The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?
You are making an assumption that the primary target of SIGINT is terrorists, but in reality it's actually nation states. I think another story just came out today about GCHQ targeting EU officials and embassies.
Secret contract tied NSA and security industry pioneer
71–80 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#72The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?
Heh...I certainly had a good chuckle at this comment. I don't honestly think that the NSA ever paid more than lip-service to the "war on terror". They've been doing the same job since long before Sept. 11, 2001. Before the "war on terror" it was the "cold war", there just happens to have been an awkward gap in between... The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access…
The core cause there would seem to be sharing comm channels with foriegn actors--the same thing that makes our position with regards to the 'net so awesome also means that the NSA is kind of forced to get involved closer to home. It's a tricky tradeoff.
Re: Secret contract tied NSA and security industry pioneer
#73Please forgive my ignorance of these kinds of security issues.... I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company? Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?
Well, "nothing" isn't strictly correct, but connecting them is more like the Kevin Bacon game. Rest assured that this story has nothing whatsoever to do with RSA keys.
Re: Secret contract tied NSA and security industry pioneer
#74I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…
Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.
Re: Secret contract tied NSA and security industry pioneer
#75Earlier quoted context omitted.
Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.
And what if it were very common to take jobs just to hack the internal network, scour it for sensitive-looking data, and dump it all publicly for the sake of fame? I am pretty sure most "executives" would not be happy with that norm
Re: Secret contract tied NSA and security industry pioneer
#76Re: Secret contract tied NSA and security industry pioneer
#77From the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts. " [emphasis added]
Typo; they left out "door".
Re: Secret contract tied NSA and security industry pioneer
#78>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…
Personally, I think one of the things you can't trust these days are comments by tptacek.
Re: Secret contract tied NSA and security industry pioneer
#79Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366
Re: Secret contract tied NSA and security industry pioneer
#80Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
No, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.