Quicken's secret backdoor?

Here's one thing I bet the millions of Quicken users probably don't know: Intuit has a secret back door that allows it to access your password-protected financial files -- or so says Elcomsoft, a security software vendor based in Moscow. Elcomsoft claims it has discovered the heretofore undisclosed back door to Quicken files, which would allow Intuit to open the files without a customer's password. Elcomsoft also claims to have cracked the RSA encryption that protects the files. (Elcomsoft did not disclose how many millions of monkeys working on millions of computers it took to factorize the 512-bit key.)

Among other things, Elcomsoft sells password recovery software, so naturally it's hawking a product that can allegedly strip the encryption from Quicken and allow users to access files after their password has disappeared down the memory hole.

According to Elcomsoft:

This backdoor allows Intuit to offer their own affordable service whereby Intuit will unlock a customer's file. To deliver this service, Intuit uses a 512-bit RSA key known only to Intuit. Before Elcomsoft's discovery of Intuit's backdoor, Intuit was the only organization that could unlock their customers' files.

"It is very unlikely that a casual hacker could have broken into Quicken's password protection regimen," said Vladimir Katalov, Elcomsoft's CEO. "Elcomsoft, a respected leader in the crypto community, needed to use its advanced decryption technology to uncover Intuit's undocumented and well-hidden backdoor, and to successfully perform a factorization of their 512-bit RSA key."

Perhaps Intuit included the Quicken backdoor to make it possible for the United States Internal Revenue Service (IRS), FBI, CIA, or other law-enforcement and forensics organizations to use an "escrow key" to gain entry into password-protected Quicken files. Unfortunately, the existence of such a backdoor and escrow key creates a vulnerability that might leave millions of Quicken users worldwide with compromised bank account data, credit card numbers, and income information.

Elcomsoft says it has reported this vulnerability to US CERT.

What does Intuit have to say? Nothing yet -- they haven't gotten back to me. If and when they do, I'll post their response here.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert X. Cringely

InfoWorld
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?