Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

71–80 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#71
post #57

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

You are making an assumption that the primary target of SIGINT is terrorists, but in reality it's actually nation states. I think another story just came out today about GCHQ targeting EU officials and embassies.

Nation states are likely to roll their own dongles though. The folk that use these are bluechips meeting due diligence requirements.

Re: Secret contract tied NSA and security industry pioneer

#72

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

Heh...I certainly had a good chuckle at this comment. I don't honestly think that the NSA ever paid more than lip-service to the "war on terror". They've been doing the same job since long before Sept. 11, 2001. Before the "war on terror" it was the "cold war", there just happens to have been an awkward gap in between... The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access…

This is a very well-put comment.

The core cause there would seem to be sharing comm channels with foriegn actors--the same thing that makes our position with regards to the 'net so awesome also means that the NSA is kind of forced to get involved closer to home. It's a tricky tradeoff.

Re: Secret contract tied NSA and security industry pioneer

#73
post #50

Please forgive my ignorance of these kinds of security issues.... I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company? Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?

RSA the company has nothing to do with RSA the algorithm.

Well, "nothing" isn't strictly correct, but connecting them is more like the Kevin Bacon game. Rest assured that this story has nothing whatsoever to do with RSA keys.

Re: Secret contract tied NSA and security industry pioneer

#74
post #52
post #20

I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…

Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.

Those aren't the only options. Anyone with any smarts can figure out how to quietly and anonymously leak a lot of these details. The fact is that they were too cowardly to do even that though.

Re: Secret contract tied NSA and security industry pioneer

#75
post #58
post #52

Earlier quoted context omitted.

Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.

And what if it were very common to take jobs just to hack the internal network, scour it for sensitive-looking data, and dump it all publicly for the sake of fame? I am pretty sure most "executives" would not be happy with that norm

My guess is that most people educated enough and promoted enough to get access to such information wouldn't risk years of efforts for potential fame. I'd say most of the whistle-blowers want to remain anonymous.

Re: Secret contract tied NSA and security industry pioneer

#77
post #15

From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]

Typo; they left out "door".

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#78
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.

Re: Secret contract tied NSA and security industry pioneer

#80
post #2

Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.

No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.

What makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?
Post reply on HN