tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard.
Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive-aggresively insult our knowledge of the situation. I look forward to reading what he has to say.
>Thanks for the link. I would have just gone on confirming my own biases without it.
This is incredibly evident in your comments on Dual_EC and sometimes happens on other comments as well. You draw a line in the sand and argue around it constantly, eventually bleeding into passive-aggressive attacks on the knowledge of others.
I find it valuable to hear from others outside of my industry (which is not crypto) who have no expertise in that field. They often have a fresh and agnostic look at something. Do you think all these comments slinging mud at you - however inaccurate they may be - were born from nothing?
I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it.
Thanks for proving my point.
I'm very interested in that actually. I'm often curious what shapes people's perspectives on these issues, particularly if it doesn't align with any obvious incentives. I always thought that you must have family in law enforcement or something, but I'd love to know the actual reason.
* I'm professionally involved in computer security, like you, and have an an amateur interest in the law (I'm considering law school at some point).
* Message board nerds have a lot of weird, wrong beliefs about computer security and the law.
There is a political difference between me and HN: I'm not an anarcho-capitalist (that silly "world's smallest political test" thingy puts me dead center in "left liberal"). But politics have little to do with where I end up on the NSA threads; it's things like not understanding (or really, having even skimmed) NIST crypto standards, or not taking the time to understand what the 4th Amendment means. The things that get me into "trouble" here have more to do with taking the time to actually read primary sources than anything else.
We probably disagree about NSA a lot less than you think we do.
I hate it when people do that. If you have a position on something, don't leave us all guessing, just state it!
He was right. Nobody in their right mind does use Dual_EC_DRBG.
From this episode I conclude that RSA Security LLC was not in their right mind.
Edit: Actually, I take that back. I have no problem believing that RSA Security are perfectly sane. Would we be completely shocked if the reason they chose a questionable default was due to coercion from the spooks? Only NSA has the keys, so it's a pretty safe backdoor.
You know, props to China, had to go through the work of owning RSA's seed server last year just to level the playing field. They get so derided in the media for doing that, but it seems unfair when the other team has a backdoor. Who is the real "Advanced Persistent Threat"?
The problems with it were known days after the standard was published.. meaning anyone who implemented was well aware of its problems.
Edit: actually, the first attack was in march 06 -- 3 months before the standard was published: http://www.math.ntnu.no/~kristiag/drafts/dual-ec-drbg-commen...
I should have said calling into question the insanity, will edit.
Looks like that still stands according to the article we're supposed to be discussing here:
".. no sensible cryptographer would go near the thing"
But I also expressed the view that no one would have used this. I guess it makes a lot more sense now: It seemed weird to put it in the standard, as no one was going to just use it. I'd been guessing that they hoped that it would be made an option and then they could do some negotiation attack to force it. I was missing a more obvious explanation: Someone was already willing to ship it, but they wanted the plausible denyability of it being a standard, because it looked too suspect otherwise.
[1] http://www.pcworld.idg.com.au/article/129305/rsa_security_so...
[2] http://satchitssecurity.typepad.com/a_page_from_satchits_sec...
Thanks for the link. I would have just gone on confirming my own biases without it.