Live data from Hacker News

NSA built a NoSQL database

wiki.apache.org

21–30 of 57 posts

Re: NSA built a NoSQL database

#21
post #20
post #10

Prediction: There will be a backdoor.

Warning Zed! This is a humor free zone.

Damn, you'd think with 200k lines of awesome Java that needs to be documented with a manual that's hundreds of pages long that uses 3 other massive Java projects and released by a government agency that's done backdoors in everything from crypto systems, operating systems, to even backdoors themselves, that there'd be at least a plausibility of them putting one in.

Re: NSA built a NoSQL database

#22
post #19

Earlier quoted context omitted.

I don't necessarily think there will be one, but I wouldn't be surprised either. Security flaws can be extremely subtle and 200,000 lines of code is a lot to review... Given that there's plausible deniability (we didn't do it intentionally, it was a genuine bug!), if you were them, wouldn't it at least cross your mind to try it? Also, at some point, if it becomes popular, some sysadmin at a large foreign government a…

But if there is a back door, doesn't releasing it as open source open the possibility that China's or Iran's equivalent of the NSA will audit the code and find it too?

That's why they should stop doing that. We aren't the smartest country on the planet anymore.

Re: NSA built a NoSQL database

#23
post #15
post #12

Earlier quoted context omitted.

C'mon Zed, really? a) The code will be open source - the community can verify the code for anything untoward b) Given the nature of the product, most implementations are going to be behind a firewall anyway, with the storage layer talking to business logic. Even if there was a backdoor, and I'm sure there isn't, not sure how NSA could get in. Do you think there's a backdoor in NSA's open-source algorithm for SHA-1 to…

I think it was just a joke, chill :)

A joke?! A JOKE?! You jest good sir. I merely put on my tinfoil hat and thought, "Hmmm, didn't this happen to OpenBSD, Windows, every crypto system ever, numerous databases, and probably SELinux?" Then extrapolated out to a very valid point.

How dare you claim I am not deadly serious about the NSA putting a back door in a database that is intended to be secure for the internet. How. Dare. You!

Re: NSA built a NoSQL database

#24
post #21
post #20

Earlier quoted context omitted.

Warning Zed! This is a humor free zone.

Damn, you'd think with 200k lines of awesome Java that needs to be documented with a manual that's hundreds of pages long that uses 3 other massive Java projects and released by a government agency that's done backdoors in everything from crypto systems, operating systems, to even backdoors themselves, that there'd be at least a plausibility of them putting one in.

Just curious, what backdoors have been discovered from the NSA?

Re: NSA built a NoSQL database

#25
post #21
post #20

Earlier quoted context omitted.

Warning Zed! This is a humor free zone.

Damn, you'd think with 200k lines of awesome Java that needs to be documented with a manual that's hundreds of pages long that uses 3 other massive Java projects and released by a government agency that's done backdoors in everything from crypto systems, operating systems, to even backdoors themselves, that there'd be at least a plausibility of them putting one in.

http://en.wikipedia.org/wiki/NSAKEY

That's just from a quick google. Back in the day there were stories of "A Visit from Mr. Brown" or something like that. The NSA or "some agency" would go around to anyone making crypto or operating systems and ask to be given backdoors in exchange for deals on export restrictions. Periodically a government agency in another country would find them and we'd be embarrassed. These days it's not as common since crypto exports aren't restricted (much) so the threat of, "If you don't add a backdoor we'll label your software a weapon and you can't sell it to the world." doesn't work.

Then again, could all just be a huge conspiracy.....mwhahahaah.

Re: NSA built a NoSQL database

#26
post #24
post #21

Earlier quoted context omitted.

Damn, you'd think with 200k lines of awesome Java that needs to be documented with a manual that's hundreds of pages long that uses 3 other massive Java projects and released by a government agency that's done backdoors in everything from crypto systems, operating systems, to even backdoors themselves, that there'd be at least a plausibility of them putting one in.

Just curious, what backdoors have been discovered from the NSA?

Oop sorry, I replied wrong. Your answer is above.

Re: NSA built a NoSQL database

#27
post #25
post #21

Earlier quoted context omitted.

Damn, you'd think with 200k lines of awesome Java that needs to be documented with a manual that's hundreds of pages long that uses 3 other massive Java projects and released by a government agency that's done backdoors in everything from crypto systems, operating systems, to even backdoors themselves, that there'd be at least a plausibility of them putting one in.

http://en.wikipedia.org/wiki/NSAKEY That's just from a quick google. Back in the day there were stories of "A Visit from Mr. Brown" or something like that. The NSA or "some agency" would go around to anyone making crypto or operating systems and ask to be given backdoors in exchange for deals on export restrictions. Periodically a government agency in another country would find them and we'd be embarrassed. These day…

Bruce Schneier explains why that is not a back door.

http://www.schneier.com/crypto-gram-9909.html#NSAKeyinMicros...

So other than this, are there any other NSA "backdoors in everything from crypto systems, operating systems, to even backdoors themselves"?

Re: NSA built a NoSQL database

#28
post #27
post #25

Earlier quoted context omitted.

http://en.wikipedia.org/wiki/NSAKEY That's just from a quick google. Back in the day there were stories of "A Visit from Mr. Brown" or something like that. The NSA or "some agency" would go around to anyone making crypto or operating systems and ask to be given backdoors in exchange for deals on export restrictions. Periodically a government agency in another country would find them and we'd be embarrassed. These day…

Bruce Schneier explains why that is not a back door. http://www.schneier.com/crypto-gram-9909.html#NSAKeyinMicros... So other than this, are there any other NSA "backdoors in everything from crypto systems, operating systems, to even backdoors themselves"?

Oh, the great Bruce Schneier says so, so therefore it must be. How do you know he's not a shill for Microsoft and the NSA? Hmm?

The great thing about backdoors is, when they get discovered they have perfect plausible deniability. "Oh that key named NSAKEY isn't for the NSA it's for...uh...this other agency. Yeah that's it! It's not even a key. Right Bruce? Right?!"

Re: NSA built a NoSQL database

#29
post #23
post #15

Earlier quoted context omitted.

I think it was just a joke, chill :)

A joke?! A JOKE?! You jest good sir. I merely put on my tinfoil hat and thought, "Hmmm, didn't this happen to OpenBSD, Windows, every crypto system ever, numerous databases, and probably SELinux?" Then extrapolated out to a very valid point. How dare you claim I am not deadly serious about the NSA putting a back door in a database that is intended to be secure for the internet. How. Dare. You!

I still can't tell if you're joking.

I've seen a possible back door or two in this or that, but nothing like "every crypto system ever".

If you have evidence of a back door in AES, SHA-2, or anything NIST has standardized (other than Dual_EC_DRBG or openly weakened stuff like export SSL) lots of people would like to hear about it.

Re: NSA built a NoSQL database

#30
post #7

" The core codebase consists of 200,000 lines of code (mainly Java) and 100s of pages of documentation." 100s of pages of documentation is a promising start for any open source project.

NSA uses Java. Great to know. Apparently the professionals at the NSA are not swayed by fashion.
Post reply on HN