Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

51–60 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#52
post #20

I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…

Think of it from the executives perspective:

Option A: keep mouth shut, make a shit ton of money

Option B: become a martyr, face prison time

People like Snowden are rare.

Re: Secret contract tied NSA and security industry pioneer

#53

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

Terrorists don't, but the banks that they use probably do. You've gotta break into a lot of systems before you get to the information you want.

Re: Secret contract tied NSA and security industry pioneer

#54
post #41

Earlier quoted context omitted.

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Gemalto.

I've worked with them on a chip and PIN* port from Java to the .Net Micro Framework. Very talented bunch of guys.

* My preference anyway to RSA.

Re: Secret contract tied NSA and security industry pioneer

#55

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

Businesses use RSA VPN dongles, and the stories that are starting to surface now are more about economic espionage.

"Follow the money" is a slippery slope.

Re: Secret contract tied NSA and security industry pioneer

#56
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

Well NSA do have highly regarded crypto guys. And they do back the technology.

Re: Secret contract tied NSA and security industry pioneer

#57

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

You are making an assumption that the primary target of SIGINT is terrorists, but in reality it's actually nation states. I think another story just came out today about GCHQ targeting EU officials and embassies.

Re: Secret contract tied NSA and security industry pioneer

#58
post #52
post #20

I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…

Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.

And what if it were very common to take jobs just to hack the internal network, scour it for sensitive-looking data, and dump it all publicly for the sake of fame? I am pretty sure most "executives" would not be happy with that norm

Re: Secret contract tied NSA and security industry pioneer

#59
post #50

Please forgive my ignorance of these kinds of security issues.... I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company? Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?

No, it doesn't mean that at all. RSA is the same algorithm based on https://en.wikipedia.org/wiki/RSA_%28cryptosystem%29 as it always was, and it and its use in openssh have received lots of scrutiny. That the company has the same name is immaterial.

Re: Secret contract tied NSA and security industry pioneer

#60
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

Either you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong…

Unsurprisingly you're already being down-voted. For a community that prides itself on being rational and home to spirited debate, when it comes to the NSA, any contrarian opinions (or even alternative perspectives) tend to be quickly attacked and silenced.

If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments. Now, it appears that most of these users have become tired of being instantly downvoted, and instead avoid these subjects entirely.

I hope that tptacek continues to participate in these security policy discussions, not only for his extensive domain knowledge, but also because he is not afraid to voice beliefs that disagree with prevailing opinion. And right or wrong, its very refreshing.

Post reply on HN