Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
11–20 of 235 posts
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#12Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#13Earlier quoted context omitted.
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
Not sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#14(the tweet where I found it at https://mobile.twitter.com/NSAGov/status/1217152211056238593 has an image version of that PDF, in case you don't trust that domain)
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#15This is yet another illustration of why complexity is evil in cryptographic and security critical code. It's evil everywhere, but it's particularly evil there. The relationship between bugs and complexity is exponential, not linear. X.509 is an over-engineered legacy-cruft-encrusted nightmare. I've implemented stuff that uses it and I never , even after the most careful auditing by myself and peers, leave with the se…
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#16Earlier quoted context omitted.
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
Their job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https:…
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#17At least this only affects Windows 10 (as far as I can tell)
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#18Earlier quoted context omitted.
Their job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https:…
So...SIGINT and CNO. Exactly as I stated.
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#19Earlier quoted context omitted.
Not sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/
And what do you think the end state of all that cybersecurity research is?
Re: Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
#20Earlier quoted context omitted.
>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
They are paid to collect intelligence for the benefit of the american people, not american companies. Luckily citizens united hasn't stretched that far.
Mission Statement The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances.