Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

111–120 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#111

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

>Any sufficiently skilled rouge actor

Not quite - finding the actual magic number that enables the backdoor would involve solving the discrete log problem for the suspicious constant in the spec. A more likely scenario is some disgruntled employee steals the number and sells it to the highest bidder.

Re: Secret contract tied NSA and security industry pioneer

#113
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

As much as he can get under one's skin, and as much as he can be abrasive, and any number of other things, I trust his opinions on security and crypto. He's rational to a fault--unfortunately, that means that when facts change he may be left with egg on his face. I don't think there's anything wrong with how he's handled this stuff.

>...I trust his opinions on security and crypto.

And here, ladies and gents, is exactly why we'll continue to inhabit an exploitable world forevermore.

Re: Secret contract tied NSA and security industry pioneer

#114
If it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tools like OpenSSL? What if you add blackmail to the mix?

Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.

Re: Secret contract tied NSA and security industry pioneer

#115

Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366

Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty

When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.

Re: Secret contract tied NSA and security industry pioneer

#116

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

Just a side note, rouge = red, rogue = villain/scoundrel/etc... I hate being that guy but it happened twice and triggered my have to post response. Tshuß!

Just a side note, "Tschüß!" = bye/cheers/etc; "Tshuß!" = I can't spell German.

I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.

Re: Secret contract tied NSA and security industry pioneer

#117
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#118

Who in their right mind would use an American technology product at this point? You would be an idiot to think that it wasn't backdoored by the NSA.

Unfortunately, I think there's still a pretty large market of people who just don't give a crap about being NSA'd. Nothing to hide, and all of that.

That said it's likely individual consumers who are likely to have this attitude rather than businesses.

Re: Secret contract tied NSA and security industry pioneer

#119
post #100

Earlier quoted context omitted.

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is mor…

Your series of comments in this thread is way below the threshold for positive contributions to any HN discussion.

I'm curious as to your opinion of tptacek's deleted comment, and whether that was above or below the positive contribution threshold.

Re: Secret contract tied NSA and security industry pioneer

#120
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

It never claimed that those experts were working in the customer's best interest, though. ;)
Post reply on HN