Live data from Hacker News

Schneier's take on the alleged backdoor in OpenBSD

schneier.com

21–30 of 40 posts

Re: Schneier's take on the alleged backdoor in OpenBSD

#21
post #19
post #11

Earlier quoted context omitted.

He's just pointing out that a big project will have bugs and he's right. That's not a matter of opinion. Not much fuzz testing has been done on OpenBSD since the early 2000s. When Theo did fuzz test back then, he found bugs. He claims to have found two just now while doing the audit in the crypto code. Code has bugs. Large projects have many bugs.

In the early 2000's I was still speaking to Theo, and I don't believe that during that time period he ever did systemic fuzz testing on OpenBSD. SPIKE wasn't even released until 2002. Also: while we use fuzzers to probe for specific kinds of crypto flaws, the kind of fuzzing being done then (and for the most part today) does not identify crypto flaws. We are, let's be clear, talking about a project that appears to ha…

Here is what he said about his fuzz testing in 2000:

http://lwn.net/2000/0803/a/openbsdfuzz.php3

Re: Schneier's take on the alleged backdoor in OpenBSD

#22
post #18
post #5

Earlier quoted context omitted.

Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?

Yeah the NSA modified the DES S-Box in its development, they made the final tweeks to the GSM A5/1 algorithm, another person points out the Clipper Chip, etc. You are clueless if you didn't know these things, do you think the NSA just sits on their butt?

The NSA is believed to have strengthened DES by making its substitutions more resilient against differential cryptanalysis. Careful with with words like "clueless".

On this point I'm inclined to agree with Schneier: why inject backdoors into things, leaving fingerprints and betraying both opsec and tradecraft, when you can just sit back and watch the software companies build the backdoors for you? NSA has as much as come out and said this at keynote speeches already, but it seems pretty obvious from my vantage point.

Re: Schneier's take on the alleged backdoor in OpenBSD

#23
post #21
post #19

Earlier quoted context omitted.

In the early 2000's I was still speaking to Theo, and I don't believe that during that time period he ever did systemic fuzz testing on OpenBSD. SPIKE wasn't even released until 2002. Also: while we use fuzzers to probe for specific kinds of crypto flaws, the kind of fuzzing being done then (and for the most part today) does not identify crypto flaws. We are, let's be clear, talking about a project that appears to ha…

Here is what he said about his fuzz testing in 2000: http://lwn.net/2000/0803/a/openbsdfuzz.php3

He's talking about the academic research project fuzzing was named for. All it did was fuzz command line arguments.

Re: Schneier's take on the alleged backdoor in OpenBSD

#24
post #14
post #8

Earlier quoted context omitted.

The Clipper Chip[1] immediately comes to mind as the most publicized case of the NSA wanting a backdoor in consumer products. There are also recent stories of the US Government wanting similar encryption disabling mechanisms in other technology[2]. Coupled with the Patriot Act and it letting the NSA eavesdrop on communications, it gives a precedent. A quote I am reminded of is "If you are on the internet, you aren't…

Yeah, but 'wanted' doesn't equal 'did' like the OP claims.

I had always considered the Clipper-Chip incident to hint at the tip of an iceberg.

Do you really think that was an isolated one-time event?

Re: Schneier's take on the alleged backdoor in OpenBSD

#25
post #24
post #14

Earlier quoted context omitted.

Yeah, but 'wanted' doesn't equal 'did' like the OP claims.

I had always considered the Clipper-Chip incident to hint at the tip of an iceberg. Do you really think that was an isolated one-time event?

The Clipper Chip was introduced in the open. They tried to push it through legislation. It's not like the NSA blackmailed Intel executives to include the capabilities secretly in their Pentium Processors without notifying their customers.

Same with the new proposed legislation. But all that demonstrates is that the NSA has an interest in being able to (legally) monitor encrypted communications. Which everyone already knows.

If someone had 'busted' the NSA trying to do something sneaky and/or covert and/or illegal, then you could argue that it's the tip of some iceberg of nefarious activity. But like I said this was all done out in the open.

You might as well say that because we know the FBI wiretaps phones through legally obtained court orders, that's the tip of the iceberg that points to millions of illegal wiretaps. It's a bad inference.

Re: Schneier's take on the alleged backdoor in OpenBSD

#27
post #20
post #16

Earlier quoted context omitted.

sorry I didn't mean to appear to disrespect Bruce Schneier, I've met him, gone to his book signings, own all his books, I even buy his books for gifts to my friends. I'm a huge fan of his work. We need people like him who have done highly advance studies in the security field; he is the best and an amazingly lucid writer. I never said he was a random academic or that his overall research should be disregarded. I real…

I am not so much a Schneier fan, so if you feel like you need cover for leveling any kind of criticism against anything he says, don't worry too much. Are you sure you believe Schneier would know anything about the code quality of a specific IPSEC implementation --- or really, about the code quality of any IPSEC implementation?

Alright, I will bite. What are your reasons for not liking Bruce?

(I can't wait for this)

Re: Schneier's take on the alleged backdoor in OpenBSD

#29
post #27
post #20

Earlier quoted context omitted.

I am not so much a Schneier fan, so if you feel like you need cover for leveling any kind of criticism against anything he says, don't worry too much. Are you sure you believe Schneier would know anything about the code quality of a specific IPSEC implementation --- or really, about the code quality of any IPSEC implementation?

Alright, I will bite. What are your reasons for not liking Bruce? (I can't wait for this)

I don't so much "not like him". But, compare cite records:

http://scholar.google.com/scholar?q=Serge+Vaudenay&hl=en...

http://scholar.google.com/scholar?q=hans+dobberton&hl=en...

http://scholar.google.com/scholar?hl=en&q=eli+biham&...

http://scholar.google.com/scholar?hl=en&q=bruce+schneier...

Re: Schneier's take on the alleged backdoor in OpenBSD

#30
post #29
post #27

Earlier quoted context omitted.

Alright, I will bite. What are your reasons for not liking Bruce? (I can't wait for this)

I don't so much "not like him". But, compare cite records: http://scholar.google.com/scholar?q=Serge+Vaudenay&hl=en... http://scholar.google.com/scholar?q=hans+dobberton&hl=en... http://scholar.google.com/scholar?hl=en&q=eli+biham&... http://scholar.google.com/scholar?hl=en&q=bruce+schneier...

oh is that all. An entire generation were taught cryptography on the back of AC, so he definitely the widest read crypto dev.
Post reply on HN