Live data from Hacker News

Schneier's take on the alleged backdoor in OpenBSD

schneier.com

31–40 of 40 posts

Re: Schneier's take on the alleged backdoor in OpenBSD

#31
post #28
post #26

Easy way to prove it isn't true: Has there ever been a criminal case prosecuted in the USA where the FBI entered or revealed intercepted VPN data as evidence?

Ah, but perhaps this is why it's so important gitmo detainees, et al, are not granted a trial?

Not sure about that, but if the FBI were conducting any investigations where they were able to exploit VPN traffic because of a hole in OpenBSD, it would show up in a trial somewhere (and if the prosecution do not present how they got the data, a defense can find out through discovery).

Re: Schneier's take on the alleged backdoor in OpenBSD

#32
post #30
post #29

Earlier quoted context omitted.

I don't so much "not like him". But, compare cite records: http://scholar.google.com/scholar?q=Serge+Vaudenay&hl=en... http://scholar.google.com/scholar?q=hans+dobberton&hl=en... http://scholar.google.com/scholar?hl=en&q=eli+biham&... http://scholar.google.com/scholar?hl=en&q=bruce+schneier...

oh is that all. An entire generation were taught cryptography on the back of AC, so he definitely the widest read crypto dev.

He is definitely the widest-read crypto dev. There can be no question of that.

Re: Schneier's take on the alleged backdoor in OpenBSD

#33
post #32
post #30

Earlier quoted context omitted.

oh is that all. An entire generation were taught cryptography on the back of AC, so he definitely the widest read crypto dev.

He is definitely the widest-read crypto dev. There can be no question of that.

Out of curiosity, who else is out there writing essay-length on crypto and security in general?

Re: Schneier's take on the alleged backdoor in OpenBSD

#34
post #32

Earlier quoted context omitted.

He is definitely the widest-read crypto dev. There can be no question of that.

Out of curiosity, who else is out there writing essay-length on crypto and security in general?

One of the better recent sites has been RSnake's:

http://ha.ckers.org/

But he just retired from blogging about netsec and is done with the industry, I think (a lot of ppl get sick of it, I left the sec industry 10+ years ago and never looked back)

Re: Schneier's take on the alleged backdoor in OpenBSD

#35
post #34

Earlier quoted context omitted.

Out of curiosity, who else is out there writing essay-length on crypto and security in general?

One of the better recent sites has been RSnake's: http://ha.ckers.org/ But he just retired from blogging about netsec and is done with the industry, I think (a lot of ppl get sick of it, I left the sec industry 10+ years ago and never looked back)

rsnake doesn't do any crypto work. Like, at all. A fine guy to go to for XSS or SQLI.

Re: Schneier's take on the alleged backdoor in OpenBSD

#36
post #8
post #5

Earlier quoted context omitted.

Plus the NSA has a history of putting backdoors into solutions. Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?

The Clipper Chip[1] immediately comes to mind as the most publicized case of the NSA wanting a backdoor in consumer products. There are also recent stories of the US Government wanting similar encryption disabling mechanisms in other technology[2]. Coupled with the Patriot Act and it letting the NSA eavesdrop on communications, it gives a precedent. A quote I am reminded of is "If you are on the internet, you aren't…

The whole purpose of the Clipper Chip was the escrowed encryption - that is a big difference from a backdoor, especially from a concealed backdoor.

Re: Schneier's take on the alleged backdoor in OpenBSD

#37
post #26

Easy way to prove it isn't true: Has there ever been a criminal case prosecuted in the USA where the FBI entered or revealed intercepted VPN data as evidence?

This is false logic. This way you can only prove that the backdoor exists, not that it doesn't.

Re: Schneier's take on the alleged backdoor in OpenBSD

#38
post #26

Easy way to prove it isn't true: Has there ever been a criminal case prosecuted in the USA where the FBI entered or revealed intercepted VPN data as evidence?

This is false logic. This way you can only prove that the backdoor exists, not that it doesn't.

What I meant to say was that a reason why it may not be true. I started typing the response with one thing in mind and ended with another.

Point still applies though. No cases where prosecution has cited intercepted VPN traffic.

Re: Schneier's take on the alleged backdoor in OpenBSD

#39
post #22
post #18

Earlier quoted context omitted.

Yeah the NSA modified the DES S-Box in its development, they made the final tweeks to the GSM A5/1 algorithm, another person points out the Clipper Chip, etc. You are clueless if you didn't know these things, do you think the NSA just sits on their butt?

The NSA is believed to have strengthened DES by making its substitutions more resilient against differential cryptanalysis. Careful with with words like "clueless". On this point I'm inclined to agree with Schneier: why inject backdoors into things, leaving fingerprints and betraying both opsec and tradecraft, when you can just sit back and watch the software companies build the backdoors for you? NSA has as much as…

"The NSA is believed to have strengthened DES" No they didn't they cut the key size in half, and where can I find on a source that shows me that the s-box changes were intended to make DES stronger?

Re: Schneier's take on the alleged backdoor in OpenBSD

#40
post #39
post #22

Earlier quoted context omitted.

The NSA is believed to have strengthened DES by making its substitutions more resilient against differential cryptanalysis. Careful with with words like "clueless". On this point I'm inclined to agree with Schneier: why inject backdoors into things, leaving fingerprints and betraying both opsec and tradecraft, when you can just sit back and watch the software companies build the backdoors for you? NSA has as much as…

"The NSA is believed to have strengthened DES" No they didn't they cut the key size in half, and where can I find on a source that shows me that the s-box changes were intended to make DES stronger?

Alan Konheim (one of the designers of DES) commented, "We sent the S-boxes off to Washington. They came back and were all different."

[...]

Some of the suspicions about hidden weaknesses in the S-boxes were allayed in 1990, with the independent discovery and open publication by Eli Biham and Adi Shamir of differential cryptanalysis, a general method for breaking block ciphers. The S-boxes of DES were much more resistant to the attack than if they had been chosen at random, strongly suggesting that IBM knew about the technique back in the 1970s.

I'm done bickering about trivia, though. If you'd like the last word, as long as you don't say anything overtly stupid, I'm not going to respond. Happy holidays!

Post reply on HN