Live data from Hacker News

RSA warns developers not to use RSA products

blog.cryptographyengineering.com

21–30 of 81 posts

Re: RSA warns developers not to use RSA products

#22
post #2

The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

I think it's probably very easy to rise into the upper levels of management at EMC while being a complete moron.

Re: RSA warns developers not to use RSA products

#23
post #6

Earlier quoted context omitted.

This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…

He's been trying to downplay the importance of the leaks since it first started, so what did you expect.

[deleted]

Re: RSA warns developers not to use RSA products

#24
post #15

[deleted]

Actually, you very well can (try to) backdoor any kind of cryptographic algorithm. A hashing algorithm, an encryption algorithm, or a PRNG algorithm.

Read this article in full to understand just how it works: http://blog.cryptographyengineering.com/2013/09/the-many-fla...

Now of course, can you do it in a way that not even a veteran cryptographer could ever notice it? Pretty unlikely.

Re: RSA warns developers not to use RSA products

#25
post #2

The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).

We still don't know who at RSA opened the spreadsheet that carried the malware behind the SecurID breach.

Seems like we've got a reasonable guess now though.

Re: RSA warns developers not to use RSA products

#26
post #8

It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.

An intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor.

Re: RSA warns developers not to use RSA products

#27
post #12
post #8

It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.

Serious question: what's the difference? I would have followed the definition for backdoor since it relies on particular secret information relating P and Q that the NSA might have—but where should one draw the line between backdoors and vulnerabilities? Intent?

Repeating my comment:

An intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor.

So yes, it's pretty much a matter of intent.

Re: RSA warns developers not to use RSA products

#28
post #17
post #8

It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.

It's a PRNG based on a trapdoor function where apparently the NSA has the key. With that key they can recover the RNG state from just a small amount of it. Thats a backdoor by most descriptions. This isn't just a bug.

Snowden obviously has that key as well.

Re: RSA warns developers not to use RSA products

#29

Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)

You seem to be implying that anyone uses BSafe. Does anyone use it?

You mean like here [1] and here [2] and here [3]?

[1] http://www.pcworld.idg.com.au/article/129305/rsa_security_so...

[2] http://satchitssecurity.typepad.com/a_page_from_satchits_sec...

[3] http://www.tgc.com/dsstar/01/0724/103320.html

Post reply on HN