Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

201–210 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#201

Earlier quoted context omitted.

This is what happens when you make it personal, though. I try to let being right be its own reward, not a license to tell people how wrong they were.

tptacek has the most karma on HN (even moreso than pg): https://news.ycombinator.com/leaders (for reference, pg has 149712 karma at the time of writing; tptacek has 165020 and the next person has 88887) His opinion is respected by many (and many accept what he says without question). A retraction by tptacek reminds us all to think critically lawnchair_larry's comment is equivalent to questioning the president or a ma…

Comparing someone with high comment karma to the president is a bit absurd, no? The president could more aptly be compared to forum moderators on any given discussion website, as both have some executive power.

Re: Secret contract tied NSA and security industry pioneer

#205

What implications does this have for RSA?

Hopefully the end of them. It's the only thing that matters to these mercenaries...

I strongly agree.

Crypto is something where reputation is sine qua non. After the 2011 data breech they lost a lot of it. Now how can anyone trust them ever again?

Re: Secret contract tied NSA and security industry pioneer

#206
post #196

Earlier quoted context omitted.

Nacchio defrauded shareholders out of millions of dollars. Let's be careful about who we're valorizing.

I'm generally curious about this. I have no idea how to judge Nacchio's career. Can you point some facts proving this point of view? Or maybe: How was his position any different than yours, if you had a request from the NSA that you wouldn't want to fulfil, knowing that rejecting it could destroy your company, what would you do?

The issue is, imo, very murky but as I understand it:

NSA approached Nacchio and Qwest to do what they were doing with AT&T and Verizon. Qwest had previously helped the NSA intercept all comms in Salt Lake City during the Olympics but told the NSA they weren't interested in cooperating. Nacchio sells some stock. Qwest is suddenly dropped as the favored vendor for a huge government contract leading to a drop in Qwest's share price and earnings.

The US federal goverment's position was that Nacchio knew the contract was going to get dropped and cashed out early - insider trading. Nacchio contended that he was just selling stock and that the government had pulled the contract to entrap and prosecute him in the current case.

Re: Secret contract tied NSA and security industry pioneer

#207

Earlier quoted context omitted.

There's enough wrong with what the NSA has been doing, and enough reasons to encourage people to take an interest in how to curtail, or at least better police, their actions without resorting to tawdry conspiracy theories. The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network,…

USCC doesn't protect anyone either. They, like most of the Department of "Defense", are almost entirely offense in nature.

The best defence is a good offence.

Re: Secret contract tied NSA and security industry pioneer

#208
RSA is commercially dead. There's no excuse.

Also, closed-source hardware HSMs are blackboxes that are fundamentally paranoia-inducing. There's no reason to trust that the vendor, supply chain and/or manufacturers didn't backdoor them or introduce other attack surfaces. The only way to trust an implementation is decap a sample of ASICs and match features against masks you generated... from sources you trust (whether open source or yours).

If it's a black box, there's no way to trust it (all modern CPUs, N/S-bridge, memory, flash (ssd), hd controllers, on and on.)

Conclusion: We need more open-source hardware that is production-quality (BSD licensed)! This would be very expensive in terms of people time, but it's necessary move since corporations can't be trusted.

Re: Secret contract tied NSA and security industry pioneer

#209
Not surprised.

One of the security guys who worked for General Magic (GM made an early mobile OS with some security features) told me that he had a visit from the NSA. The NSA tried to get him to leak bits of the keys in the GM protocols. "Just here and there. I've got dozens of these," said one of the NSA reps.

This would have been early 90s.

The NSA has been doing domestic stuff like this for a long time.

Re: Secret contract tied NSA and security industry pioneer

#210
post #17

This is going to end RSA

The reaction from the average IT architect is to just select another vendor that provides yet another closed-source, blackbox hardware security solution, backdoored by who know which government(s) &| other entities. Open source hardware is (un)fortunately a necessary requirement (verilog/vhdl, firmware sources and no blackbox SoCs), samples of which are periodically verified by destructive and nondestructive means. Very, very costly, but doable and raises confidence.
Post reply on HN