Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
1–10 of 235 posts
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#2And the discussion on HN: https://news.ycombinator.com/item?id=22039481
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#3The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked.
Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public.
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#4X.509 is an over-engineered legacy-cruft-encrusted nightmare. I've implemented stuff that uses it and I never, even after the most careful auditing by myself and peers, leave with the sense that I have handled everything correctly or that my code is totally air-tight.
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#5From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…
More like "do the actual job they are paid to do"
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#6From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…
>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#7https://portal.msrc.microsoft.com/en-US/security-guidance/ad...
> A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#8Earlier quoted context omitted.
>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
"The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances."
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#9From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked. Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major softwar…
>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#10Earlier quoted context omitted.
>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.