[0] https://twitter.com/FiloSottile/status/1555669786826244096
[0] https://twitter.com/FiloSottile/status/1555669786826244096
Some may argue that DJB has personal or social failings but he has never been caught compromising a crypto system. Any individual who did wouldn't not by credible anymore in the community, a government agency however is constantly welcomed back to the table.
> Accusing scientists of taking bribes or (previously) plagiarism is wildly unprofessional.
This statement is either naive or purposefully misdirecting the audience. Anyone working in security knows that insider compromise includes a lot more than just monetary bribes - even a paragon of ethics has friends, family and their own personal safety they care about.
Again, the FOIA is good, the framing and FUD is harmful and part of a pattern that might be hard to see outside the community.
The selection process wasn't as open and transparent as one would like given the importance of cryptographic standards. I think we agree there, as you also think that the FOIA is good - which means that there needs to be more transparency. It took 6 years until there was proof that Dual_EC_DRBG really has a backdoor, which has been suspected since the beginning. Shouldn't we be extra cautious this time? If there was some backdoor again, it might take years before it is discovered.
> Again, the FOIA is good, the framing and FUD is harmful and part of a pattern that might be hard to see outside the community.
Could you explain which pattern you see there for us outside of the community? So far I don't see harmful FUD or a framing that is baseless, I see concerns that I feel are valid because of lacking transparency and the NSA's history of interfering with NIST's standardization processes. Why do you think that these concerns are harmful?