The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…
Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.
Secret contract tied NSA and security industry pioneer
41–50 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#42$10Mi? That's a very cheap price for trashing your companies reputation. More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.
Re: Secret contract tied NSA and security industry pioneer
#43Terrorists don't use VPN dongles.
What is really going on here?
Re: Secret contract tied NSA and security industry pioneer
#44Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.
Re: Secret contract tied NSA and security industry pioneer
#45Re: Secret contract tied NSA and security industry pioneer
#46The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…
Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.
Re: Secret contract tied NSA and security industry pioneer
#47I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…
Re: Secret contract tied NSA and security industry pioneer
#48Re: Secret contract tied NSA and security industry pioneer
#49>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…
Personally, I think one of the things you can't trust these days are comments by tptacek.
HN is incredibly fortunate to count members like 'tptacek as part of its community. We should be behaving in ways which encourage more comments and commenters of his ilk, not less.
Re: Secret contract tied NSA and security industry pioneer
#50I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company?
Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?