Live data from Hacker News

NSA OSS Technologies

nationalsecurityagency.github.io

31–40 of 114 posts

Re: NSA OSS Technologies

#32
post #27

I see the PR department is getting smarter...

Federal government is required to open source at least 20 percent of its code now: https://sourcecode.cio.gov/

There are pretty big national security exemptions which the NSA could use without any question: https://sourcecode.cio.gov/Exceptions/

That makes this effort even more commendable.

Re: NSA OSS Technologies

#33
post #26

There's a lot of neat things there. (This one looks interesting: https://iadgov.github.io/goSecure/ ) Also interesting is splitting the repos: that the NSA and IAD have different repos, and that one seems focused on defensive tech while the other is publishing analysis tools. I know there's a lot of people who aren't fans of the NSA (or what they do), but I think most of us can see a need for a military-grade organiz…

I wonder why https://www.iad.gov (linked at https://github.com/iadgov ) is not using a TLS certificate trusted in normal browsers. I cannot visit the webpage as it uses DoD Root CA, which is not installed on my computer.

Having the US department of defense be able to forge certificates for every site world-wide, in every major browser - out of the box - might be a little too much, even with the CA system as broken as it is.

On the other hand, if you run your own CA and mostly care about your own users - using a cert signed by your own CA makes sense - to a certain extent.

Re: NSA OSS Technologies

#34
post #27

I see the PR department is getting smarter...

Federal government is required to open source at least 20 percent of its code now: https://sourcecode.cio.gov/

Wow, that's great. The US being a first mover in OSS again, a pity that Germany doesn't have this.

Re: NSA OSS Technologies

#36

There's a lot of neat things there. (This one looks interesting: https://iadgov.github.io/goSecure/ ) Also interesting is splitting the repos: that the NSA and IAD have different repos, and that one seems focused on defensive tech while the other is publishing analysis tools. I know there's a lot of people who aren't fans of the NSA (or what they do), but I think most of us can see a need for a military-grade organiz…

I think you're right. It's sad to see many people are looking at these tools and performing a sort of "Allegory of the Cave" by extrapolating, then, the evils that can be done with these tools.

Something, mostly common sense, tells me that we will not find some smoking gun to a crime here in these OSS repos...if anyone wanted that, they can refer to any number of leaks.

Ultimately, I'm happy to see this stuff shared, happy to see others use it and happy to see the OSS community build on it.

Post reply on HN