Live data from Hacker News

Is Extended Random a Malicious NSA Plot?

sockpuppet.org

51–56 of 56 posts

Re: Is Extended Random a Malicious NSA Plot?

#51
post #36

Earlier quoted context omitted.

Mozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989

Good for you, that's the exact same link I posted, and if you'll read the whole bug report like I did, you'll see that I'm not the one who reported it, nor the one who reported the duplicate. Reported: 2014-04-27 03:09 PDT by Zakharias https://bugzilla.mozilla.org/show_bug.cgi?id=993224 Reported: 2014-04-07 19:02 PDT by Katrien So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their s…

To paraphrase: "A implies B, now I'll write a bunch of stuff about why B matters even though that's not under dispute." (Your point of disagreement regarding questions of fact is A.)

Your weakness here (in arguing for B) is the possibility that A is false. That you take A as a premise is evidence enough that you know your belief in A is without basis.

Re: Is Extended Random a Malicious NSA Plot?

#52
post #3

Earlier quoted context omitted.

In small (11px), light-ish (#777777) next to the first paragraph: > If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! I think Dual_EC is a backdoor.

First time I've ever seen sidenotes done like that. BTW, screen reader users (i.e. blind people) can't possibly miss the sidenotes; in fact, each sidenote will interrupt the text at the point where the note is most relevant. So a screen reader will render the first sentence like this: Did Clyde Frog If I call NSA “Clyde Frog” long enough, eventually other people will too. Someone has to start the meme! subvert crypto…

Do screen readers do any special handling of parentheticals? For a note that short, I wouldn't have been surprised if it were inserted inline in parentheses.

Re: Is Extended Random a Malicious NSA Plot?

#53

PKRNG - if the attacker obtains the private key, why do they need the 28+bytes?

If the victim is using Dual_EC_DRBG and Clyde Frog can obtain ~32 bytes of RNG output, they can figure out in reasonable time what the seed to the RNG was (assuming they know how the curve parameters were generated).

"This is a huge deal in the case of SSL/TLS, for example. If I use the Dual-EC PRG to generate the "Client Random" nonce transmitted in the beginning of an SSL connection, then the NSA (sic) will be able to predict the "Pre-Master" secret that I'm going to generate during the RSA handshake. Given this information the connection is now a cleartext read. "[1]

So, Clyde Frog can figure out your RNG state and predict what key you will generate for your TLS session. That's how they obtain the private key.

[1] http://blog.cryptographyengineering.com/2013/09/the-many-fla...

Re: Is Extended Random a Malicious NSA Plot?

#54
post #36

Earlier quoted context omitted.

Mozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989

Good for you, that's the exact same link I posted, and if you'll read the whole bug report like I did, you'll see that I'm not the one who reported it, nor the one who reported the duplicate. Reported: 2014-04-27 03:09 PDT by Zakharias https://bugzilla.mozilla.org/show_bug.cgi?id=993224 Reported: 2014-04-07 19:02 PDT by Katrien So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their s…

You should be embarrassed. What kind of a person writes things like this? You literally have no idea who you're talking about. You saw a name once in a story somewhere, projected a whole backstory onto that name out of your own febrile imagination, and now here you are, lobbying to make everyone else honor your delusions.

Re: Is Extended Random a Malicious NSA Plot?

#55

Earlier quoted context omitted.

Good for you, that's the exact same link I posted, and if you'll read the whole bug report like I did, you'll see that I'm not the one who reported it, nor the one who reported the duplicate. Reported: 2014-04-27 03:09 PDT by Zakharias https://bugzilla.mozilla.org/show_bug.cgi?id=993224 Reported: 2014-04-07 19:02 PDT by Katrien So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their s…

To paraphrase: "A implies B, now I'll write a bunch of stuff about why B matters even though that's not under dispute." (Your point of disagreement regarding questions of fact is A.) Your weakness here (in arguing for B) is the possibility that A is false. That you take A as a premise is evidence enough that you know your belief in A is without basis.

It's amazing that, even though people should be more grateful to open-source projects for providing them a bunch of stuff for free, somehow certain members of the public feel that because the project is "open source" it gives them the right to demand the project to be run the way they want it, including kicking out the Unclean.

Re: Is Extended Random a Malicious NSA Plot?

#56
post #41
post #37

Earlier quoted context omitted.

That's not perfectly accurate; the reason I think an abstract name is helpful is that GCHQ is just as bad, if not worse: it's handy to have a name that captures all of them.

In my defense, when I first skimmed the article I missed the note about the secondary meaning and was quite confused. "New hacker group? Old hacker group I don't know about? Kids these days..."

I did too. I assumed it was referring to an individual working for USG (although "Frog" is a pretty uncommon surname, I'd think).
Post reply on HN