Earlier quoted context omitted.
You think the NSA impersonated themselves?
I meant it may have been a real NSA agent, acting on actual orders, but that he may have lied to get access to source code. If so he wouldn't need to do any MitM attack.
The NSA called me after midnight and requested my source code (2018)
21–30 of 219 posts
Re: The NSA called me after midnight and requested my source code (2018)
#22Re: The NSA called me after midnight and requested my source code (2018)
#23Earlier quoted context omitted.
Only works if the 411 call was MiTMd. edit I was confused and my reply is confusing. I was trying to say that a third party could have stolen the source code by MiTMing the 411 call.
Or if someone who worked for 411 or a hacker changed the number for the naval base to be one they controlled. Dave could be the CEO of 411 for all I know.
Agreed. A couple of ideas for better authenticating the NSA boogeyman.
1. Verify the number in a phone book.
2. Call a friend and ask them to follow the 411 protocol.
3. Drive to a hotel in a different state then follow the 411 protocol.
4. Overnight a cell phone to the NSA headquarters and wait for Dave to call you from it.
5. Call the FBI and ask them for the NSA number.
Re: The NSA called me after midnight and requested my source code (2018)
#24Wow it's a good thing they were examining a "dumb criminal's" laptop instead of preventing 9/11. If they had done that the armaments manufacturers would have missed out on a bonanza.
Are you trolling?
So yeah, I'm the one trolling.
ps: It's also interesting to note that comments like that above start out with four or five upvotes, from honest HN users. Within ten minutes, however, they're downvoted into oblivion. USA-MIC has a strong HN game.
Re: The NSA called me after midnight and requested my source code (2018)
#25Interesting story, but wouldn’t be surprised if the real play here was to get his source code so they could get some bad guys to use a modified version that the NSA could crack. Put a back door in and then intercept traffic trying to download the encryption app to download the back-doored version. The fact that the NSA has to call him in the middle of the night to learn that the free version didn’t use strong encrypt…
Re: The NSA called me after midnight and requested my source code (2018)
#26Interesting read. I wonder whether this was an attempt at social engineering†? While we tend to think of the NSA (or other foreign agencies in this field) working on intercepting information only through electronic means, sometimes a direct approach is often easier (obligatory - xkcd: https://xkcd.com/538/ ). Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor) an…
Only works if the 411 call was MiTMd. edit I was confused and my reply is confusing. I was trying to say that a third party could have stolen the source code by MiTMing the 411 call.
Re: The NSA called me after midnight and requested my source code (2018)
#27Certainly doesn't make me want to use any software made by this guy.
Your security should never depend upon security of your source code. If you're doing things correctly, then the source code doesn't change anything about the security of the data that is encrypted.
Perhaps you mean that he chose to use 40-bit keys instead of 256-bit keys in the free version? I mean, I guess. But that's just a matter of better understanding the details. It sounds like he outlined this clearly and anyone looking for more security knew to pay for the product to get the 256-bit keys.
Re: The NSA called me after midnight and requested my source code (2018)
#28Certainly doesn't make me want to use any software made by this guy.
Wait, why would you not want to use software relied on for national security interests?
The idea that there's an intentional backdoor through security for some institution that may or may not be acting in your best interest is enough for me to not want to use it.
Just about everyone has something to hide, but what they're hiding and the reasons they're hiding it may only be used as leverage against them and have nothing that's a threat to anyone else. My encrypted data has some old tax returns and past medical records--nothing too exciting or compromising, but neither are things I want random people having access to should my copy of the data be compromised.
There are plenty of valid reasons not to want a government agency to be able to pry into every aspect of it's citizens lives. I'd say most people hiding things do it for a lot of social/cultural purposes that aren't too significant at least not in terms of national security.
Take most peoples' browser history--few people want others crawling through searches that might make them feel stupid or insecure for whatever reason. Perhaps they looked at someone's public profile they're interested in dating and don't want to be labeled a 'creep' or perhaps they've been making great use of the free PornHub Premium access lately. People have rights to secure/hide those things and they're no real threat to national security.
Re: The NSA called me after midnight and requested my source code (2018)
#29Re: The NSA called me after midnight and requested my source code (2018)
#30Interesting read. I wonder whether this was an attempt at social engineering†? While we tend to think of the NSA (or other foreign agencies in this field) working on intercepting information only through electronic means, sometimes a direct approach is often easier (obligatory - xkcd: https://xkcd.com/538/ ). Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor) an…
A counterargument against that is A: if the goal is to produce a version with a backdoor, they don't need the source to accomplish that and B: if that was the goal, they wouldn't want to give the original author any reason to know they were asking about it, so that when the backdoor is found in the wild he can pipe up and go "Oh, yeah, that reminds me, the NSA got my source code a few months ago..."