Is Extended Random a Malicious NSA Plot?
sockpuppet.org
Is Extended Random a Malicious NSA Plot?
1–10 of 56 posts
Re: Is Extended Random a Malicious NSA Plot?
#2Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
Re: Is Extended Random a Malicious NSA Plot?
#3I hate to ask a dumb question, but the article discusses the actions of Clyde Frog a lot. Is Clyde Frog a person, a company, a government project, or what? A web search found a TV show and a stuffed animal, so I'm honestly puzzled. Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
> If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! I think Dual_EC is a backdoor.
Re: Is Extended Random a Malicious NSA Plot?
#4I hate to ask a dumb question, but the article discusses the actions of Clyde Frog a lot. Is Clyde Frog a person, a company, a government project, or what? A web search found a TV show and a stuffed animal, so I'm honestly puzzled. Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
Re: Is Extended Random a Malicious NSA Plot?
#5I hate to ask a dumb question, but the article discusses the actions of Clyde Frog a lot. Is Clyde Frog a person, a company, a government project, or what? A web search found a TV show and a stuffed animal, so I'm honestly puzzled. Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
Anyways: for the DTV hackers, the adversary, DTV and its security contractors, were called "Dave".
I always liked that, so I figured, let's give our global adversary a name.
Re: Is Extended Random a Malicious NSA Plot?
#6Re: Is Extended Random a Malicious NSA Plot?
#7Can anyone figure out whether USG is Unix Systems Group or United States Government. (I think we're safe in assuming they aren't United States Gypsum (though, from my trips through Empire to Gerlach, that was the first thing that came to mind)). [Edit - if you read through the entire (epic and wonderful resource) article, United States Government is used where USG might be - so I think we are safe in assuming it is U…
Re: Is Extended Random a Malicious NSA Plot?
#8"I lean towards “not”; the structure of these proposals makes Clyde Frog’s job needlessly harder, if only by practically ensuring that OpenSSL and Schannel would never default to enabling them. But people smarter than me are convicted of the idea that this was a backdoor attempt." Well yeah it would make their job harder unless one of the largest security companies in the world used that random generator in their flagship encryption product!!!
I feel like maybe their are better arguments for why this was not a subversion attempt, but honestly the points for seem so, so strong and the points against seem like a mountain of wishy-washy humming and hawwing and extending the principle of charity even in the face of the above mentioned giant blaring klaxon of wrong-doing. I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like.
Re: Is Extended Random a Malicious NSA Plot?
#9Doesn't this essay absolutely bury one of the most important parts of this scandal, that RSA used DUAL_EC as the default random number generator in their FIPS certified encryption product for almost a decade!?! I note that this is glossed over with a description so marginal I would tempted to call it dishonest if I were not trying to apply the principle of charity to its author. "RSA BSAFE had support for DUAL_EC." S…
? Extended Random is not a random number generator.
Re: Is Extended Random a Malicious NSA Plot?
#10Doesn't this essay absolutely bury one of the most important parts of this scandal, that RSA used DUAL_EC as the default random number generator in their FIPS certified encryption product for almost a decade!?! I note that this is glossed over with a description so marginal I would tempted to call it dishonest if I were not trying to apply the principle of charity to its author. "RSA BSAFE had support for DUAL_EC." S…
tptacek's first side note on the right column is that his opinion is that DUAL_EC_DRBG is an NSA backdoor. Far from burying the most important part of the scandal, he puts it front and center. This discussion is about other proposed extensions to TLS, not DUAL_EC_DRBG.
It might be too late, but I recommend you edit your comment to change "Extended Random" to DUAL_EC_DRBG (the random number generator). Extended Random is an extension proposed by the NSA (Clyde Frog).