Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

141–150 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#141
post #116

Earlier quoted context omitted.

Just a side note, "Ts ch üß!" = bye/cheers/etc; "Tshuß!" = I can't spell German. I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.

How many times did you check your comment to make sure all grammar and punctuation is perfect? :)

Is wasn't perfect. There was a space between "but" and the ellipsis. Not to mention the several other mistakes.

Re: Secret contract tied NSA and security industry pioneer

#142

Earlier quoted context omitted.

When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.

Pretty much. Not only that, but he's incredibly influential, so to see him get knocked down a peg does a lot of good.

This is a bit much and was not at all the motivation behind my comment.

Re: Secret contract tied NSA and security industry pioneer

#143

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

Lucky Green, who appears to have had inside knowledge of this deal based on this mailing list post from September, seems to disagree that this was a good investment:

http://lists.randombit.net/pipermail/cryptography/2013-Septe...

The particularly relevant portion is this:

"This was $10M wasted. While this vendor may have had a dominating position in the market place before certain patents expired, by the time DoD/NSA paid the $10M, few customers used that vendor's cryptographic libraries.

There is no reason to believe that the $250M per year that I have seen quoted as used to backdoor commercial cryptographic software is spent to any meaningful effect."

Interestingly the mailing list post doesn't seem to mention the use of RSA's adoption as a factor in the NIST standard, so it's possible that while their knowledge was more advanced than the public's they didn't know about that side-effect.

Re: Secret contract tied NSA and security industry pioneer

#144

Earlier quoted context omitted.

I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.

https://news.ycombinator.com/item?id=6944628 > Jesus, what a tool you are. How very civil and gracious.

Sometimes it's tough to contain righteous internet rage. I think he knows that crossed the line and that is why he deleted the comment.

Re: Secret contract tied NSA and security industry pioneer

#145

Earlier quoted context omitted.

I think Pavel is providing the financial backing for Telegram, rather than being an employee - http://en.wikipedia.org/wiki/Pavel_Durov

Ah, the Telegram HN account just said he "proposed the contest", so I assumed employee. If he is the financier, then it is not surprising that he doesn't understand why his crypto contest is a bad idea.

right and it also explains why the Telegram guys went ahead with his suggestion, because they're presumably keen to keep their main financial backer happy.

I don't think there's any attempt to sell snakeoil here, this is a case of a road to hell being paved with good intentions. To people not well versed in cryptography the things Pavel is saying and the approach Telegram is taking all seem completely reasonable, and the people who do do crypto and are responding might as well be talking a different language. To them the flaws and red flags are so obvious that their responses are incredulous, which has led to the vitriolic back and forth we've seen - neither side can comprehend the other's position. This is Dunning-Kruger[0].

[0] http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect

Re: Secret contract tied NSA and security industry pioneer

#146

Earlier quoted context omitted.

Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong…

Unsurprisingly you're already being down-voted. For a community that prides itself on being rational and home to spirited debate, when it comes to the NSA, any contrarian opinions (or even alternative perspectives) tend to be quickly attacked and silenced. If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments. Now, it appears that…

> If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments.

Always mixed with a steady groan of "enough of NSA stories" and "none of this is surprising". The heated discussions were in no small part about wether this was even the problem it was made out to be and wether it should even be discussed (to this extent).

Not that I agree with downvoting instead of replying, or with bashing tptacek (Everybody loves telling experts "I told you so". Doesn't make us experts tho :P), but I don't agree with your narrative either. It's not falsifiable, anyway. People might just as well have given up on trying to downplay this, and walked away instead, which would be even worse. Why speculate. Bashing and downvoting for disagreement without argument sucks either way.

Re: Secret contract tied NSA and security industry pioneer

#147
post #80

Earlier quoted context omitted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

What makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?

Only the same things that makes me think american companies would not accept money from foreign spy agencies.

Re: Secret contract tied NSA and security industry pioneer

#148
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…

In cryptography, the expectation is that the person presenting the algorithm should substantiate their claims, preferably with a proof. Saying that something is secure because it hasn't been broken yet does not settle well with people. And when it does happen, it's clearly caveated ("assuming the hardness of Discrete Logarithms", for example).

That aside, your challenge smacks of snake oil. I gave an analogy earlier that captures the essence of the complaints:

Suppose I am selling fire-proof safes. These are designed to protect your documents and valuables from thieves and from fire and other events.

The normal way people set up tests is to put some documents and valuables in a box and actually try to break it (MythBusters style, bringing out cool machinery and trying different ways). For fire resistance, there is a rating system (https://en.wikipedia.org/wiki/Fire-resistance_rating) and a standard way to test.

The Telegram proposition is: we are going to place the safe in Fort Knox. If you can't break the safe that is in Fort Knox, then clearly our safe is secure.

People are arguing that in order to break the safe, you have to break into Fort Knox. And for all intents and purposes that's not going to happen. You could have put a cardboard box in Fort Knox but no one can tell the difference because of the way you structured the challenge.

In that sense, you aren't testing the real-life security.

Re: Secret contract tied NSA and security industry pioneer

#149

Earlier quoted context omitted.

I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.

https://news.ycombinator.com/item?id=6944628 > Jesus, what a tool you are. How very civil and gracious.

He deleted, i.e. retracted it. In full. To harp on about it instead of talking about the story kinda sucks. We're talking about mass surveillance and everything being recorded, and look at what we are doing. Repeat after me: every day is a new day.

Re: Secret contract tied NSA and security industry pioneer

#150

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

You're wrong on points 5 and 6. Dual_EC_DRBG is not "unsafe" per se; it's just that the constants chosen could be precalculated so as to allow easier prediction of the resulting random numbers. This doesn't mean that the numbers the constant was calculated from are easily calculable by an attacker.
Post reply on HN