Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

31–40 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#31
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Fastmail uses the YubiKey for two factor authentication.

http://www.yubico.com/

Re: Secret contract tied NSA and security industry pioneer

#32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

Re: Secret contract tied NSA and security industry pioneer

#33
post #3

TLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit." Dual_EC_DRBG was a NIST standard.

From the article:

"RSA adopted the algorithm even before NIST approved it. The NSA then cited the early use of Dual Elliptic Curve inside the government to argue successfully for NIST approval, according to an official familiar with the proceedings."

Re: Secret contract tied NSA and security industry pioneer

#34
post #10

I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.

i wonder if Snowden has any detailed info on the NSA indroduced/forced backdoors (he obviously was aware about their existence in general like pretty much everybody in the world who isn't a tptacek's religious follower) and this or something like this is what keeps him alive - ie. NSA is afraid of dead man switch while other side(s) hopes that Snowden will reveal more and specifically useful for actual hacking info with time.

Re: Secret contract tied NSA and security industry pioneer

#35
post #10

I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.

This is one of the many issues people have with what the NSA is doing. Weak crypto means not only the NSA can exploit it but possibly many other criminals.

Re: Secret contract tied NSA and security industry pioneer

#36
post #11
post #10

I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.

I don't think this fiasco is related to the tokens but yes the tokens has other problems such that it didn't need NSA to break it.

I wasn't sure I skimmed half the article. It did have a giant image of one the tokens though.

Re: Secret contract tied NSA and security industry pioneer

#38
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Seeing that RSA SecurID VPN dongle pic in the article scared me.

Why do you think they put it there?

Re: Secret contract tied NSA and security industry pioneer

#40
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

IETF is very different from the NIST.
Post reply on HN