Earlier quoted context omitted.
After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…
This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…
Secret contract tied NSA and security industry pioneer
131–140 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#132Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
Re: Secret contract tied NSA and security industry pioneer
#133I hope bsafe licensees sue. Any one know of any serious efforts to replace some of the standard cipher suites in common code? AES -> Serpent, SHA -> Whirlpool etc...
Re: Secret contract tied NSA and security industry pioneer
#134If it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tools like OpenSSL? What if you add blackmail to the mix? Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.
In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. (E.g. an independent researcher can actually gain access to and participate in a large and reasonably priced health insurance risk pool. And where money is not the overriding, if not sole, determination of judicial proceedings.)
Going very general in my comment, security is both a community effort and a personal responsibility. The more we "outsource" our own security ("Just trust us." -- Three Letter Agencies and private contractors), the more the price goes up while the quality of the results goes down.
You get the government you pay for, or... if you are more concerned about a quality, effective government, the government you participate in.
Hopefully, the pendulum is beginning to swing back from "pay for" to "participate in".
Re: Secret contract tied NSA and security industry pioneer
#135Earlier quoted context omitted.
Just a side note, rouge = red, rogue = villain/scoundrel/etc... I hate being that guy but it happened twice and triggered my have to post response. Tshuß!
Just a side note, "Ts ch üß!" = bye/cheers/etc; "Tshuß!" = I can't spell German. I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.
Re: Secret contract tied NSA and security industry pioneer
#136Earlier quoted context omitted.
After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…
This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…
Re: Secret contract tied NSA and security industry pioneer
#137NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…
There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories. The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network,…
Re: Secret contract tied NSA and security industry pioneer
#138Earlier quoted context omitted.
This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…
I think Pavel is providing the financial backing for Telegram, rather than being an employee - http://en.wikipedia.org/wiki/Pavel_Durov
Re: Secret contract tied NSA and security industry pioneer
#139Re: Secret contract tied NSA and security industry pioneer
#140Earlier quoted context omitted.
Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty
When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.