Earlier quoted context omitted.
Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty
When 'tptacek is wrong, he's obnoxiously wrong, especially in his inability to believe in government misbehavior, and his willingness to denigrate "message board nerds" on that sort of matter. (See also his attacks on Greenwald when the Snowden story started.) So personally I was looking forward to seeing somebody comment about him.
Secret contract tied NSA and security industry pioneer
251–260 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#252Earlier quoted context omitted.
A catchy sound byte, but in almost all practical situations, the best defence is avoiding conflict. In fights: flee. In international affairs: diplomacy.
That is disasterous. That logic is why Chaimberlain allowed Hitler to get more and more and more power. ("Surely they'll agree to peace if we just let them have Poland.") It is also why my generation (I'm 27) will eventually have to fight a nuclear war that pits Iran against Israel and possibly the US. That war will potentially kill millions. And whose fault will it be? Obama's and Bush's. They will (if history is ju…
PS You forgot Clinton bombing pharmaceutical plants in Sudan, then taking his eye off the ball to play his sax, schmooze with Hollywood and chase skirts, while the wheels of 9/11 were set inexorably in motion.
Re: Secret contract tied NSA and security industry pioneer
#253NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…
http://www.nytimes.com/2011/06/04/technology/04security.html...
Re: Secret contract tied NSA and security industry pioneer
#254Earlier quoted context omitted.
Asymmetric warfare with multiple adversaries doesn't work that way. For example, Stuxnet did not make U.S power plants safe from malicious attackers. I recommend reading Ralph Langner's op-ed in the New York Times. http://www.nytimes.com/roomfordebate/2012/06/04/do-cyberatta...
It did make word temporarily safer from Iran nuclear bomb though. Of course, it is only temporary, but almost everything you do is. As for the article, it claims that Stuxnet "opened the Pandora box", but it did nothing of the sort. Stuxnet by itself did not enable anything that wasn't possible before - it was possible for malicious actors to create attacks on US networked infrastructure, and it still is. Stuxnet cha…
Re: Secret contract tied NSA and security industry pioneer
#255Re: Secret contract tied NSA and security industry pioneer
#256Re: Secret contract tied NSA and security industry pioneer
#257Earlier quoted context omitted.
It did make word temporarily safer from Iran nuclear bomb though. Of course, it is only temporary, but almost everything you do is. As for the article, it claims that Stuxnet "opened the Pandora box", but it did nothing of the sort. Stuxnet by itself did not enable anything that wasn't possible before - it was possible for malicious actors to create attacks on US networked infrastructure, and it still is. Stuxnet cha…
Does anyone series believe that Iran is a threat to the world. How about basing threat levels on previous actions? For example, who invades countries most often? Or who's military kills the most people? I've heard about WMD threats before - and who did the invading and killing in the end? That saga ended with almost everyone looking bad.
Re: Secret contract tied NSA and security industry pioneer
#258Earlier quoted context omitted.
I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.
> He is capable of arguing with people with strongly opposing views with civility You're clearly talking about a different tptacek, widely known on this site for his coarsely abrasive, impossibly high friction, social interactions and not admitting he's wrong on issues trivial or important. He's also widely known for a being an expert in his field. All that being said, I agree with you that this site is more valuable…
What are you talking about? Whatever caricature you're illustrating here is not Thomas Ptacek.
With the way you've been talking, I would've suspected you were a newer member, but you've been around for three years or so. So I simply have no idea what you're talking about.
Would you please point out precisely which comments you take issue with? https://www.hnsearch.com/search#request/comments&q=by%3Atpta...
I think the thing to remember about Thomas, and me, and everyone else, is that we're all human, and we all have different moods which influence our behavior. Thomas's, on average, is exemplary.
Re: Secret contract tied NSA and security industry pioneer
#259Earlier quoted context omitted.
Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong…
>Do you have any? Don't really have a dog in this fight, but: up until today, there was no evidence "the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products". Were people wrong to be suspicious?
Re: Secret contract tied NSA and security industry pioneer
#260Earlier quoted context omitted.
After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be…
This is a really bad and somewhat frustrating comment (if you're trolling, nicely done). He's absolutely correct about Telegram and this is not how you run crypto contests. This isn't even a tptacek opinion, it's a "everybody who has any reputation in the crypto field" opinion. Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto…
What I was saying in the comment above, however, had nothing to do with the contest. I expressed concern about tptacek's aggressive promotion of one algorithms (branded as "modern") over the other (claimed as "anachronistic") without any substantial proof. https://news.ycombinator.com/item?id=6941934
This is really alarming.