Live data from Hacker News

Schneier's take on the alleged backdoor in OpenBSD

schneier.com

1–10 of 40 posts

Re: Schneier's take on the alleged backdoor in OpenBSD

#4
he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code: good luck Schneier, obviously you don't know that much about OpenBSD security culture and history. Plus the NSA has a history of putting backdoors into solutions. This is just my opinion from experience.

Re: Schneier's take on the alleged backdoor in OpenBSD

#5
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

Plus the NSA has a history of putting backdoors into solutions.

Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?

Re: Schneier's take on the alleged backdoor in OpenBSD

#6
post #5
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?

[deleted]

Re: Schneier's take on the alleged backdoor in OpenBSD

#7
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

[deleted]

Re: Schneier's take on the alleged backdoor in OpenBSD

#8
post #5
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?

The Clipper Chip[1] immediately comes to mind as the most publicized case of the NSA wanting a backdoor in consumer products. There are also recent stories of the US Government wanting similar encryption disabling mechanisms in other technology[2]. Coupled with the Patriot Act and it letting the NSA eavesdrop on communications, it gives a precedent. A quote I am reminded of is "If you are on the internet, you aren't being paranoid enough".

[1] http://en.wikipedia.org/wiki/Clipper_chip

[2] http://www.wired.com/threatlevel/2010/09/fbi-backdoors/

Re: Schneier's take on the alleged backdoor in OpenBSD

#9
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

Bruce Schneier isn't some random academic. He's extremely highly respected, and is the Chief Security Technology Officer of BT Communications. He has tons of experience with securing systems in the real world, and to say he "obviously [doesn't] know that much about OpenBSD security culture and history" is crazy.

Re: Schneier's take on the alleged backdoor in OpenBSD

#10
post #4

he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…

[deleted]
Post reply on HN