Earlier quoted context omitted.
[deleted]
[deleted]
RSA warns developers not to use RSA products
41–50 of 81 posts
Re: RSA warns developers not to use RSA products
#42Earlier quoted context omitted.
His answers are post-hoc justifications. The real reason they picked it was because they wanted to make money on sweet, sweet government contracts, and the easiest way to do that is to just do everything NIST says to the letter.
http://lists.randombit.net/pipermail/cryptography/2013-Septe...
Re: RSA warns developers not to use RSA products
#43Earlier quoted context omitted.
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
I don't understand his constant line in the sand on this issue (amongst other things). You basically illustrated exactly how he structures his arguments on this topic.
Re: RSA warns developers not to use RSA products
#44Earlier quoted context omitted.
You seem to be implying that anyone uses BSafe. Does anyone use it?
You mean like here [1] and here [2] and here [3]? [1] http://www.pcworld.idg.com.au/article/129305/rsa_security_so... [2] http://satchitssecurity.typepad.com/a_page_from_satchits_sec... [3] http://www.tgc.com/dsstar/01/0724/103320.html
Thanks for the link. I would have just gone on confirming my own biases without it.
Re: RSA warns developers not to use RSA products
#45The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
1. say "we deliberately built the backdoor into our software, please never buy our products again if you value your security" and go live the rest of his life in a Buddhist monastery in Tibet,
2. say some embarrassing BS which gives him a veil of plausible deniability while raising doubts of his personal competency, but who cares, he's a C-type, they don't have to know all the details, right?
Re: RSA warns developers not to use RSA products
#46Re: RSA warns developers not to use RSA products
#47Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
He was right. Nobody in their right mind does use Dual_EC_DRBG.
From this episode I conclude that RSA Security LLC was not in their right mind.
Re: RSA warns developers not to use RSA products
#48Re: RSA warns developers not to use RSA products
#49Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
Looks like that still stands according to the article we're supposed to be discussing here:
".. no sensible cryptographer would go near the thing"