Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
RSA warns developers not to use RSA products
21–30 of 81 posts
Re: RSA warns developers not to use RSA products
#22The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Re: RSA warns developers not to use RSA products
#23Earlier quoted context omitted.
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
He's been trying to downplay the importance of the leaks since it first started, so what did you expect.
Re: RSA warns developers not to use RSA products
#24[deleted]
Read this article in full to understand just how it works: http://blog.cryptographyengineering.com/2013/09/the-many-fla...
Now of course, can you do it in a way that not even a veteran cryptographer could ever notice it? Pretty unlikely.
Re: RSA warns developers not to use RSA products
#25The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Seems like we've got a reasonable guess now though.
Re: RSA warns developers not to use RSA products
#26It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
Re: RSA warns developers not to use RSA products
#27It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
Serious question: what's the difference? I would have followed the definition for backdoor since it relies on particular secret information relating P and Q that the NSA might have—but where should one draw the line between backdoors and vulnerabilities? Intent?
An intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor.
So yes, it's pretty much a matter of intent.
Re: RSA warns developers not to use RSA products
#28It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
It's a PRNG based on a trapdoor function where apparently the NSA has the key. With that key they can recover the RNG state from just a small amount of it. Thats a backdoor by most descriptions. This isn't just a bug.
Re: RSA warns developers not to use RSA products
#29Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
You seem to be implying that anyone uses BSafe. Does anyone use it?
[1] http://www.pcworld.idg.com.au/article/129305/rsa_security_so...
[2] http://satchitssecurity.typepad.com/a_page_from_satchits_sec...
Re: RSA warns developers not to use RSA products
#30[deleted]
http://www.wired.com/politics/security/commentary/securityma...
Edit: this was in response to the deleted comment