Earlier quoted context omitted.
Wait, why would you not want to use software relied on for national security interests?
Does this jump into the "something/nothing to hide" argument? The idea that there's an intentional backdoor through security for some institution that may or may not be acting in your best interest is enough for me to not want to use it. Just about everyone has something to hide, but what they're hiding and the reasons they're hiding it may only be used as leverage against them and have nothing that's a threat to any…
The NSA called me after midnight and requested my source code (2018)
31–40 of 219 posts
Re: The NSA called me after midnight and requested my source code (2018)
#32Re: The NSA called me after midnight and requested my source code (2018)
#33Re: The NSA called me after midnight and requested my source code (2018)
#34Earlier quoted context omitted.
Or if someone who worked for 411 or a hacker changed the number for the naval base to be one they controlled. Dave could be the CEO of 411 for all I know.
> Or if someone who worked for 411 or a hacker changed the number for the naval base to be one they controlled. Dave could be the CEO of 411 for all I know. Agreed. A couple of ideas for better authenticating the NSA boogeyman. 1. Verify the number in a phone book. 2. Call a friend and ask them to follow the 411 protocol. 3. Drive to a hotel in a different state then follow the 411 protocol. 4. Overnight a cell phone…
Re: The NSA called me after midnight and requested my source code (2018)
#35July 2000 is I guess a pre-Google world...so how would "Call 411 and ask for the number of main naval base in Bethesda, MD" work? Just curious how the operator did these lookups?
Re: The NSA called me after midnight and requested my source code (2018)
#36Re: The NSA called me after midnight and requested my source code (2018)
#37Re: The NSA called me after midnight and requested my source code (2018)
#38Interesting read. I wonder whether this was an attempt at social engineering†? While we tend to think of the NSA (or other foreign agencies in this field) working on intercepting information only through electronic means, sometimes a direct approach is often easier (obligatory - xkcd: https://xkcd.com/538/ ). Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor) an…
"Perhaps all they wanted was the source code of his application to repackage (after introducing a backdoor)" A counterargument against that is A: if the goal is to produce a version with a backdoor, they don't need the source to accomplish that and B: if that was the goal, they wouldn't want to give the original author any reason to know they were asking about it, so that when the backdoor is found in the wild he can…
It certainly would make their job easier (and be a lot cheaper)!
> B: if that was the goal, they wouldn't want to give the original author any reason to know they were asking about it,
That's a good point - unless they were targeting a specific target.
Re: The NSA called me after midnight and requested my source code (2018)
#39Certainly doesn't make me want to use any software made by this guy.
Curious why... Your security should never depend upon security of your source code. If you're doing things correctly, then the source code doesn't change anything about the security of the data that is encrypted. Perhaps you mean that he chose to use 40-bit keys instead of 256-bit keys in the free version? I mean, I guess. But that's just a matter of better understanding the details. It sounds like he outlined this c…
Re: The NSA called me after midnight and requested my source code (2018)
#40Without even getting into the social engineering possibility. I don't see a way this looks good for the author.