Live data from Hacker News

Signify: Securing OpenBSD from Us to You

openbsd.org

31–40 of 88 posts

Re: Signify: Securing OpenBSD from Us to You

#31

Quick comment regarding key sizes. NSA has a patent on ECC, expects licenses for commercial use, and has some kind of conditions you must adhere to if applying for a license. I'll let your imagination wonder on that last part as mine does. The choice is easy for me between asymmetric crypto that's patent-free and a kind the NSA controls. This might not apply to your personal use but it can to any company using such a…

A few of these people didn't seem to do much research. There's not only one patent on ECC: there's around 130 esp by Certicom with a whole wikipedia article [1] dedicated to the topic. The early NSA patents are indeed expired while the linked Certicom patents seem to be in effect. Article also mentions Bernstein's might be exempt but anyone following patent troll suits won't be assured by that. Certicom loosing the lawsuit against Sony's high-priced lawyers with some prior art is somewhat assuring. Yet, it's a fact that ECC in certain forms (or in general?) is patented and even Schneier was disturbed by how well the patents were written.

So, next time ECC patents come up, those replying like they don't exist hopefully will not mislead HN readers again. (sdevlin's fair comment being an exception) I mean, if there are no patents, we wouldn't have people griping about licensing costs [2] or companies dropping $100+mil on the company for its ECC patents, would we?

[1] https://en.wikipedia.org/wiki/ECC_patents

[2] http://seekingalpha.com/article/2554945-blackberry-make-cert...

Re: Signify: Securing OpenBSD from Us to You

#32
post #23
post #21

Earlier quoted context omitted.

> NSA has a patent on ECC ... Wow, I was not aware that it was even possible for government agencies to hold patents. Is there any reasonable justification for that?

Neither the NSA nor anybody else has a patent on ECC. (And no, there is no reasonable justification for government agencies to hold patents, except to make them free to the public.) There are some patents on particular ECC techniques, as explained in http://cr.yp.to/ecdh/patents.html , but they do not cover the currently most popular ECC systems, and in any case they are mostly expired.

See my above reply concerning 130 patents on ECC.

Re: Signify: Securing OpenBSD from Us to You

#33
post #21

Earlier quoted context omitted.

> NSA has a patent on ECC ... Wow, I was not aware that it was even possible for government agencies to hold patents. Is there any reasonable justification for that?

Maybe to prevent some private company from patenting it? It depends on what one does with a patent. I would think making it free for anyone use, if that were indeed the case, would be appropriate though.

Who knows NSA's purpose. Certicom's was money from licensing: so much that their company (mainly patents) sold for over a hundred million dollars to Blackberry. I have details in comment above.

Re: Signify: Securing OpenBSD from Us to You

#34
post #27

Earlier quoted context omitted.

I got back on GnuPG recently because an associate wouldn't communicate without it. We came up with a trustworthy way to exchange keys. After that, I just cut and pasted crap from this: http://irtfweb.ifa.hawaii.edu/~lockhart/gpg/ Been working fine so far. I'm sure there's all kinds of complicated ways to use it but it just takes a few commands to do most of the work. I only use two these days: one for sending and one…

Are you really confident that cutting and pasting crap from a random web page (particularly one without TLS, so the guy sitting across from you at Starbucks can MITM it) provides you with sufficient understanding to notice when you are accidentally doing something insecure?

I cross-referenced it against the documentation. Let's assume someone won't, though. The commands' appearance make their intent pretty obvious. Further, using them produces output that confirms what the cheat sheet says. For instance, adding a public key said something along the lines of "public key added." Decrypting the incoming message showed its plaintext. Encrypting outgoing plaintext turned it into ciphertext other party decrypted. Along with a warning that the key didn't have others' signatures on it, which ironically re-assured me more because it shouldn't.

So, a visual inspection of the commands and their results in a sandboxed machine was about all one needed to know that they worked. My experience with similar tools helps there. More concerned people can thoroughly cross-reference them with the documentation, source code, program's author, and so on. Whatever level of assurance they like. The basic level, though, was incredibly simple.

I'd take using GPG over learning Emacs or OpenBSD any day. In level of difficulty, that is.

Re: Signify: Securing OpenBSD from Us to You

#35
post #24

Quick comment regarding key sizes. NSA has a patent on ECC, expects licenses for commercial use, and has some kind of conditions you must adhere to if applying for a license. I'll let your imagination wonder on that last part as mine does. The choice is easy for me between asymmetric crypto that's patent-free and a kind the NSA controls. This might not apply to your personal use but it can to any company using such a…

That would be a neat trick, since the foundational patents for ECC were filed in early 90s. The NSA patents are even earlier.

It was: Certicoms ECC patents got them acquired for roughly 7 times what Matasano got. A neater trick would be if you're right, the patents don't exist, and Blackberry was scammed. It go down as one of the greatest cons of that year with Blackberry's shareholders having more to gripe about. I'm just going with Occam's Razor: the ECC patents exist and you're just trolling my latest comment without any evidence to back up your claims. That's been your M.O. so far.

Re: Signify: Securing OpenBSD from Us to You

#36
post #24

Earlier quoted context omitted.

That would be a neat trick, since the foundational patents for ECC were filed in early 90s. The NSA patents are even earlier.

It was: Certicoms ECC patents got them acquired for roughly 7 times what Matasano got. A neater trick would be if you're right, the patents don't exist, and Blackberry was scammed. It go down as one of the greatest cons of that year with Blackberry's shareholders having more to gripe about. I'm just going with Occam's Razor: the ECC patents exist and you're just trolling my latest comment without any evidence to back…

You write this as if the comment I responded to wasn't right there for everyone to read. You said:

NSA has a patent on ECC, expects licenses for commercial use, and has some kind of conditions you must adhere to

My presumption was that you were referring to patents assigned to NSA. NSA had patents relevant to number theoretic crypto. They're long-expired.

Apparently, what you actually meant was:

NSA has licensed a patent now owned by Blackberry.

What this has to do with open source ECC software, you have not made clear. Nobody is talking about using MQV.

It had never occurred to me that I'd sold a company that came within a factor of 7 of the value of Certicom's ECC patents. I did better than I thought I did! Woohoo!

RSA is significantly less safe than ECC alternatives. The situation is not as clear with DH, but it is if you just use Curve25519; Curve25519 is much safer than multiplicative group DH.

Re: Signify: Securing OpenBSD from Us to You

#37
post #23

Earlier quoted context omitted.

Neither the NSA nor anybody else has a patent on ECC. (And no, there is no reasonable justification for government agencies to hold patents, except to make them free to the public.) There are some patents on particular ECC techniques, as explained in http://cr.yp.to/ecdh/patents.html , but they do not cover the currently most popular ECC systems, and in any case they are mostly expired.

See my above reply concerning 130 patents on ECC.

That's not what you said. You said NSA had patents, demanded licenses for their commercial use, and then more or less implied that the condition they imposed on the use of those curves was to backdoor or subvert software that use them.

Obviously, no.

Re: Signify: Securing OpenBSD from Us to You

#38
post #36

Earlier quoted context omitted.

It was: Certicoms ECC patents got them acquired for roughly 7 times what Matasano got. A neater trick would be if you're right, the patents don't exist, and Blackberry was scammed. It go down as one of the greatest cons of that year with Blackberry's shareholders having more to gripe about. I'm just going with Occam's Razor: the ECC patents exist and you're just trolling my latest comment without any evidence to back…

You write this as if the comment I responded to wasn't right there for everyone to read. You said: NSA has a patent on ECC, expects licenses for commercial use, and has some kind of conditions you must adhere to My presumption was that you were referring to patents assigned to NSA. NSA had patents relevant to number theoretic crypto. They're long-expired. Apparently, what you actually meant was: NSA has licensed a pa…

That's a semi-clarification. You brought up foundational patents and NSA patents in a dismissal form. You didn't acknowledge any patent risk on ECC, the gist of my comment, at all. Anyone reading your comment would think there was no patent risk much like the other commenters. Might have not been your intention.

Far as open source, the BSD licenses are used in part to encourage proprietary adoption of superior technology for everyone's benefit. Well, OpenBSD team might have their own reasons as they often do for a lot of things. Any company using BSD code in a commercial product (many do) is fine unless it's covered by patents. It's why Apache license mentions patents specifically. If this ECC was covered by ECC patents, then this could add risk to such a company over other technologies unless they licensed the patents from Blackberry. A specific example would be Genua, a German defense contractor that builds security appliances on OpenBSD.

And congratulations for beating your own expectations on the sale. One of a rare few. ;)

Re: Signify: Securing OpenBSD from Us to You

#39
post #7

It's bizarre that they consider https as an alternative to cryptographic signing, rather than an unrelated addition.

My reading was they did the exact opposite: considered https to be a failure of end-to-end security they wanted. It was various users that apparently wanted HTTPS. I could see how they got to that: I access the site with HTTP; an intercept might happen; HTTPS protects HTTP; let's protect it with HTTPS! Fortunately, the experts knew better and avoided that nonsense.

If end-to-end sec (e.g., crypto signatures) are used, like say with Debian packages which uses GPG, packages and metadata can be released over http without a problem.

Re: Signify: Securing OpenBSD from Us to You

#40
post #37

Earlier quoted context omitted.

See my above reply concerning 130 patents on ECC.

That's not what you said. You said NSA had patents, demanded licenses for their commercial use, and then more or less implied that the condition they imposed on the use of those curves was to backdoor or subvert software that use them. Obviously, no.

I've updated it for clarification. The NSA did have patents, though. After those expired, they licensed Certicom's and their web site even mentions that this only applies to products conforming to their expectations. As in, they control those to quite a degree. The alternative was paying Certicom a licensing fee.

It's still on their web site.

Post reply on HN