Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

41–50 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#41
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Gemalto.

Re: Secret contract tied NSA and security industry pioneer

#42

$10Mi? That's a very cheap price for trashing your companies reputation. More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.

"it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year"

Re: Secret contract tied NSA and security industry pioneer

#44
post #2

Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

That's quite a leap from the information in that article.

Re: Secret contract tied NSA and security industry pioneer

#46
post #6

The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Both of mine are http://vasco.com

Re: Secret contract tied NSA and security industry pioneer

#47
post #20

I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#48
Privacy: Pre-internet term(from Latin: privatus "separated from the rest, deprived of something, esp. office, participation in the government", from privo "to deprive") used to describe the ability for human beings to seclude themselves or information about themselves and thereby reveal themselves selectively.

Re: Secret contract tied NSA and security industry pioneer

#49
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong some of the time".

HN is incredibly fortunate to count members like 'tptacek as part of its community. We should be behaving in ways which encourage more comments and commenters of his ilk, not less.

Re: Secret contract tied NSA and security industry pioneer

#50
Please forgive my ignorance of these kinds of security issues....

I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company?

Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?

Post reply on HN