Live data from Hacker News

RSA warns developers not to use RSA products

blog.cryptographyengineering.com

1–10 of 81 posts

Re: RSA warns developers not to use RSA products

#2
The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he?

That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

Re: RSA warns developers not to use RSA products

#3
post #2

The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

Especially the part about KDFs being deliberately slow, and according to him that somehow implies that RNGs should also be slow. Whut? This guy is really a CTO?

Re: RSA warns developers not to use RSA products

#5
post #2

The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

His answers are post-hoc justifications. The real reason they picked it was because they wanted to make money on sweet, sweet government contracts, and the easiest way to do that is to just do everything NIST says to the letter.

Re: RSA warns developers not to use RSA products

#6

Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)

This was actually going to be the first thing I posted when I read this link.

tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard.

Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive-aggresively insult our knowledge of the situation. I look forward to reading what he has to say.

Re: RSA warns developers not to use RSA products

#9
post #2

The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

You're assuming that the CTO is technically competent. I've found over the years that even CTO's who once were technically competent either get lobotomy's, or suffer from hypoxia from the low oxygen at the summit of major corps.

Or, management exists cover up bad hiring practices. Take your pick. Either way, CTO's saying dumb things seems to be normal.

Re: RSA warns developers not to use RSA products

#10
post #6

Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)

This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…

He's been trying to downplay the importance of the leaks since it first started, so what did you expect.
Post reply on HN