Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: zeugma
>> Leverage Windows crypto api’s instead of OpenSSL/LibreSSL and run as Windows Service

> Is this a part of the extend/extinguish mindset so common at microsoft?

This could be interpreted a few ways, of which Embrace-Extend-Extinguish is one. But I think EEE is unlikely, because it wouldn't succeed, and MS is not stupid in that regard. OpenSSL is used practically everywhere else; the rest of the world isn't going to drop OpenSSL just because Microsoft starts supporting SSH with their own libraries.

Possibility two is that MS looked at the recent history of vulnerabilities in OpenSSL that caused considerable headaches around the internet, and decided they didn't want their enterprise customers to suffer from that same problem in Windows -- it would be a black eye to the new SSH support even though strictly speaking unrelated. Using their own crypto gives them control over how new vulns are handled.

Third (put on your tinfoil hat for this one), if MS has developed crypto in cooperation with the NSA or other agencies that gives them a backdoor, then they have to use that crypto in something like SSH support.

I'll let you decide what you find the most probable.

15 posted on 10/20/2015 9:17:38 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 14 | View Replies ]


To: dayglored

I figure the third scenerio is most likely, given how horrible microsoft has historically been with security in general and crypto specifically. Overall, I welcome microsoft entry into the 21st century. Perhaps they’ll catch up eventually.

I’m hoping we’ll finally be able to use scp and rsync on microsoft boxes. Rsync rocks.


17 posted on 10/20/2015 9:42:28 AM PDT by zeugma (Zaphod Beeblebrox for president! Or Cruz if Zaphod is unavailable.)
[ Post Reply | Private Reply | To 15 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson