Security loophole found in Windows operating system

November 12, 2007

A group of researchers headed by Dr. Benny Pinkas from the Department of Computer Science at the University of Haifa succeeded in finding a security vulnerability in Microsoft's "Windows 2000" operating system.

The significance of the loophole: emails, passwords, credit card numbers, if they were typed into the computer, and actually all correspondence that emanated from a computer using "Windows 2000" is susceptible to tracking.

"This is not a theoretical discovery. Anyone who exploits this security loophole can definitely access this information on other computers," remarked Dr. Pinkas.

Various security vulnerabilities in different computer operating systems have been discovered over the years. Previous security breaches have enabled hackers to follow correspondence from a computer from the time of the breach onwards. This newly discovered loophole, exposed by a team of researchers which included, along with Dr. Pinkas, Hebrew University graduate students Zvi Gutterman and Leo Dorrendorf, enables hackers to access information that was sent from the computer prior to the security breach and even information that is no longer stored on the computer.

The researchers found the security loophole in the random number generator of Windows. This is a program which is, among other things, a critical building block for file and email encryption, and for the SSL encryption protocol which is used by all Internet browsers. For example: in correspondence with a bank or any other website that requires typing in a password, or a credit card number, the random number generator creates a random encryption key, which is used to encrypt the communication so that only the relevant website can read the correspondence. The research team found a way to decipher how the random number generator works and thereby compute previous and future encryption keys used by the computer, and eavesdrop on private communication.

"There is no doubt that hacking into a computer using our method requires advanced planning. On the other hand, simpler security breaches also require planning, and I believe that there is room for concern at large companies, or for people who manage sensitive information using their computers, who should understand that the privacy of their data is at risk," explained Dr. Pinkas.

According to the researchers, who have already notified the Microsoft security response team about their discovery, although they only checked "Windows 2000" (which is currently the third most popular operating system in use) they assume that newer versions of "Windows", XP and Vista, use similar random number generators and may also be vulnerable.

Their conclusion is that Microsoft needs to improve the way it encodes information. They recommend that Microsoft publish the code of their random number generators as well as of other elements of the "Windows" security system to enable computer security experts outside Microsoft to evaluate their effectiveness.

Source: University of Haifa


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.2 /5 (38 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • Argiod - Nov 13, 2007
    • Rank: not rated yet
    "Security loophole found in Windows operating system..."

    So, I thought this was a forum for news. There's nothing new about Windows security loopholes. Anyone who uses Windows has to download security updates at least once a week. The simple cure is to switch to Ubuntu Linux. I have, and no longer have to worry about security problems. And my system runs about two to four times faster now.
  • superhuman - Mar 18, 2008
    • Rank: not rated yet
    This one is HUGE though, being able to predict random numbers and security keys is a dream come true for hackers. Seriously microshit needs to hire some professionals.

November 12, 2007 all stories

Comments: 2

4.2 /5 (38 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Trust Linux!
    created Nov 20, 2009 | popularity not rated yet | comments 0
  • Microsoft's monthly security fixes spare Windows 7
    created Nov 10, 2009 | popularity not rated yet | comments 0
  • Secure computers aren't so secure
    created Oct 30, 2009 | popularity not rated yet | comments 0
  • Be cautious upgrading to Windows 7
    created Oct 28, 2009 | popularity not rated yet | comments 0
  • How Microsoft plans to hook users on Windows 7
    created Oct 15, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Achromat lens - magnifying LCD
    created 12 hours ago
  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • More from Physics Forums - General Engineering

Other News

Sony optimistic on 3-D TVs, in-house display (AP)

Sony optimistic on 3-D TVs, in-house display

Technology / Hi Tech

created 32 minutes ago | popularity not rated yet | comments 0

(AP) -- A third to a half of the Sony Corp. TV sets sold annually will be packed with 3-D features by the year ending March 2013, a senior executive said Thursday.


Post Office card error leaves Italians in the red: report

Technology / Other

created 14 minutes ago | popularity not rated yet | comments 0

A computer glitch left Italian Post Office customers in the red by processing card transactions at 100 times their value, Italian press reported Thursday.


New guidelines for broadcasters on user-generated content

Technology / Other

created 56 minutes ago | popularity not rated yet | comments 0

For the first time guidelines are to be published on how broadcasters around the world can encourage audiences to produce better quality user-generated content and to improve media and information literacy.


Design chosen for British 1,000 mph car

Design chosen for British 1,000 mph car (w/ Video)

Technology / Engineering

created 23 hours ago | popularity 4 / 5 (8) | comments 5

(PhysOrg.com) -- A British team hoping to be the first to get a car to 1,000 mph (1,610 km/h) has made its final design selection. The six-tonne car, known as the Bloodhound, will be powered by a Eurofighter ...


Should I buy a PC or Mac?

Technology / Software

created 11 hours ago | popularity 4 / 5 (4) | comments 8

Q. Our 6-year-old PC computer is dying a slow death and we are considering moving to a new iMac but have a few concerns. First, of all, we have several Word documents on our disk drive now that we want to keep and add to ...