Live data from Hacker News

Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

media.defense.gov

11–20 of 235 posts

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#12
Nothing screams "we have microsoft keys!" harder than the fact that the only vulnerabilities reported by the NSA is a cryptographic validation bug. If I had to guess exactly what kind of vulnerabilities they do not need, this is exactly those kind. Who needs crypto validation bug when you already own microsoft's keys?!

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#13

Earlier quoted context omitted.

Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.

Not sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/

And what do you think the end state of all that cybersecurity research is?

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#14
Following a couple of twitter threads led me to this PDF: https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA...

(the tweet where I found it at https://mobile.twitter.com/NSAGov/status/1217152211056238593 has an image version of that PDF, in case you don't trust that domain)

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#15
post #4

This is yet another illustration of why complexity is evil in cryptographic and security critical code. It's evil everywhere, but it's particularly evil there. The relationship between bugs and complexity is exponential, not linear. X.509 is an over-engineered legacy-cruft-encrusted nightmare. I've implemented stuff that uses it and I never , even after the most careful auditing by myself and peers, leave with the se…

The bug is being publicly described as specific to the implementation of a particular class of cryptographic primitives (ECC). If that's accurate, simplifying the certificate data format (unnecessarily messy though it may be) wouldn't do much to mitigate this particular issue.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#16

Earlier quoted context omitted.

Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.

Their job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https:…

So...SIGINT and CNO. Exactly as I stated.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#18

Earlier quoted context omitted.

Their job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https:…

So...SIGINT and CNO. Exactly as I stated.

Security assurance isn’t necessarily cyber warfare. To have the high ground is not the same as using it offensively, hence the expectation of defensive posture as part of the NSA’s mission (although admittedly some offensive activities are to be expected, depending on the situation, such as Stuxnet and Iran).

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#19

Earlier quoted context omitted.

Not sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/

And what do you think the end state of all that cybersecurity research is?

NSA has both attack and defense mandates and organizations. Currently, the attack org has priority, but it's not like the defense org does nothing. So if the attack org doesn't want a vuln, they can let the defense org reveal it for PR points.

Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]

#20
post #9

Earlier quoted context omitted.

>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"

They are paid to collect intelligence for the benefit of the american people, not american companies. Luckily citizens united hasn't stretched that far.

Their mission also explicitly includes information assurance:

Mission Statement The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances.

Post reply on HN