RSA warns developers not to use RSA products
blog.cryptographyengineering.com
RSA warns developers not to use RSA products
1–10 of 81 posts
Re: RSA warns developers not to use RSA products
#2That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Re: RSA warns developers not to use RSA products
#3The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Re: RSA warns developers not to use RSA products
#4Re: RSA warns developers not to use RSA products
#5The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Re: RSA warns developers not to use RSA products
#6Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard.
Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive-aggresively insult our knowledge of the situation. I look forward to reading what he has to say.
Re: RSA warns developers not to use RSA products
#7Because the NSA didn't just backdoor the Dual_EC standard. It backdoored the technology industry, as well as the rule of law.
Re: RSA warns developers not to use RSA products
#8Re: RSA warns developers not to use RSA products
#9The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Or, management exists cover up bad hiring practices. Take your pick. Either way, CTO's saying dumb things seems to be normal.
Re: RSA warns developers not to use RSA products
#10Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…