Live data from Hacker News

RSA warns developers not to use RSA products

blog.cryptographyengineering.com

71–80 of 81 posts

Re: RSA warns developers not to use RSA products

#71
post #70

Earlier quoted context omitted.

Oh man, you DELETED your comment! I was replying and lost it, so it will be reproduced here due to quoting, as it is important to me that your backpedal of the century be committed to the historical record. -- First off, my comment wasn't out of spite or anything. I would call it a friendly jab. I'm guilty of reaching temporary frustration in some previous discussions with you over civil liberties and privacy, which…

I deleted my comment because I was just helping you make this thread be about me, which is the most boring thing you could possibly make it out of. I have no idea what the "100% undetectable rootkit" thing is about; if you're referring to the talk me, Nate Lawson, and Peter Ferrie did about Joanna Rutkowska's "Blue Pill", our talk made the exact opposite claim --- that virtualization did not make rootkits undetectabl…

No, you might want to re-read what I said about the rootkit thing. I'm saying you understand the compulsion to "call out" a bold claim. The joke was supposed to be me claiming that I have an undetectable rootkit, and you will then be sent on a highly publicized mission to debunk that, which was in fact referring to the Blue Pill Drama. That's actually where I first heard of your company, and when I first came to HN and saw your name, I recognized you as "the rootkit debate guy with the company that I sometimes accidentally call Monsanto".

I'm a bit surprised that you aren't just saying "haha, ok, looks like I called that one wrong." You actually say that you don't care if I think you're wrong. You are not a good sport, sir.

I don't feel like I detracted from Matthew Green's blog by commenting on an unrelated site. Also, I'm going to play the "everybody else came here to say the same thing" card to dodge any guilt.

But who are you kidding? Every crypto thread on HN is about you, whether you like it or not. Most HN readers hit the comments like before seeing the article, just to see what you have to say about it. I know because I'm one of them. That's not a complaint either, I rely on the expertise of others to balance claims put forth in articles being circulated, and you and marshray are awesome commenters for that reason, because you kind of act as a bridge between academic crypto people and non-crypto security people.

Re: RSA warns developers not to use RSA products

#72

Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)

To be fair to tptacek, he was far from the only crypto person saying that...and for good reason. In the absolute best case the algorithm was known to at least be slow and complex to implement, two things that don't usually lead to widespread adoption. The news that RSA had it as the default is interesting regardless.

Re: RSA warns developers not to use RSA products

#73
post #33

Earlier quoted context omitted.

[deleted]

An interesting data point from the boilerplate about the RSA in a press release [1]: "With approximately a billion RSA BSAFE-enabled applications in use worldwide, more than nine million RSA SecurID authentication users and almost 20 years of industry experience, RSA Security has the proven leadership and innovative technology to address the changing security needs of e-business and bring trust to the new, online eco…

Why has it been flagged off the front page?

Re: RSA warns developers not to use RSA products

#74
post #54

Earlier quoted context omitted.

You seem to have already addressed it in another comment: >Thanks for the link. I would have just gone on confirming my own biases without it. This is incredibly evident in your comments on Dual_EC and sometimes happens on other comments as well. You draw a line in the sand and argue around it constantly, eventually bleeding into passive-aggressive attacks on the knowledge of others. I find it valuable to hear from o…

How about this: why don't you tell me what you think my "line in the sand" is? I bet I don't have that line at all. I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it.

I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it.

I hate it when people do that. If you have a position on something, don't leave us all guessing, just state it!

Re: RSA warns developers not to use RSA products

#75
post #70

Earlier quoted context omitted.

I deleted my comment because I was just helping you make this thread be about me, which is the most boring thing you could possibly make it out of. I have no idea what the "100% undetectable rootkit" thing is about; if you're referring to the talk me, Nate Lawson, and Peter Ferrie did about Joanna Rutkowska's "Blue Pill", our talk made the exact opposite claim --- that virtualization did not make rootkits undetectabl…

No, you might want to re-read what I said about the rootkit thing. I'm saying you understand the compulsion to "call out" a bold claim. The joke was supposed to be me claiming that I have an undetectable rootkit, and you will then be sent on a highly publicized mission to debunk that, which was in fact referring to the Blue Pill Drama. That's actually where I first heard of your company, and when I first came to HN a…

I wasn't wrong about Dual_EC!

Also: that's not why we did the Blue Pill talk. It drives me a little nuts that people (incl. Joanna Rutkowska) thought it was.

We did the talk because it was a fun talk. All the code for that talk was kernel code, much of it coding directly to MSRs, looking for fiddley places where the presence of a hypervisor would queer measurement results. And we came up with a bunch of cool ideas! And, it turns out we're (mostly) right. But it seems like all people wanted to pay attention to was the drama.

Anyways, I'm explaining things because I can't resist explaining them, not because this is an important issue for us to work out.

Re: RSA warns developers not to use RSA products

#76

Earlier quoted context omitted.

An interesting data point from the boilerplate about the RSA in a press release [1]: "With approximately a billion RSA BSAFE-enabled applications in use worldwide, more than nine million RSA SecurID authentication users and almost 20 years of industry experience, RSA Security has the proven leadership and innovative technology to address the changing security needs of e-business and bring trust to the new, online eco…

Why has it been flagged off the front page?

It has strayed well off-topic. Even though I think it should stay on the front page, it is fairly obvious why it has been buried.

Re: RSA warns developers not to use RSA products

#77
post #59
post #52

Earlier quoted context omitted.

I'll take you up on that. Here's Schneier on ECC: https://www.schneier.com/crypto-gram-9911.html#EllipticCurve... He wrote this in 1999; ECC was at the time sort of a novelty, it's headline being "a way to do cryptography with smaller key sizes", as if ECC was mostly a way to fit crypto into smaller memory software. Schneier and Ferguson wrote _Practical Cryptography_ in 2003. It has virtually no mention whatsoever o…

You're missing context because it was deleted by the comment's author. It was claimed that Linus Torvalds was "the authority" and that articles were written by non-technical reporters. Schneier is clearly not a non-technical reporter. No claim was made by anyone that Schneier was the one-and-only security god either. Some people worship the ground person P walks on, but it's still just ground. Celebrity doesnt make 2…

(1) The reality is you probably don't understand all the implications of the RSA problem as well as you think you do either.

(2) "You" are just as likely to screw up RSA; the point is, "you" shouldn't be implementing cryptography directly at all, but rather using a well-vetted library. Both RSA and ECC have many viable free options for that.

(3) The reason RSA is going away and ECC is replacing it is that RSA is that RSA at acceptable levels of performance is getting too weak, and RSA at acceptable levels of security is too slow for mass deployment.

(4) It's hard to take "churn" seriously when change happens once over the course of 15 years.

(5) There is no cabal of consultants who get rich selling cryptosystem designs; for instance, for the most part, browser cryptography, email cryptography, and web site cryptography aren't implemented by consultants at all. (If you're wondering: we're not that kind of consultancy.)

Re: RSA warns developers not to use RSA products

#78
post #54

Earlier quoted context omitted.

How about this: why don't you tell me what you think my "line in the sand" is? I bet I don't have that line at all. I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it.

> I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it. I'm very interested in that actually. I'm often curious what shapes people's perspectives on these issues, particularly if it doesn't align with any obvious incentives. I always thought that you must have family in law enforcement or something, but I'd love to know the actual reason.

* NSA topics are heavy on computer security issues and legal issues.

* I'm professionally involved in computer security, like you, and have an an amateur interest in the law (I'm considering law school at some point).

* Message board nerds have a lot of weird, wrong beliefs about computer security and the law.

There is a political difference between me and HN: I'm not an anarcho-capitalist (that silly "world's smallest political test" thingy puts me dead center in "left liberal"). But politics have little to do with where I end up on the NSA threads; it's things like not understanding (or really, having even skimmed) NIST crypto standards, or not taking the time to understand what the 4th Amendment means. The things that get me into "trouble" here have more to do with taking the time to actually read primary sources than anything else.

We probably disagree about NSA a lot less than you think we do.

Re: RSA warns developers not to use RSA products

#79
post #37
post #8

It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.

It's a backdoor. The original paper describing the hole is (hopefully) entitled "On the Possibility of a Back Door in the NIST SP800-90 Dual Ec Prng"[0]. It's no longer a "possibility". [0] http://rump2007.cr.yp.to/15-shumow.pdf

Uh, yes it is still a "possibility". Unless you have a source I missed, which is possible but please actually cite it, all we learned about Dual_EC from the NSA leak was that the algorithm was designed at NSA. Lots of crypto is designed at NSA; it isn't all presumed to backdoored.

Re: RSA warns developers not to use RSA products

#80
Would you trust a computer security company who didn't hash the passwords of their users on their web site, and instead stored the plain text passwords encrypted in their database, with the keys to decrypt them on their server, because they claim that "Your data are encrypted on our server, if you request the password to be sent to you by email the system knows how to decrypt the information and it will send you the Email. This is for customer convenience as many customer do not wish their password to be reset each time they have a problem."

Would you trust a computer security company that when you reset your password on their web site, sent you a new password that was literally the same as your email address that you signed in with?

If this company sold closed source encryption software, would you trust that the software was competently written and did not have back doors, if the president of the company defended their actions of not hashing passwords, and of resetting passwords to their user's email addresses?

What if the president of that company had been prosecuted for computer crimes in the past, and had spend time in jail for it, because after he was first caught, he went right back to phone freaking again and got caught again?

Would you trust the president of the company, who is a convicted felon, who fraudulently made a lot of money by computer crime and got caught, but had most of the charges dropped and his sentence reduced, not to have made a deal with the government and promise to return their favor of giving him a more lenient sentence in exchange for certain favors in the future?

Can anyone guess who I'm referring to?

Post reply on HN