he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
Schneier's take on the alleged backdoor in OpenBSD
11–20 of 40 posts
Re: Schneier's take on the alleged backdoor in OpenBSD
#12he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
He's just pointing out that a big project will have bugs and he's right. That's not a matter of opinion. Not much fuzz testing has been done on OpenBSD since the early 2000s. When Theo did fuzz test back then, he found bugs. He claims to have found two just now while doing the audit in the crypto code. Code has bugs. Large projects have many bugs.
Re: Schneier's take on the alleged backdoor in OpenBSD
#13he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
Bruce Schneier isn't some random academic. He's extremely highly respected, and is the Chief Security Technology Officer of BT Communications. He has tons of experience with securing systems in the real world, and to say he "obviously [doesn't] know that much about OpenBSD security culture and history" is crazy.
Re: Schneier's take on the alleged backdoor in OpenBSD
#14Earlier quoted context omitted.
Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?
The Clipper Chip[1] immediately comes to mind as the most publicized case of the NSA wanting a backdoor in consumer products. There are also recent stories of the US Government wanting similar encryption disabling mechanisms in other technology[2]. Coupled with the Patriot Act and it letting the NSA eavesdrop on communications, it gives a precedent. A quote I am reminded of is "If you are on the internet, you aren't…
Re: Schneier's take on the alleged backdoor in OpenBSD
#15Given the past feats from Theo de Raadt, my guess is on a nice stunt to get a free thorough code check :)
After all, he doesn't really profit from a free audit, and all the auditing I've seen so far has been done by the OpenBSD team itself.
Re: Schneier's take on the alleged backdoor in OpenBSD
#16he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
Bruce Schneier isn't some random academic. He's extremely highly respected, and is the Chief Security Technology Officer of BT Communications. He has tons of experience with securing systems in the real world, and to say he "obviously [doesn't] know that much about OpenBSD security culture and history" is crazy.
Re: Schneier's take on the alleged backdoor in OpenBSD
#17he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
Bruce Schneier isn't some random academic. He's extremely highly respected, and is the Chief Security Technology Officer of BT Communications. He has tons of experience with securing systems in the real world, and to say he "obviously [doesn't] know that much about OpenBSD security culture and history" is crazy.
He is, as I am fond of saying lately, "many good things", but.
Re: Schneier's take on the alleged backdoor in OpenBSD
#18he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?
Re: Schneier's take on the alleged backdoor in OpenBSD
#19he didn't add anything new to the discussion but his opinion. Crypto scholars are excellent at cryptography and security theory, but when it comes to actually implementing secure systems (exception being crypto algorithms), and securing systems, Crypto scholars are horrible. For example he mentions that it would be better to just find an existing vulnerability instead of planting an FBI backdoor in the OpenBSD code:…
He's just pointing out that a big project will have bugs and he's right. That's not a matter of opinion. Not much fuzz testing has been done on OpenBSD since the early 2000s. When Theo did fuzz test back then, he found bugs. He claims to have found two just now while doing the audit in the crypto code. Code has bugs. Large projects have many bugs.
Also: while we use fuzzers to probe for specific kinds of crypto flaws, the kind of fuzzing being done then (and for the most part today) does not identify crypto flaws.
We are, let's be clear, talking about a project that appears to have managed to ship IPSEC code that didn't verify packet authenticators for something like a year.
Re: Schneier's take on the alleged backdoor in OpenBSD
#20Earlier quoted context omitted.
Bruce Schneier isn't some random academic. He's extremely highly respected, and is the Chief Security Technology Officer of BT Communications. He has tons of experience with securing systems in the real world, and to say he "obviously [doesn't] know that much about OpenBSD security culture and history" is crazy.
sorry I didn't mean to appear to disrespect Bruce Schneier, I've met him, gone to his book signings, own all his books, I even buy his books for gifts to my friends. I'm a huge fan of his work. We need people like him who have done highly advance studies in the security field; he is the best and an amazingly lucid writer. I never said he was a random academic or that his overall research should be disregarded. I real…