Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

131–140 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#131

Earlier quoted context omitted.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…

This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…

I think Pavel is providing the financial backing for Telegram, rather than being an employee -http://en.wikipedia.org/wiki/Pavel_Durov

Re: Secret contract tied NSA and security industry pioneer

#134

If it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tools like OpenSSL? What if you add blackmail to the mix? Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.

This is why you want some people who are not primarily motivated by money. (Neither necessarily ascetics.)

In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. (E.g. an independent researcher can actually gain access to and participate in a large and reasonably priced health insurance risk pool. And where money is not the overriding, if not sole, determination of judicial proceedings.)

Going very general in my comment, security is both a community effort and a personal responsibility. The more we "outsource" our own security ("Just trust us." -- Three Letter Agencies and private contractors), the more the price goes up while the quality of the results goes down.

You get the government you pay for, or... if you are more concerned about a quality, effective government, the government you participate in.

Hopefully, the pendulum is beginning to swing back from "pay for" to "participate in".

Re: Secret contract tied NSA and security industry pioneer

#135
post #116

Earlier quoted context omitted.

Just a side note, rouge = red, rogue = villain/scoundrel/etc... I hate being that guy but it happened twice and triggered my have to post response. Tshuß!

Just a side note, "Ts ch üß!" = bye/cheers/etc; "Tshuß!" = I can't spell German. I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.

How many times did you check your comment to make sure all grammar and punctuation is perfect? :)

Re: Secret contract tied NSA and security industry pioneer

#136

Earlier quoted context omitted.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…

This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#137

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories. The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network,…

USCC doesn't protect anyone either. They, like most of the Department of "Defense", are almost entirely offense in nature.

Re: Secret contract tied NSA and security industry pioneer

#138

Earlier quoted context omitted.

This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…

I think Pavel is providing the financial backing for Telegram, rather than being an employee - http://en.wikipedia.org/wiki/Pavel_Durov

Ah, the Telegram HN account just said he "proposed the contest", so I assumed employee. If he is the financier, then it is not surprising that he doesn't understand why his crypto contest is a bad idea.

Re: Secret contract tied NSA and security industry pioneer

#140

Earlier quoted context omitted.

Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty

When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.

Pretty much. Not only that, but he's incredibly influential, so to see him get knocked down a peg does a lot of good.
Post reply on HN