Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

171–180 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#171
post #80

Earlier quoted context omitted.

What makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?

Willing, sure, but probably less able, at least outside of the close allies like the UK.

Why less able?

Re: Secret contract tied NSA and security industry pioneer

#172
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

As much as he can get under one's skin, and as much as he can be abrasive, and any number of other things, I trust his opinions on security and crypto. He's rational to a fault--unfortunately, that means that when facts change he may be left with egg on his face. I don't think there's anything wrong with how he's handled this stuff.

I find tptacek's remarks to be enjoyable, generally speaking. In regards to crypto, I value his opinion highly, especially compared to my own novice opinion.

That said, I seldom trust anything I cannot verify. In matter s of crypto, that often means that I accept some things as magically working, and accept that the magic could wear off at any minute. Same thing with CPUs. I know generally how they work, and understand bitwise logic, but for the most part, they're just magic boxes that I've got enough experience with to have an expectation of.

In matters of the government, the fault I find with tptacek's arguments (and I hadn't even realized that it was a thing until this thread, but now I'm caught up) is that I think it is naive to trust the government. The federal government is something that our founding fathers encouraged us to be suspicious of. They specifically prescribed that, in order for our democracy to thrive, that we should be ever vigilant in regards to those we entrust with power.

Assuming good faith on the part of the NSA is naive, whether or not they're acting scandalously. Assuming good faith on the part of any politician is naive.

That isn't to suggest that we should never trust anything the government does, but if there's ever the potential for abuse, we should expect that potential to be abused at some point. If there's a loophole that could be exploited in any way, we should expect that it will be.

This diatribe isn't really directed at this comment, per se, but at your "have to trust __something__" comment, which I completely agree with as a generality. As humans, we routinely put trust into a great deal of people and things all the time, but I disagree that a government, even a pristine, flawless, immaculate government, is deserving of that trust, and it is our duty as citizens to thoroughly distrust it.

Re: Secret contract tied NSA and security industry pioneer

#173

Earlier quoted context omitted.

I'm curious as to your opinion of tptacek's deleted comment, and whether that was above or below the positive contribution threshold.

It was a reply to a taunt.

I'd say the original comment by lawnchair_larry comes off as a bit gauche... as if the XKCD "someone is wrong on the internet!" guy came here to post. I never saw the deleted comment, but it seems that after the initial frustration wore off, Thomas thought the better of it.

I've had my disagreements with some of Thomas' positions, including several over crypto/politics stories like this, but if you run out like that to play "gotcha!" it just doesn't feel right.

Re: Secret contract tied NSA and security industry pioneer

#174
post #163

Earlier quoted context omitted.

>>People like Snowden are rare. In all honesty, Snowden is a 30 year old single dude, and as far as I know, he doesn't have kids. Do you think he would have done what he did if he had a family to look after? In my opinion a person's first responsibility is to their family. So yeah, if you're married (like these executives probably are) and you're facing the choice between option A and option B, you should absolutely…

What are you saying? That because Snowden didn't have an extension to his own bloodline that it was easy for himself to come forward and blow the whistle?

I can't vouch for whether or not that is what he was saying, but if so, it's pretty likely to be true. People with families, right or wrong, tend to place the security of their family's future above their own political beliefs.

Snowden's actions were brave, regardless of his family status, and I don't wish to downplay that even one iota, but yes, if he had a wife and three kids, it likely would have made his actions even more of a longshot.

Re: Secret contract tied NSA and security industry pioneer

#175

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories. The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network,…

White House: NSA and Cyber Command to stay under one boss

http://arstechnica.com/tech-policy/2013/12/white-house-nsa-a...

Re: Secret contract tied NSA and security industry pioneer

#177

Earlier quoted context omitted.

This is what happens when you make it personal, though. I try to let being right be its own reward, not a license to tell people how wrong they were.

tptacek has the most karma on HN (even moreso than pg): https://news.ycombinator.com/leaders (for reference, pg has 149712 karma at the time of writing; tptacek has 165020 and the next person has 88887) His opinion is respected by many (and many accept what he says without question). A retraction by tptacek reminds us all to think critically lawnchair_larry's comment is equivalent to questioning the president or a ma…

What I do is just not read the usernames (beyond roughly scanning the word to figure out who replied to who). No really, I mean that, I don't even know your username.

That makes for a wonderful experience really. I interact with this nameless entity and each post is largely valued by its responses (I often leave an article open for a few hours to let the comments ripen a bit, that also adds a lot).

Re: Secret contract tied NSA and security industry pioneer

#178
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong…

>Do you have any?

Don't really have a dog in this fight, but: up until today, there was no evidence "the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products".

Were people wrong to be suspicious?

Re: Secret contract tied NSA and security industry pioneer

#180

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories. The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network,…

NSA IA is actually the lead for all IT/technical intelligence defense for both USG and other US entities vs. foreign intelligence/military agencies.
Post reply on HN