Categories: SecurityWorkspace

Microsoft Seeks Calm On German Security Panic Over Windows 8

Claims that there is a backdoor in Windows 8 giving access to all versions of the operating system to US intelligence have been gently rebuffed by Microsoft.

A reporter in Zeit had suggested the backdoor stemmed from the Trusted Platform Module, or TPM chip, which seeks to improve security by powering the Secure Boot process that checks for and ignores malicious low-level code when a machine starts up. It does this through cryptographic keys that ensure code cannot be tampered with on loading and that the code is legitimate.

Backdoor - Shutterstock - © kentohNo Windows 8 backdoor?

The Zeit writer had suggested the TPM could give the manufacturer of a device control over it.

He said that in light of the leaks from Edward Snowden, it would not be a surprise if TPM 2.0, the version used by Windows 8, was actually a backdoor the National Security Agency (NSA) could easily exploit. As the chips powering TPM are manufactured in China, the Chinese could easily access Windows 8 machines too, the report alleged.

The reporter attained documents from the German government that led him to reach his supposition. But the German government has not said there is a backdoor in the OS.

The Office for Information Security (BSI)  later clarified the government’s position, and did say the use of TPM 2.0 and Windows 8 (TPM is used in other non-Windows machines, including Chromebooks, making the claims even more questionable) meant the user had to deal with “a loss of control over the operating system and the hardware used”.  This could lead to greater risk for the federal government and critical infrastructure, it said.

But the body said it had not warned the general public nor government bodies against using Windows 8.

It said “the newly established mechanisms can also be used for sabotage by third parties”, but appeared only to be talking generally about vulnerability exploitation. There was no suggestion of a purposeful backdoor, as Zeit had hypothesised, even if the BIS does have problems with TPM.

Microsoft has responded to the kerfuffle first by denying it has ever provided such access to users’ data and by talking up the security benefits of TPM 2.0. It suggested government departments would be wise to use the security protections it provides by default. But for those governments who want to gain back control of their machines, they can go with OEMs who make Windows PCs without TPM.

“Since most users accept defaults, requiring the user to enable the TPM will lead to IT users being less secure by default and increase the risk that their privacy will be violated. We believe that government policies promoting this result are ill-advised,” a spokesperson said.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

WhatsApp Appeal Against EU Fine Backed By Court Advisor

Notable development for Meta, after appeal against 2021 WhatsApp privacy fine is backed by advisor…

7 hours ago

Intel Board Shakeup As Three Members Confirm Retirement

First sign of shakeup under new CEO Lip-Bu Tan? Three Intel board members confirm they…

8 hours ago

Trump’s SEC Pick Pledges ‘Coherent’ Crypto Rules

Trump's nominee for SEC Chairman, Paul Atkins, has pledged a “rational, coherent, and principled approach”…

8 hours ago

Former Intel CEO Pat Gelsinger Joins Venture Capital Firm

After being 'retired' by Intel's board of directors, ex-CEO Pat Gelsinger has joined a VC…

13 hours ago

Trump Says China Tariffs May Be Cut To Seal TikTok Deal

President touts easing Chinese tariffs to facilitate TikTok sale, and also implements 25 percent tariff…

15 hours ago

Newspaper Lawsuit Against OpenAI Can Proceed Says Judge

Copyright lawsuit against OpenAI and Microsoft from The New York Times and other newspapers can…

16 hours ago