Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

81–90 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#81
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

You can definitely trust technical information from tptacek. But you should treat his speculation as you would anyone else.

Re: Secret contract tied NSA and security industry pioneer

#82

Earlier quoted context omitted.

Heh...I certainly had a good chuckle at this comment. I don't honestly think that the NSA ever paid more than lip-service to the "war on terror". They've been doing the same job since long before Sept. 11, 2001. Before the "war on terror" it was the "cold war", there just happens to have been an awkward gap in between... The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access…

This is a very well-put comment. The core cause there would seem to be sharing comm channels with foriegn actors--the same thing that makes our position with regards to the 'net so awesome also means that the NSA is kind of forced to get involved closer to home. It's a tricky tradeoff.

It's the same reason you never see James Bond negotiating with foreign heads of state. You don't send an assassin to do a diplomat's job. Everything that is being revealed about the NSA's actions, this buying of influence especially, is positively reprehensible...BUT it is important to keep an eye on where the blame really lies: with the people that let their assassins dictate their foreign policy and domestic priorities.

Re: Secret contract tied NSA and security industry pioneer

#83

The NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?

>Terrorists don't use VPN dongles.

The story isn't about VPN dongles, it's about a backdoor in an encryption product sold by RSA.

Re: Secret contract tied NSA and security industry pioneer

#84
NSA invents weak (Back Door present) crypto algo.

Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million.

NSA points to RSA as an early adopter and gets NIST to certify it.

Millions of systems are now protected by an RSA product that the NSA deliberately weakened.

Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products -

NSA (Cyber security Command) gets even more money to "Protect" us from said Rogue actors.

So all-in-all good investment on their part

Edit: Spelling fixed per commenter pointing out the difference between rouge and rogue. I did imply malicious actors not red-cheeked actors (not that they are mutually exclusive).

Re: Secret contract tied NSA and security industry pioneer

#86

Earlier quoted context omitted.

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

Fastmail uses the YubiKey for two factor authentication. http://www.yubico.com/

and LastPass

Re: Secret contract tied NSA and security industry pioneer

#87
post #20

I wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly d…

Other executives have.

Look at what happened to Qwest CEO Joseph Nacchio after challenging illegal NSA warrantless wiretapping requests. (Hint: he just got out of federal prison about two months ago.)

http://online.wsj.com/news/articles/SB1000142405270230398390... Mr. Nacchio said he still believes his insider-trading prosecution was government retaliation for rebuffing requests in 2001 from the National Security Agency to access his customers' phone records. His plans to use that belief as a defense at trial never materialized; some of the evidence he wanted to use was deemed classified and barred from being introduced. To Mr. Nacchio, the revelations of former NSA contractor Edward Snowden, who leaked documents saying the agency monitors the email and phone records of Americans, have justified his own stance. He contended the NSA's request was illegal. "I feel vindicated," he said. "I never broke the law, and I never will."

Re: Secret contract tied NSA and security industry pioneer

#88

Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366

Your reaction to this story was wondering if it can be used to demonstrate another member of HN being wrong in the past? Petty

Re: Secret contract tied NSA and security industry pioneer

#89
post #28

Earlier quoted context omitted.

Serious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.

I like Yubikeys: https://www.yubico.com/ . They show up as a USB keyboard, so you don't have to type the codes in. There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better…

Yubikey NEO (latest revision) is like the one you already have + a java card that comes with a PGPcard app (and supposedly, you can write your own apps)

They don't have a timer like the RSA key fobs, and need a USB or NFC connection - but are generally very reliable, and given their constraints.

The questiion, of course, is what reason you have to believe that yubico (and for that matter, gemalto, g10code and the rest) are not similarly in bed with the NSA.

Re: Secret contract tied NSA and security industry pioneer

#90
...which is why Theo Deraadt is now suddenly everyone's best friend, despite his personality. :) OpenSSH and its mother project, OpenBSD, are now all that is left of our civilization's freedom to think.

Thanks, Theo, for never selling us out; for being such an uncompromising bastard; for not being like the RSA. May Athena gird you for war against the Spartans.

Post reply on HN