Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

21–30 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#21
>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft)

Does this count?(not trying to be sarcastic or a smart-a##), I just want to get a handle on what I should or should not trust these days. Seeing that RSA SecurID VPN dongle pic in the article scared me. I've pretty much been looking to your comments to give me a baseline.

Re: Secret contract tied NSA and security industry pioneer

#22
Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor.

Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke.

https://news.ycombinator.com/item?id=6941366

Re: Secret contract tied NSA and security industry pioneer

#23
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

This is really hilarious.

Re: Secret contract tied NSA and security industry pioneer

#24
"RSA, now a subsidiary of computer storage giant EMC Corp, urged customers to stop using the NSA formula after the Snowden disclosures revealed its weakness." - Just shake my head at this. As news is revealed that all these companies were complicit, they cry foul and "warn" users? RSA deserves to lose all international customers who refuse to buy their products because of hidden backdoors.

Re: Secret contract tied NSA and security industry pioneer

#28
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

I like Yubikeys: https://www.yubico.com/. They show up as a USB keyboard, so you don't have to type the codes in.

There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better than authing with just a password or client cert.

Re: Secret contract tied NSA and security industry pioneer

#29
the r in rsa is ron rivest who was responsible for some very elegant ideas. his papers, that i've read, are generally very simple and clear. but he also wrote md2 [an old hash, n longer used] which contains some "magic numbers" that no-one can explain. they are supposed to be derived from pi, but no-one knows how... http://crypto.stackexchange.com/questions/11935/how-is-the-m... (i even emailed him, but was shrugged off; i know it's silly and paranoid, but...)

anyway, i wonder what happens now to all the customers that use rsa dongles? big, international, political organisations...

Post reply on HN