Live data from Hacker News

Signify: Securing OpenBSD from Us to You

openbsd.org

51–60 of 88 posts

Re: Signify: Securing OpenBSD from Us to You

#51
post #48

Earlier quoted context omitted.

It's not just those curves. Virtually all elliptic-curve cryptography is patent-free, as you would expect for a family of cryptosystems studied since 1986 based on centuries-old math. There are a few current patents, but they cover techniques almost nobody uses.

If it's patent free, why are people paying for it as I linked to? NSA paid for it and are specific that it applies to FIPS 140-2 solutions. Companies were paying Certicom for it. As far as a few years ago, an article gripes about how much Blackberry charges for it. Just weird that it doesn't apply to anything yet companies and governments were all paying for it. If something has changed, I'd like the definitive answe…

People are paying for it because they get value out of what they are paying for. TCP/IP isn't patented, but companies will pay several million dollars for a TCP/IP stack for their embedded firmware.

Don't conflate people's willingness to pay for a particular implementation (accompanying documentation, support, tools), with a legal requirement that they need to do so for the underlying technology.

Re: Signify: Securing OpenBSD from Us to You

#52
post #48

Earlier quoted context omitted.

It's not just those curves. Virtually all elliptic-curve cryptography is patent-free, as you would expect for a family of cryptosystems studied since 1986 based on centuries-old math. There are a few current patents, but they cover techniques almost nobody uses.

If it's patent free, why are people paying for it as I linked to? NSA paid for it and are specific that it applies to FIPS 140-2 solutions. Companies were paying Certicom for it. As far as a few years ago, an article gripes about how much Blackberry charges for it. Just weird that it doesn't apply to anything yet companies and governments were all paying for it. If something has changed, I'd like the definitive answe…

tptacek has already responded to your nonsense below at greater length than I have the patience for: https://news.ycombinator.com/item?id=9709692

FIPS 140-2 is not a cryptosystem standard; it covers the design of hardware security modules using a wide range of algorithms, the majority of which don't use ECC at all. The fact that you mention it at all (rather than, say, FIPS 186-2 Appendix 6) suggests that you have no idea what it is.

Certicom (now part of BlackBerry) offers not just patent licenses but also software licenses.

Several of the previously potentially relevant patents (mentioned in the link upthread) have expired within the last five years.

I recommend you stop giving people advice on subjects where not only do you know nothing, but the things you think you know are false.

Re: Signify: Securing OpenBSD from Us to You

#53
post #48

Earlier quoted context omitted.

I appreciate the update on the situation for those curves.

It's not just those curves. Virtually all elliptic-curve cryptography is patent-free, as you would expect for a family of cryptosystems studied since 1986 based on centuries-old math. There are a few current patents, but they cover techniques almost nobody uses.

@ ghshephard

Your comment implies they're only paying for an implementation. To be sure, do you have a link to a resource analyzing the patents on ECC and showing they don't apply to anything they (or we) use for ECC? That it's a moot issue in its entirety or mostly except for known cases? Otherwise, I'm going to guess that you're guessing like everyone else.

Re: Signify: Securing OpenBSD from Us to You

#54
post #9
post #5

A recent reddit post where a (US) user ordered OpenBSD by mail: http://www.reddit.com/r/openbsd/comments/369vmw/looks_like_i...

Given the NSA's reputation for doing things on the sly, isn't this a little clumsy to attribute to them? As one of the commentators says, it was more likely to be a border agent on the lookout for new music. At one place I worked, we had USB security dongles for license management. We started sending them out in envelopes, and found that few reached their destination intact - the envelope would arrive, with a hole in…

I think-hope he's kidding about the NSA part.

Re: Signify: Securing OpenBSD from Us to You

#55
post #48

Earlier quoted context omitted.

It's not just those curves. Virtually all elliptic-curve cryptography is patent-free, as you would expect for a family of cryptosystems studied since 1986 based on centuries-old math. There are a few current patents, but they cover techniques almost nobody uses.

If it's patent free, why are people paying for it as I linked to? NSA paid for it and are specific that it applies to FIPS 140-2 solutions. Companies were paying Certicom for it. As far as a few years ago, an article gripes about how much Blackberry charges for it. Just weird that it doesn't apply to anything yet companies and governments were all paying for it. If something has changed, I'd like the definitive answe…

[deleted]

Re: Signify: Securing OpenBSD from Us to You

#56
post #52

Earlier quoted context omitted.

If it's patent free, why are people paying for it as I linked to? NSA paid for it and are specific that it applies to FIPS 140-2 solutions. Companies were paying Certicom for it. As far as a few years ago, an article gripes about how much Blackberry charges for it. Just weird that it doesn't apply to anything yet companies and governments were all paying for it. If something has changed, I'd like the definitive answe…

tptacek has already responded to your nonsense below at greater length than I have the patience for: https://news.ycombinator.com/item?id=9709692 FIPS 140-2 is not a cryptosystem standard; it covers the design of hardware security modules using a wide range of algorithms, the majority of which don't use ECC at all. The fact that you mention it at all (rather than, say, FIPS 186-2 Appendix 6) suggests that you have no…

@ kragen

The FIPS 140-2 claim comes from the NSA's licensing of those patents and requirements:

https://www.nsa.gov/business/programs/quick_facts.shtml

Far as patents, there's a quite a variety of them with some filed within the current 20 year window. I repeat for a third time, do you have a resource with a list of patents relevant to ECC and showing that none of them apply to any current implementations (esp BSD licensed)? It might surprise you but your word doesn't mean jack in a patent case: it's the patents, lawyers, and judges that settle it. So, I'm only going to back down on ECC patent risk if we get a definitive statement across these patent portfolios that there's zero risk on one or more implementations. What you all have given me so far is (a) there's no patents on ECC whatsoever, a lie or idiocy; (b) some non-lawyer said certain ones don't apply so magically they all don't in a real court; (c) you personally believe nothing applies so they won't in a court; (d) there's software licenses going on so patents don't apply in a real court despite NSA et al licensing patents. It all sounds really weak. People have lost suits and their profits for less.

I'm still awaiting your reference with evidence that each of the ECC patents don't apply to OSS or commercial implementations. Additionally, since it was added, I'd like your side to cite evidence that everyone is licensing software implementations instead of patents that don't apply to anything. That contradicts what I linked to so burden of proof is on you to show there's no patent-related licensing but software instead.

Re: Signify: Securing OpenBSD from Us to You

#57

Earlier quoted context omitted.

If it's patent free, why are people paying for it as I linked to? NSA paid for it and are specific that it applies to FIPS 140-2 solutions. Companies were paying Certicom for it. As far as a few years ago, an article gripes about how much Blackberry charges for it. Just weird that it doesn't apply to anything yet companies and governments were all paying for it. If something has changed, I'd like the definitive answe…

People are paying for it because they get value out of what they are paying for. TCP/IP isn't patented, but companies will pay several million dollars for a TCP/IP stack for their embedded firmware. Don't conflate people's willingness to pay for a particular implementation (accompanying documentation, support, tools), with a legal requirement that they need to do so for the underlying technology.

I didn't. I thought that, after much publicity and a lawsuit, they paid for patent licenses out of coercion rather than willingness. The usual reason. Maybe the patents don't apply to anything, NSA was just being generous by buying patent licenses for nothing, and everyone else was buying software licenses. As I asked above, I just want a solid reference showing this and that the 100+ patents don't apply to anything we use.

So far, everyone wants me to take their word for it despite my references showing government and companies buying patent licenses. Weird. I'm thinking I should send a letter to Blackberry asking if ECC is covered by their patents or if everyone just wanted to pay for an implementation for various reasons. Might simplify this debate.

Re: Signify: Securing OpenBSD from Us to You

#58
post #52

Earlier quoted context omitted.

tptacek has already responded to your nonsense below at greater length than I have the patience for: https://news.ycombinator.com/item?id=9709692 FIPS 140-2 is not a cryptosystem standard; it covers the design of hardware security modules using a wide range of algorithms, the majority of which don't use ECC at all. The fact that you mention it at all (rather than, say, FIPS 186-2 Appendix 6) suggests that you have no…

@ kragen The FIPS 140-2 claim comes from the NSA's licensing of those patents and requirements: https://www.nsa.gov/business/programs/quick_facts.shtml Far as patents, there's a quite a variety of them with some filed within the current 20 year window. I repeat for a third time , do you have a resource with a list of patents relevant to ECC and showing that none of them apply to any current implementations (esp BSD l…

The references you've linked back up what I've said, not what you've said; not my problem if you don't understand them.

Re: Signify: Securing OpenBSD from Us to You

#59
post #45

Earlier quoted context omitted.

I've updated it for clarification. The NSA did have patents, though. After those expired, they licensed Certicom's and their web site even mentions that this only applies to products conforming to their expectations. As in, they control those to quite a degree. The alternative was paying Certicom a licensing fee. It's still on their web site.

See https://www.nsa.gov/business/programs/quick_facts.shtml for the ECC patent license agreement. It appears to be free, but your use needs to pass some fairly specific restrictions. Not sure if the PLA is available at any cost if your use does not pass.

@ quesara

Yeah that's the one. It has to be FIPS 140-2 compliant or approved by NSA. Outside Type 1 devices or FIPS Level 3-4, both of those seem to suck in practice for security. One way or another, it doesn't get unless they approve it.

Edit to add: That covers the small selection of patents NSA licensed for use in their implementations (esp FIPS 140-2 products). There's around a hundred more of unknown effect. I'd love to see a detailed breakdown of those and risk posed in various ECC use cases.

Re: Signify: Securing OpenBSD from Us to You

#60

Signify is the first OpenBSD code that I've ever read from start to finish - (minus the external libraries like the Ed25519 package). Watching the initial checkins, followed by the amazing improvement in the command line options within a a few weeks of checking by external contributors - the final product is much, much better than the first checkin. What I really appreciate, is that they managed to strike a balance b…

"... the complete absence of CA architecture, or web-of-trust..."
Post reply on HN