Live data from Hacker News

Secret contract tied NSA and security industry pioneer

reuters.com

91–100 of 346 posts

Re: Secret contract tied NSA and security industry pioneer

#91
post #32

Earlier quoted context omitted.

Personally, I think one of the things you can't trust these days are comments by tptacek.

I disagree with many of tptacek's opinions but honestly he's one of the reasons this site is great. He is capable of arguing with people with strongly opposing views with civility, which is something that is entirely too rare these days. He's also capable of admitting when he's wrong and being gracious when proven right. Also entirely too rare these days. I'd rather have a thousand tptaceks on this site than zero.

https://news.ycombinator.com/item?id=6944628

> Jesus, what a tool you are.

How very civil and gracious.

Re: Secret contract tied NSA and security industry pioneer

#92
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

After reading tptacek's comments in the latest thread about Telegram https://news.ycombinator.com/item?id=6940665 I can only agree. He insisted Telegram team should abandon its custom solution without providing any actual proof that it's vulnerable. His advice was to rely only on "modern" algorithms (mostly the ones included in "NSA Suite B Cryptography"), but he provided zero evidence why these algorithms should be more secure than the ones already in use.

Re: Secret contract tied NSA and security industry pioneer

#93
post #32
post #21

>> https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-…

Personally, I think one of the things you can't trust these days are comments by tptacek.

[deleted]

Re: Secret contract tied NSA and security industry pioneer

#94
post #52

Earlier quoted context omitted.

Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.

Those aren't the only options. Anyone with any smarts can figure out how to quietly and anonymously leak a lot of these details. The fact is that they were too cowardly to do even that though.

As somebody who has been in IT for almost two decades, I can't think of a safe way to get a file off our corporate LAN without leaving a trail leading to me.

I realize it's an argument from ignorance fallacy, and maybe there are such ways, but I'm not aware of them.

Re: Secret contract tied NSA and security industry pioneer

#95

Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366

The beauty of this backdoor, for all its faults, is that it was reasonable to believe that it wasn't a backdoor. And it was also reasonable to believe that it was. This backdoor is quite deniable, elegantly so.

So far I have disagreed with tptacek when it comes to what's backdoored and not. But I can understand his reasoning, and it's quite sensible.

Re: Secret contract tied NSA and security industry pioneer

#96
post #79

Eagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366

[deleted]

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN.

Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is more of a "yeah, you got me" . Instead it sounds like I'm accidentally trolling you.

For what it's worth, I did legitimately get excited to run to HN to play "told you so". After months of debate over this issue across numerous threads, I'm not going to lie, vindication is momentarily exciting.

> For what it's worth, my take on Dual EC (before learning more about it) was the same as noted NSA apologist Bruce Schneier.

Wait, tptacek is calling Bruce Schneier an NSA apologist?

Aside from being absurd, your claim that you shared the same opinion is also false. Your own comment here directly contradicts this, and you even dismiss Schneier's credentials upthread, yet appeal to his authority in your comment:

https://news.ycombinator.com/item?id=6424920

"I am aware that Schneier believes Dual_EC to be backdoored. I'm aware that Dual_EC comes from NSA. I would not use Dual_EC and would flag it if I saw it in an app I assessed. But I would still, right now, with the information I have, bet against it being an NSA backdoor. Not because I trust the NSA, but because it's a very dumb backdoor."

Edit: In reply to a now deleted comment by tptacek.

Re: Secret contract tied NSA and security industry pioneer

#98
post #52

Earlier quoted context omitted.

Think of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.

Those aren't the only options. Anyone with any smarts can figure out how to quietly and anonymously leak a lot of these details. The fact is that they were too cowardly to do even that though.

These aren't the details that need to be 'leaked' anonymously - the whole point for the original suggestion to work as intended requires a public claim from aranking officer of that company; the actual info isn't important but the public testimony is.

Re: Secret contract tied NSA and security industry pioneer

#99

NSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Comma…

Minor quibble (and yes I'm as outraged by this as you are) - but "rouge" means "a red powder or cream used as a cosmetic for coloring the cheeks or lips", whereas "rogue" means "a person or thing that behaves in an aberrant, faulty, or unpredictable way", which is what you mean in this comment.

Re: Secret contract tied NSA and security industry pioneer

#100
post #79

Earlier quoted context omitted.

[deleted]

> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is mor…

Your series of comments in this thread is way below the threshold for positive contributions to any HN discussion.
Post reply on HN