hacker to run your security? 'Yes' say Brit IT bosses
We don't have enough securo bods in the industry either, reckon gloomy BOFHs
London schoolboy cuffed for BIGGEST DDOS ATTACK IN HISTORY
Bet his parents wish he'd been playing computer games
RSA: That NSA crypto-algorithm we put in our products? Stop using that
Encryption key tool was dodgy in 2007, and still dodgy now
The NSA's hiring - and they want a CIVIL LIBERTIES officer
In other news, the Spanish Inquisition want an equal opprtunities officer
'Occupy' affiliate claims Intel bakes SECRET 3G radio into vPro CPUs
Tinfoil hat brigade say every PC is on mobile networks, even when powered down
prev story