#CryptoAPI

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-25

@GossiTheDog Obviously this is nothing new, as #Microsoft's #CryptoAPI is so #backdoored that it's basically #Govware.

I'll be collecting apologies once the next #ToldYaSo hits.

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-24

@ann3nova sadly this is nothing new.

The entire #CryptoAPI of #Windows is #backdoored for decades and #CensorBoot merely exists to prevent #Linux adoption and #DualBoot from working!

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-24

@Xeniax OFC #CensorBoot never was about #Security and #Microsoft having #Govware - #Backdoors in their #CryptoAPI is nothing new.

If this doesn't disqualify Windows & Microsoft in general then those who made that decision should be fired.

The only secure #encryption is #FLOSS with #SelfCustody of all the keys…

#USpol #cyherfascism #CloudAct #GAFAMs

2025-12-22

Chúc mừng lần đầu tiên đạt doanh thu 40,99€ từ dự án API dữ liệu crypto của tôi - giá 85% rẻ hơn các đối thủ! Hy vọng truyền cảm hứng cho những người đam mê công nghệ và khởi nghiệp. #CryptoAPI #SideProject #Startup #DoanhThuTrongBán #CôngNghệFinTech

reddit.com/r/SideProject/comme

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-26
Kevin Karhan :verified:kkarhan@infosec.space
2025-07-15

@briankrebs That explains all the shite I've seen, incl. the #CryptoAPI #backdoor in #Windows itself...

github.com/kkarhan/windows-ca-

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-09

@iX_Magazin #Windows ist inhärent unfixbar unsicher...

Siehe #CryptoAPI - #Backdoor!

Kevin Karhan :verified:kkarhan@infosec.space
2025-07-01

@euroinfosec which doesn't matter when they literally #backdoor the #CryptoAPI and integrate #Govware like #Recall!

github.com/kkarhan/windows-ca-

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-17

@cR0w too many.

github.com/kkarhan/windows-ca-

So far testing by @ct_Magazin / @heiseonline (and myseof later on) revealed only few #Apps not vulnerable to this specifics #Govware:

Anything else that uses the CryptoAPI is, espechally *all #Chromium-Forks (aka. All Browsers except Firefox, Tor Browser, #dillo, #LynxBrowser…)

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-11
Kevin Karhan :verified:kkarhan@infosec.space
2025-05-29

@marjolica @utf_7 @dashjackson @froge @arstechnica It'll impact any application that uses #Windows' #CryptoAPI and doesn't come with it's own #Encryption Library and #CertificateManagment.

Needless to say all #Chromium variants and #IE / #Edge are vulnerable to this #Backdoor which exists since at least #WindowsXP to this day!

  • Thus consider said #OS inherently unsafe!
Kevin Karhan :verified:kkarhan@infosec.space
2025-05-22

@GossiTheDog @signalapp it merely prevents #Screenshots by claiming it's #DRM'd content.

The correct solution for #Signal would be to alert all their users and specifically block #Windows in general or at least #Windows11 simply because it is a #Govware and empirically cannot be made private or secure.

But that would require them to actually give a shit, which thed don't, cuz otherwise they would've stopped demanding #PII like a #PhoneNumber and moved out of juristiction of #CloudAct.

  • I mean, what's gonna prevent the #Trump-Regime from threatening @Mer__edith et. al. with lifetime in jail for not kicking the #ICC (or anyone else he and his fans dislike) from #Signal's infrastructure?

Since they are highly centralized.they certainly are capable to comply with "#Sanctions" (or whatever bs he'll claim!)...

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-20

@DeltaWye @kfh I'd say @torproject / #TorBrowser as it's #Firefox but without #tracking, #adware and #analytics!

But if you're using #Govware like #Windows, any #Browser that doesn't use the #backdoored #CryptoAPI (i.e. all #Chromium-Forks do use it!) is better...

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-15

@paco #Copilot & #Recall are the perfect #InfoStealer #malware combo!

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-03

@cryptrz add to that the fact that the #CryptoAPI is #backdoored and that said #backdoor can be triggered with a simple #HTTPS request in any #Browser [except #Firefox & #TorBrowser as they use #NSS instead!] (or #PowerShell's horrible wget implementation)...

And we have sufficient proof thaf #Windows is a #Govware that noone should use and that should be banned across the globe.

github.com/kkarhan/windows-ca-

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-18

@0x40k well, #Microsoft to this day has a #Backdoor in the #CryptoAPI that remains unfixed to this day...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-12

@roman78 @admin @olifantenbaer angesichts der Lücken in #CryptoAPI inklusive #Backdoors ist das digitales #FlexTape bei durchgerrostetem Rohr...

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-11

@gborn @MichaelD @Bundesligatrainer @Ihazchaos nein, eben nicht.

Dass #Windows10 [und besonders #Windows11] nicht #DSGVO- & #BDSG-konform sein können ist evidenzierte Tatsache und ich habe noch keine*n Anwält*in gesehen die etwas anderes behaupten und dafür im Zweifelsfalle auch die #Haftung übernehmen würden.

  • Wohingegen ich mir sicher bin dass @SUSE & @ubuntu mir im Zweifelsfalle sogar ne #Versicherung der #Compliance ab Werk anbieten würden, was #Microsoft aufgrund von #CloudAct inhärent nicht kann!

  • Außerdem verbietet sich das Procurement von Anbietern die in "illegaler Agententätigkeit" [u.a. #PRISM] involviert sind (!!!) schon aus oberflächlicher due diligence...

Von einfach ausnutzbaren #Govware - #Backdoors in der #CryptoAPI unter #Windows hab ich noch garnicht angefangen!

#EOD

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-01

@puppygirlhornypost2 @navi yeah, but that's a common problem based off #TechIlliteracy and lack of proper explaination!

Bonus points if #TPM bs prevents #DataRecovery.

  • My biggest problem with #FDE/ #FullDiskEncryption is that is mandates direct access to a system to authenticate, thus one needs to manually mount stuff on servers post-boot instead.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst