Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

121–130 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#121

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories.

The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network, is US Cyber Command: http://en.wikipedia.org/wiki/United_States_Cyber_Command

Re: Secret contract tied NSA and security industry pioneer

#122
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…

You guys are still failing to appreciate that your composition of cryptographic primitives is unproven, which means it is probably broken. Why is it probably broken? Because most compositions of crypto primitives are broken and your adversary is so formidable he will find the smallest problem.

In cryptography, you either prove it is safe or you consider it broken. Your choice should be considered broken until you prove otherwise.

Re: Secret contract tied NSA and security industry pioneer

#124
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…

This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion.

Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto contests that are probably linked all over your other threads.

Re: Secret contract tied NSA and security industry pioneer

#125

Earlier quoted context omitted.

Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty

Not just 'another member of HN', the most high-rated, the most prolific member of HN who is very often found shaping the direction of discussions here and is now a considerable voice in the security community. He's also someone that new tech startup founders listen to when deciding what to use and what not to use.

I know who tptacek is, I've read some of his papers, I've applied to the crypto challenges, I've disagreed with him in the past about the importance of BSAFE to the industry. It still comes across as petty to launch into a meta discussion of who's right and who's wrong on HN when there's much more interesting topics to consider based on this article's revelations.

Re: Secret contract tied NSA and security industry pioneer

#126
post #79

Earlier quoted context omitted.

[deleted]

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is mor…

> Wait, tptacek is calling Bruce Schneier an NSA apologist?

I think that was intended as sarcasm. He's defending his previous position by saying that he (previously) had the same opinion as Bruce Schneier, whom no one would accuse of being partial to the NSA.

Re: Secret contract tied NSA and security industry pioneer

#127
post #100

Earlier quoted context omitted.

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is mor…

Your series of comments in this thread is way below the threshold for positive contributions to any HN discussion.

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#128
post #80

Earlier quoted context omitted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

What makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?

Willing, sure, but probably less able, at least outside of the close allies like the UK.

Re: Secret contract tied NSA and security industry pioneer

#129
post #100

Earlier quoted context omitted.

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is mor…

Your series of comments in this thread is way below the threshold for positive contributions to any HN discussion.

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#130
post #89
post #28

Earlier quoted context omitted.

I like Yubikeys: https://www.yubico.com/ . They show up as a USB keyboard, so you don't have to type the codes in. There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better…

Yubikey NEO (latest revision) is like the one you already have + a java card that comes with a PGPcard app (and supposedly, you can write your own apps) They don't have a timer like the RSA key fobs, and need a USB or NFC connection - but are generally very reliable, and given their constraints. The questiion, of course, is what reason you have to believe that yubico (and for that matter, gemalto, g10code and the res…

Trusting trust :) This is one of, but not the main reasons why we build our own (Bloomberg B-Unit, PDF is the only good pic I see: http://www.bloomberg.com/professional/files/2013/11/b-unit_3...)
Post reply on HN