Earlier quoted context omitted.
Just a side note, "Ts ch üß!" = bye/cheers/etc; "Tshuß!" = I can't spell German. I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.
How many times did you check your comment to make sure all grammar and punctuation is perfect? :)
Secret contract tied NSA and security industry pioneer
141–150 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#142Earlier quoted context omitted.
When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.
Pretty much. Not only that, but he's incredibly influential, so to see him get knocked down a peg does a lot of good.
Re: Secret contract tied NSA and security industry pioneer
#143NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…
http://lists.randombit.net/pipermail/cryptography/2013-Septe...
The particularly relevant portion is this:
"This was $10M wasted. While this vendor may have had a dominating position in the market place before certain patents expired, by the time DoD/NSA paid the $10M, few customers used that vendor's cryptographic libraries.
There is no reason to believe that the $250M per year that I have seen quoted as used to backdoor commercial cryptographic software is spent to any meaningful effect."
Interestingly the mailing list post doesn't seem to mention the use of RSA's adoption as a factor in the NIST standard, so it's possible that while their knowledge was more advanced than the public's they didn't know about that side-effect.
Re: Secret contract tied NSA and security industry pioneer
#144Earlier quoted context omitted.
I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.
https://news.ycombinator.com/item?id=6944628 > Jesus, what a tool you are. How very civil and gracious.
Re: Secret contract tied NSA and security industry pioneer
#145Earlier quoted context omitted.
I think Pavel is providing the financial backing for Telegram, rather than being an employee - http://en.wikipedia.org/wiki/Pavel_Durov
Ah, the Telegram HN account just said he "proposed the contest", so I assumed employee. If he is the financier, then it is not surprising that he doesn't understand why his crypto contest is a bad idea.
I don't think there's any attempt to sell snakeoil here, this is a case of a road to hell being paved with good intentions. To people not well versed in cryptography the things Pavel is saying and the approach Telegram is taking all seem completely reasonable, and the people who do do crypto and are responding might as well be talking a different language. To them the flaws and red flags are so obvious that their responses are incredulous, which has led to the vitriolic back and forth we've seen - neither side can comprehend the other's position. This is Dunning-Kruger[0].
[0] http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
Re: Secret contract tied NSA and security industry pioneer
#146Earlier quoted context omitted.
Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong…
Unsurprisingly you're already being down-voted. For a community that prides itself on being rational and home to spirited debate, when it comes to the NSA, any contrarian opinions (or even alternative perspectives) tend to be quickly attacked and silenced. If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments. Now, it appears that…
Always mixed with a steady groan of "enough of NSA stories" and "none of this is surprising". The heated discussions were in no small part about wether this was even the problem it was made out to be and wether it should even be discussed (to this extent).
Not that I agree with downvoting instead of replying, or with bashing tptacek (Everybody loves telling experts "I told you so". Doesn't make us experts tho :P), but I don't agree with your narrative either. It's not falsifiable, anyway. People might just as well have given up on trying to downplay this, and walked away instead, which would be even worse. Why speculate. Bashing and downvoting for disagreement without argument sucks either way.
Re: Secret contract tied NSA and security industry pioneer
#147Earlier quoted context omitted.
No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.
What makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?
Re: Secret contract tied NSA and security industry pioneer
#148Earlier quoted context omitted.
Personally, I think one of the things you can't trust these days are comments by tptacek.
After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…
That aside, your challenge smacks of snake oil. I gave an analogy earlier that captures the essence of the complaints:
Suppose I am selling fire-proof safes. These are designed to protect your documents and valuables from thieves and from fire and other events.
The normal way people set up tests is to put some documents and valuables in a box and actually try to break it (MythBusters style, bringing out cool machinery and trying different ways). For fire resistance, there is a rating system (https://en.wikipedia.org/wiki/Fire-resistance_rating) and a standard way to test.
The Telegram proposition is: we are going to place the safe in Fort Knox. If you can't break the safe that is in Fort Knox, then clearly our safe is secure.
People are arguing that in order to break the safe, you have to break into Fort Knox. And for all intents and purposes that's not going to happen. You could have put a cardboard box in Fort Knox but no one can tell the difference because of the way you structured the challenge.
In that sense, you aren't testing the real-life security.
Re: Secret contract tied NSA and security industry pioneer
#149Earlier quoted context omitted.
I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.
https://news.ycombinator.com/item?id=6944628 > Jesus, what a tool you are. How very civil and gracious.
Re: Secret contract tied NSA and security industry pioneer
#150NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…