Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Microsoft China Encryption Operating Systems Privacy Security Windows

Microsoft Announces 'Windows 10 China Government Edition', Lets Country Use Its Own Encryption (windows.com) 108

At an event in China on Tuesday, Microsoft announced yet another new version of Windows 10. Called Windows 10 China Government Edition, the new edition is meant to be used by the Chinese government and state-owned enterprises, ending a standoff over the operating system by meeting the government's requests for increased security and data control. In a blog post, Windows chief Terry Myerson writes: The Windows 10 China Government Edition is based on Windows 10 Enterprise Edition, which already includes many of the security, identity, deployment, and manageability features governments and enterprises need. The China Government Edition will use these manageability features to remove features that are not needed by Chinese government employees like OneDrive, to manage all telemetry and updates, and to enable the government to use its own encryption algorithms within its computer systems.
This discussion has been archived. No new comments can be posted.

Microsoft Announces 'Windows 10 China Government Edition', Lets Country Use Its Own Encryption

Comments Filter:
  • by Anonymous Coward

    Doing business with totalitarian governments is all good as long as the money keeps pouring in.

    • by Anonymous Coward

      Doing business with totalitarian governments is all good as long as the money keeps pouring in.

      TFS says China, not the US.

      • Totalitarianism (Score:5, Insightful)

        by XXongo ( 3986865 ) on Tuesday May 23, 2017 @11:14AM (#54469955) Homepage

        I have to remind you that "totalitarianism" is not a synonym for "a government I don't like", nor even "a government that does despicable things."

        It is "a system of government that is centralized and dictatorial and requires complete subservience to the state."

        The US does not (yet) assert total control over its citizens, although some political factions might like to go in that direction.

        • by Anonymous Coward

          You need to step out of the basement, that is exactly how the US operates in several key areas: border intersections, airports, etc. You just don't want to acknowledge that fact.

          • I am allowed to mock and ridicule the leader of my country in the US, it's practicaly my civic duty to do so. I don't know of any totalitarian governments that allow that sort of freedom.

            Do not mistake a few totalitarian like facets to be the same as being in a totalitarian state.

          • Border intersection? Wtf. Did you mean border crossing?
        • Re:Totalitarianism (Score:4, Interesting)

          by nomadic ( 141991 ) <`nomadicworld' `at' `gmail.com'> on Tuesday May 23, 2017 @12:05PM (#54470315) Homepage

          Interestingly, China used to be a totalitarian state but I think they've moved over into the authoritarian state category.

          • Governments evolve this way because at the end of the day it's not cost-effective for one group to control every aspect of everyone's life. e.g. if they're projecting their authority to control what you have for breakfast every day then that's a lot of paperwork for something which gains them very little power, in fact it drains the ruling party's resources.

            • by nomadic ( 141991 )

              Also it's hard to maintain totalitarian rule when you have a growing, politically significant middle class.

    • Re:Business as usual (Score:5, Interesting)

      by jellomizer ( 103300 ) on Tuesday May 23, 2017 @10:35AM (#54469689)

      But who is the totalitarian government? China or the United States?
      Being that the world is recovering for a wide spread ransom ware attack caused from an long time "unpatched flaw" used by the United States National Security Agency. It would make sense for a government such as China to try to protect its data with its own "security measures".

      I am not being naive in not bringing up that China will probably have an encryption algorithm with a back door so the government can weed out subversives. However chances our our counties being the United States, United Kingdom, Canada, Germany, France... Are not agencies of good and riotous, but have a complex set of national needs to protect order.

      While I am sure profit was Microsoft big factor, however there is also a general global self interests to make sure the world stays up to date in software. Being that Windows is so dominate world wide not caving in for this case, would mean China would use outdated hacked versions of Windows, with their spying happening anyways. At least with Microsoft having some control, the fact that the Chinese Windows 10 has Government Encryption will let subversives to know what not to use.

      • Encryption is not tied to any one country. If they switch from AES (which has no backdoors) to ANYTHING ELSE then it is by definition less secure. There is no security benefit from using their own encryption. Even a conspiracy theorist would admit that the chances of AES being broken by even the NSA is close to 0.

        So this change by China is not about protecting itself from foreign governments but is completely about controlling information and allowing itself to spy on its citizens.

        • by ( 4475953 )

          If they switch from AES (which has no backdoors) to ANYTHING ELSE then it is by definition less secure. There is no security benefit from using their own encryption.

          This is the most preposterous and uninformed bullshit about cryptography I've heard for a long time. AES had fairly low security margins even at the time it was introduced, and it is easy to come up with a slower, but ostensibly more secure Feistel cipher provided you have some expertise in cryptography and cryptanalysis and are careful. AES has been developed as a replacement for 3DES, with speed and applications in finance and bank transactions in mind, not for high security demands. It makes a lot of se

        • Re:Business as usual (Score:4, Informative)

          by cryptizard ( 2629853 ) on Tuesday May 23, 2017 @01:05PM (#54470665)
          I agree that there is nothing wrong with AES, but there is also nothing wrong with wanting to use your own encryption if you are the Chinese government. They have their own extremely qualified cryptographers, we are not talking about some guy in his basement coming up with his own block cipher. If the situations were reversed and the Chinese government had invented and standardized AES, there is no way the US government would use it even if every academic in the world said it was secure.

          The Chinese block cipher is called SM4 [wikipedia.org] and its algorithm is publicly available. It is a pretty standard Feistel construction, if it is truly vulnerable then people will discover that and then everyone will know. That is how science works.
        • Re:Business as usual (Score:4, Informative)

          by TechyImmigrant ( 175943 ) on Tuesday May 23, 2017 @01:44PM (#54470901) Homepage Journal

          What makes you think this is about AES and what makes you think the algorithms that China wants to use are not superior to the NIST options?

          In the case of hashes, the Chinese options are simply better both in terms of resistance to known attacks and implementability and come courtesy of the professor who broke SHA-1, who is Chinese.

          NIST fucked up royally with SHA3, putting it up to a popularity vote. The Europeans turned up at the meeting in strength and voted for the home team. It had nothing to do with the algorithm. Hence the adoption of SHA3 in hardware is going nowhere. We wanted a new hash, not a license to waste gates and power.

          There was an interesting dynamic at ISO SC27 WG2 a couple of years ago, where the Chinese (literally, the proposals come from nation state delegates) hash proposal was presented, along with a proof of why all the SHA were fucked and why the new structure dealt with it. At the same meeting, the NSA were there presenting Simon and Speck block ciphers for adoption by ISO (which are superb ciphers from any way you look at it, far superior to AES or SMS4 in implementability and at least as secure in security). The crows were having none of it. All comments were of the form "You're the NSA and we don't trust you". Keep in mind the comments are coming from representatives of governments. not individuals. I am not a US citizen, but I was a US delegate.

          China has a legitimate reason to dislike some of the NIST crypto options and legitimate reasons to prefer their own.

          If this was open source people would be happy that you could use your own choice of crypto algorithms. Microsoft would be better off making the crypto plugable in windows for the rest of us, not just the Chinese government.
           

      • by XXongo ( 3986865 )

        But who is the totalitarian government? China or the United States?

        China.

        Being that the world is recovering for a wide spread ransom ware attack caused from an long time "unpatched flaw" used by the United States National Security Agency. It would make sense for a government such as China to try to protect its data with its own "security measures".

        That is indeed sensible, but it is unrelated to totalitarianism. The fact is that China is a totalitarian system.

      • It would make sense for a government such as China to try to protect its data with its own "security measures".

        China should make its own operating system to their own spec, and no one can buy it, and no one can pay their engineers who worked on it, and they can suck it.

        No one should be catering to their government's needs, it should be free to fall on its face.

      • But who is the totalitarian government? China or the United States?

        Compared to China's recent past, neither. I suspect it doesn't matter, though, as you're probably ignorant of most actual human rights issues in the world, and are narrowly focused on the excesses of the NSA, CIA, and FBI versus how much each government actually tries to control its citizens' public and private lives.

        Being that the world is recovering for a wide spread ransom ware attack caused from an long time "unpatched flaw" used by the United States National Security Agency. It would make sense for a government such as China to try to protect its data with its own "security measures".

        This is also ignorant. The security flaw would still be there, for someone else to discover, if the NSA had not discovered it. It would also still be there if they had not informed MS so that i

      • by DarkOx ( 621550 )

        But who is the totalitarian government? China or the United States?

        China obviously, to suggest otherwise makes we weep for our future. You apparently have no understanding of Totalitarian means or your blind rage at the abuses of our government has cause you to loose perspective entirely. Totalitarianism is more about breadth of government than structure or power. In theory you can have totalitarian republic, in practice I am sure eventually people would get tired of it and no matter how propagandized would start to vote for people seeking to relax the rules. When tota

    • by Hentes ( 2461350 )

      There is nothing "usual" in this. Windows telemetry is already the largest surveillance operation in the world, handing the keys over to the Chinese government will give them some very scary probing capabilities.

  • by Anonymous Coward on Tuesday May 23, 2017 @10:09AM (#54469511)

    Controlled updates, managing all telemetry, and rolling your own encryption? Where can I buy this magical product?!?

  • by Anonymous Coward on Tuesday May 23, 2017 @10:10AM (#54469523)

    "remove features that are not needed by Chinese government employees like OneDrive, to manage all telemetry and updates"

    Excellent! Where can I get a copy?

    • by Anonymous Coward

      Me too. This is exactly the Windows I've been wanting for years. Does MS even realize what a market there is for this in the US?

      • by Anonymous Coward on Tuesday May 23, 2017 @10:37AM (#54469707)

        Sure they do, but the market for your data is much better. Also, people bitch a lot but they keep buying Windows, so why would Microsoft care what their users think?

    • Want to buy party membership?

    • by AmiMoJo ( 196126 )

      There may be hope for the rest of the world. If Microsoft puts in the necessary work to remove all that stuff and keep the OS working, chances are there will be some way to enable the enhancements on other versions too.

  • "enable the government to use its own encryption algorithms"

    • by James McGuigan ( 852772 ) on Tuesday May 23, 2017 @10:37AM (#54469705) Homepage

      "enable the government to use its own encryption algorithms"

      This would either imply one of two things (or both):

      1. The Chinese Government wants to install encryption backdoors in its own systems, to prevent employees from keeping secrets from it.

      2. The Chinese Government is worried that the US government has installed encryption backdoors in the standard algorithms and wants to enable its employees to keep secrets from the US government

      • Could be both.

        Fear of US back doors, wants Chinese back doors.

        I suspect though that it will end up being less secure wither way. Less tested for attack however they implement it.

      • How long will it be before someone in the current US government asks for a "Freedom Edition" requiring NSA-provided encryption, I wonder?

        Maybe it would just mandate use of a particular elliptical curve algorithm...

  • It should be easier to determine what Chinese servers to block at the firewall than to play Microsoft's game of obfuscating where the telemetry data is being sent to.

  • Meanwhile (Score:5, Insightful)

    by kkoo ( 4352157 ) on Tuesday May 23, 2017 @10:35AM (#54469687)
    Everyone else continues to use Microsoft Windows 10 US Government Edition.
  • by evolutionary ( 933064 ) on Tuesday May 23, 2017 @11:31AM (#54470059)
    Okay, if the Chinese Government required a special version of this Windows to run in their country, then something stinks about it. Like the data collection and invasive controls that windows 10 possessed from the get go. Doctors, Lawyers, Accountants or virtually anyone handling confidential information need to be paying attention. The very use of Windows 10 in their work violates client/patient confidentiality. (as it sends file header + other potential information possibly not revealed yet) to MS and from their to the US Government. IIn the movie "Bridge of Spies" I remember Hank's line to the CIA agent "We are not having this conversation" concerning a spy he was representing.

    People may brush this off in the USA but countries in other countries potentially doing international business, scientific research, or many other things may not their information going to a foreign power. We weren't exactly thrilled when NASA emails wound up being copied to China with a simple DNS availability message boost (we have since corrected, THAT was scary). Windows 10 is and has always been a trojan in it's very conception and we all need to say "No". Windows 7 or Linux, possibly Apple (but I'm not sure I trust them with their iron grip policies particularly on their Iphones) are perfectly user friend/usable solutions.

    Those In the Medical profession, I know many hospitals/doctors are stuck with Windows-only drivers/software packages but the medical industry is going to have to make some serious choices: either publicly tell the world their information will go the US Government/Microsoft (for possibly sale) or the medical community will have to demand drivers//software versions that are Linux or Mac compatible. Some are staying on Widows 7 for this reason, but MS had is trying to pressure everyone to go to Windows 10 either by withholding critical updates (they did patch XP for the NSA contributed ransomware so clearly some mandates there) or possibly through other means. (remember, they did start by force feeding which got a public stick) There could even be legal implications for lawyers and medical professions that could be violated here. Hopefully we'll start getting the message soon. It's becoming a not so brave new world.
  • Microsoft Announces 'Windows 10 China Government Backdoor Edition'
  • by Anonymous Coward

    Does it still contain NSAKEY [wikipedia.org]?

  • by Anonymous Coward

    I wonder what happened to the EU version with that window thing that let you get another browser, or that other EU version without the media player (rofl).

  • Trump should remove there H1B's from china for this. This IS THE USA WE DO NOT BOW TO RED CHINA!!!

  • Assuming that it will have a specific version identifier, this could have the side-effect of clearly identifying Chinese government computers, marking them as prime targets for their foes, but conversely also eliminating the risk of friendly-fire.

  • Man, the chinese government just gets all the good things.... wait what?

  • M$ selling out to the PRC? How si this even news?
    M$ has done anything the CPC has asked of them.
    Yet, the CPC does nothing about software piracy so M$ continues to lose revenue.

    “Compromise is a stalling between two fools.” - Stephen Fry
  • The backdoors this software is going to have?

"If it ain't broke, don't fix it." - Bert Lantz

Working...