Schneier's take on the alleged backdoor in OpenBSD
schneier.com
schneier.com
Have there been proven (or at least credibly shown probable) to be NSA backdoors into shipping products?
Do you really think that was an isolated one-time event?
Same with the new proposed legislation. But all that demonstrates is that the NSA has an interest in being able to (legally) monitor encrypted communications. Which everyone already knows.
If someone had 'busted' the NSA trying to do something sneaky and/or covert and/or illegal, then you could argue that it's the tip of some iceberg of nefarious activity. But like I said this was all done out in the open.
You might as well say that because we know the FBI wiretaps phones through legally obtained court orders, that's the tip of the iceberg that points to millions of illegal wiretaps. It's a bad inference.
On this point I'm inclined to agree with Schneier: why inject backdoors into things, leaving fingerprints and betraying both opsec and tradecraft, when you can just sit back and watch the software companies build the backdoors for you? NSA has as much as come out and said this at keynote speeches already, but it seems pretty obvious from my vantage point.
[...]
Some of the suspicions about hidden weaknesses in the S-boxes were allayed in 1990, with the independent discovery and open publication by Eli Biham and Adi Shamir of differential cryptanalysis, a general method for breaking block ciphers. The S-boxes of DES were much more resistant to the attack than if they had been chosen at random, strongly suggesting that IBM knew about the technique back in the 1970s.
I'm done bickering about trivia, though. If you'd like the last word, as long as you don't say anything overtly stupid, I'm not going to respond. Happy holidays!
(I can't wait for this)
http://scholar.google.com/scholar?q=Serge+Vaudenay&hl=en...
http://scholar.google.com/scholar?q=hans+dobberton&hl=en...
But he just retired from blogging about netsec and is done with the industry, I think (a lot of ppl get sick of it, I left the sec industry 10+ years ago and never looked back)
He is, as I am fond of saying lately, "many good things", but.
Also: while we use fuzzers to probe for specific kinds of crypto flaws, the kind of fuzzing being done then (and for the most part today) does not identify crypto flaws.
We are, let's be clear, talking about a project that appears to have managed to ship IPSEC code that didn't verify packet authenticators for something like a year.
After all, he doesn't really profit from a free audit, and all the auditing I've seen so far has been done by the OpenBSD team itself.
Has there ever been a criminal case prosecuted in the USA where the FBI entered or revealed intercepted VPN data as evidence?
Point still applies though. No cases where prosecution has cited intercepted VPN traffic.