Feeds

Germany warns: You just CAN'T TRUST some Windows 8 PCs

Microsoft: You can still buy an 'insecure' Win 8 machine sans TPM chip

Secure remote control for conventional and virtual desktops

Microsoft's new touchy Windows 8 operating system is so vulnerable to prying hackers that Germany's businesses and government should not use it, the country's authorities have warned in a series of leaked documents.

According to files published in German weekly Die Zeit, the Euro nation's officials fear Germans' data is not secure thanks to the OS's Trusted Computing technology – a set of specifications and protocols that relies on every computer having a unique cryptographic key built into the hardware that's used to dictate what software can be run.

Authorities at Germany's Federal Office for Information Security (BSI) later clarified that it was the Trusted Computing specs in Windows 8 in conjunction with the Trusted Platform Module (TPM) chip embedded in the hardware that creates the alleged security issue. BSI released a statement that backtracked slightly, insisting that using Windows 8 in combination with a TPM may make a system safer, but noting that it is investigating "some critical aspects related to specific scenarios in which Windows 8 is operated in combination with a hardware that has a TPM 2.0".

Trusted Computing is a controversial bunch of specifications developed by a group of companies including AMD, Cisco, Fujitsu, Hewlett-Packard, IBM, Intel, Microsoft and Wave Systems Corp.

The tech is designed to stop the use of software and files which do not contain the correct digital rights permissions (thus protecting the property of vendors behind the protocols), including "unauthorised operating systems" (a specific function of the much-maligned Secure Boot). Microsoft argues that Secure Boot protects users from rootkits and other malware attacks. The set of permissions is automatically updated online, outside of the control of the user.

A machine that contains a Trusted Platform Module and runs software adhering to the Trusted Computing specifications is, arguably, under the control of the vendor – in this case Microsoft. It also identifies the machine to the vendor, meaning that users' identities can be linked to their machines as well as their online activities. As Redmond is a US firm, opponents to the protocols argue, users' data is theoretically accessible to US spooks in the National Security Agency via the Foreign Intelligence Surveillance Act, as Die Zeit points out.

A TPM 2.0 chip is being built into more and more computers running Windows 8.

The newspaper obtained an internal document from Germany's Ministry of Economic Affairs written at the beginning of 2012. It warned of "the loss of full sovereignty over information technology" and that "the security objectives of confidentiality' and integrity are no longer guaranteed".

It continued: "The use of 'Trusted Computing'... in this form ... is unacceptable for the federal administration and the operators of critical infrastructure."

Trusted Platform Module 2.0 is considerably more invasive than older versions. Once this is rolled out across all Windows-using PCS, the Germans fear, there will be "simply no way to tell what exactly Microsoft does to its system through remote updates".

"From the perspective of the BSI, the use of Windows 8 in combination with a TPM 2.0 is accompanied by a loss of control over the operating system and the hardware used. This results in new risks for the user, especially for the federal government and critical infrastructure."

The Register previously described Trusted Computing as the "widely derided idea of computing secured for, and against, its users".

The leaked documents advised that Windows 7 is still safe to use, at least until 2020. Windows 8, on the other hand, is so tied up with Trusted Computing protocols that it is already "unfit for use".

Microsoft denied there was any backdoor. In a lengthy statement, a spokeswoman insisted that users cannot expect "privacy without good security". Redmond argued that users could purchase machines whose manufacturers had disabled the TPMs. Presumably this will one day become a selling point, although Microsoft argues this will actually make the hardware less "secure".

She said:

TPM 2.0 is designed to be on by default with no user interaction required. Since most users accept defaults, requiring the user to enable the TPM will lead to IT users being less secure by default and increase the risk that their privacy will be violated. We believe that government policies promoting this result are ill-advised."

It is also important to note that any user concerns about TPM 2.0 are addressable. The first concern, generally expressed as “lack of user control,” is not correct as OEMs have the ability to turn off the TPM in x86 machines; thus, purchasers can purchase machines with TPMs disabled (of course, they will also be unable to utilize the security features enabled by the technology). The second concern, generally expressed as “lack of user control over choice of operating system,” is also incorrect. In fact, Windows has been designed so that users can clear/reset the TPM for ownership by another OS if they wish. Many TPM functions can also be used by multiple OSes (including Linux) concurrently.

Rumours about a backdoor in Windows are almost as old as Microsoft itself. In 2009, El Reg reported on the NSA's admission that it had worked with developers on Windows 7's operating system security, forcing Redmond to deny there was a backdoor left open to spooks. ®

Intelligent flash storage arrays

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.