Live data from Hacker News

Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

media.defense.gov

1–10 of 235 posts

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#3
From Krebs tweets:

The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked.

Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#4
This is yet another illustration of why complexity is evil in cryptographic and security critical code. It's evil everywhere, but it's particularly evil there. The relationship between bugs and complexity is exponential, not linear.

X.509 is an over-engineered legacy-cruft-encrusted nightmare. I've implemented stuff that uses it and I never, even after the most careful auditing by myself and peers, leave with the sense that I have handled everything correctly or that my code is totally air-tight.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#5
post #3

From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…

>a new initiative at NSA dubbed "Turn a New Leaf,"

More like "do the actual job they are paid to do"

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#6
post #3

From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…

>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"

Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#7
The actual advisory from Microsoft (CVE-2020-0601):

https://portal.msrc.microsoft.com/en-US/security-guidance/ad...

> A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#8

Earlier quoted context omitted.

>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"

Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.

Their job is more than that.

"The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances."

[1] https://www.nsa.gov/about/mission-values/

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#9
post #3

From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…

>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"

They are paid to collect intelligence for the benefit of the american people, not american companies. Luckily citizens united hasn't stretched that far.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#10

Earlier quoted context omitted.

>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"

Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.

Not sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/
Post reply on HN