Secret contract tied NSA and security industry pioneer
reuters.com
reuters.com
Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million.
NSA points to RSA as an early adopter and gets NIST to certify it.
Millions of systems are now protected by an RSA product that the NSA deliberately weakened.
Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products -
NSA (Cyber security Command) gets even more money to "Protect" us from said Rogue actors.
So all-in-all good investment on their part
Edit: Spelling fixed per commenter pointing out the difference between rouge and rogue. I did imply malicious actors not red-cheeked actors (not that they are mutually exclusive).
Tshuß!
I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.
It is "I hate being the guy that hates those who hate being that guy" :-)
However, lest anyone think I think I'm perfect, I'll point out that I omitted the period after "etc".
guy -> guy,
using 'but' twice in the sentence
etc -> etc. (noted by author)
in general, the phrasing of the second sentence is questionable. perhaps it should be two sentences with a period after "I'm lying"
In many instances, "ß" has been replaced by "ss", namely where the resulting sound ought to be sharp and short. Schuss, Tschüss, Nuss.
Not quite - finding the actual magic number that enables the backdoor would involve solving the discrete log problem for the suspicious constant in the spec. A more likely scenario is some disgruntled employee steals the number and sells it to the highest bidder.
The NSA doesn't "protect" anyone. They are an intelligence agency. Their mandate is to collect information. The group you're thinking of, the one that's actually supposed to "protect" the network, is US Cyber Command: http://en.wikipedia.org/wiki/United_States_Cyber_Command
It is also why my generation (I'm 27) will eventually have to fight a nuclear war that pits Iran against Israel and possibly the US.
That war will potentially kill millions. And whose fault will it be? Obama's and Bush's. They will (if history is just and we don't change course) go down in history as potentially making mistakes that killed millions, just as Stalin and Hitler did.
Or we could insist now (or, ideally, a few years ago) that Iran not develop nuclear weapons capability, if necessary fighting a minor tactical war to stop them.
(There is NO reason to have Vietnam IV, where Afghanistan and Iraq are Vietnam II and III. Except of course socialism for defense contractors and altruism as we throw away trillions "re-building" the latter two countries.)
You should have hedged with "can be" instead of "is." Fighting preemtive wars can be disastrous too.
> my generation (I'm 27) will eventually have to fight a nuclear war that pits Iran against Israel and possibly the US
Do you seriously believe that? Sure, Iran will get to throw their weight around a bit more with nuclear power, but they're not that desperate or stupid.
> Obama and Bush ... will go down in history ... just as Stalin and Hitler did
No.
> a minor tactical war [would] stop [Iran from developing nuclear weapons]
Maybe. You complain about "throwing away trillions" fighting silly wars and re-building countries. You do realize that the exact same sell (fight a minor war, stop the terrorists!) was used for the last two multi-trillion-dollar debacles, right?
Either we give them a bloody nose and they just try again (keeping their cards closer to their chest this time) or we spend trillions trying to install another puppet government.
Iran has lost the war vs Iraq a some years ago. As a European, I don't see Iran as a threat. But you probably do...
My personal view is that the USA was interested in the oil sitting there. End of story. Same thing with Ghadafi. The rest is politics to justify a war that doesn't make any sense.
Indeed the Iraq war was Blair's political destruction in the UK. Why do you think no one wants to attack Syria? Out of lack of evidence ? At that level you don't need evidence, you create them...
>>> Why do you think no one wants to attack Syria?
Because attack presumes you need to achieve something. There's nothing in Syria that can be achieved right now that would be a desirable target. Assad is evil, islamic fundamentalists that battle him are evil too, US has no power and no political will to reform Syria and make anything good out of that mess. Neither does anybody else. That's why Assad is not being removed - because after removing him nobody knows how to clean up the mess.
World War 2 started when Germany decided to invade Poland in late 1939. Germany was never given Poland.
You get even the most basic history wrong and then proceed to say that Bush and Obama are historically equivalent to Stalin and Hitler?
Never let facts get in the way of a good dogma.
Germany and the Soviet Union. Sure, the Soviets attacked after the Germans, but they split Poland between them before the invasion.
PS You forgot Clinton bombing pharmaceutical plants in Sudan, then taking his eye off the ball to play his sax, schmooze with Hollywood and chase skirts, while the wheels of 9/11 were set inexorably in motion.
No, we won't. There is simply no geopolitical logic to Iran and Israel going to war.
There's even logic to its foreign relations, underneath the ideological veneer. Imagine if someone thought US policy actually worked literally as presidential speeches suggest; you'd think they're an ignorant tool. "Everyone knows that speeches are just speeches," you'd say, with no connection to the actual practice of governance. It may surprise you to learn that it's like that in any state, including Iran.
Disclaimer: US citizen living in Armenia, NW of Iran. None of the very numerous Iranians here leave one with the impression that they are from a place with "no logic". Turn off Fox News.
I don't agree with this at all. For instance, Obama has done what he promised: More big government programs and spending, nationalized healthcare. People knew what they were getting with Obama when he ran for President. There are a lot of problems with America but I can't stand it when people attack it for reasons that it actually doesn't deserve.
> None of the very numerous Iranians here leave one with the impression that they are from a place with "no logic".
I was referring to the government, which was pretty explicit. Fundamentally, there is a tradeoff between religiosity and logic in any religious government. The two are opposites. We cannot assume that Iran will never instigate a war for religious reasons, or that no rogue element of its government will ever share its weapons with outside religious groups.
> Turn off Fox News.
We can discuss the issues, but you cannot dismiss me by trying to claim I'm ignorant. I actually don't even watch Fox News, but I disagree with maligning Americans who do.
I can point you to a litany of campaign and post-inaugural promises that are widely perceived to be broken by a large cross-section of people, from closing Guantánamo to definitively and swiftly ending American involvement in Afghanistan and Iraq.
2. "We cannot assume that Iran will never instigate a war for religious reasons, or that no rogue element of its government will ever share its weapons with outside religious groups."
So, factionalism exists within the Iranian state? And what is the American state, a univocal monolith? For an overplayed but relevant example, I give you Iran Contra, or, for that matter, the runaway intelligence apparatus that Snowden helped put into sharper relief.
The point being that there are semi-autonomous appendages to any non-trivially-sized state. It should come as no surprise to anyone that there are extremist elements within Iran. Indeed, I would be willing to grant you that the extremist elements are more prominently positioned and influential within Iran's state. That's a far cry from "there is no logic to Iran". What does that even mean?
http://www.nytimes.com/roomfordebate/2012/06/04/do-cyberatta...
As for the article, it claims that Stuxnet "opened the Pandora box", but it did nothing of the sort. Stuxnet by itself did not enable anything that wasn't possible before - it was possible for malicious actors to create attacks on US networked infrastructure, and it still is. Stuxnet changed nothing there. Criminals and security professionals know the possibilities for a long time. And are using them. Making it sound as if the evil US has again spoiled the paradise for everyone makes no sense, and the author, being the expert in the field, should have known better, but looks like his political views overcame his professional judgement here.
(A ground war between Israel and Iran is a practical impossibility, by the way - neither country has the strategic reach for that).
According to their experts, a nuclear Iran is a good idea.
http://en.wikipedia.org/wiki/File:Shah_of_Iran_building_two_...
Besides that, that Iran doesn't exist anymore.
It will run out, though. The only questions are when, and what the contingencies will be once it does.
>>> basing threat levels on previous actions?
That would be stupid because it means that only the second action can be countered. Given how first action can cause devastating consequences, limiting oneself to only reacting to a second one would be terminally stupid. American administration, for example, was justly criticized for sleeping through 9/11, and acting unprepared when it happened. Generals like to prepare for the past wars, it is much easier, but there's no reason to condone such behavior.
>>> who invades countries most often?
Invasions can differ. If Nazi Germany invaded Poland once, and Britain invaded Nazi Germany once, they are not equal.
>>> who's military kills the most people?
Again, depends on the people. If Al-Qaida kills 3000 Americans in 9/11, and then Americans kill 10000 Al-Qaida fighters after that, I'd say good job, they only should have done it earlier, so we would have 3000 less victims.
>>> That saga ended with almost everyone looking bad.
It looks bad to you because you take an impossible position that fighting evil should be done without hurting anyone. It would be nice if there was a nice, fluffy, unicorn-land evil that you could fight by issuing a strongly-worded declaration of condemnation and maybe refuse to send them a Christmas card next time. Unfortunately, real evil is much harder and messier to fight.
I know. People that thought if USA sees no evil, hears no evil and refuses to speak about evil then all troubles would happen to somebody else existed since there was such thing as USA. They were wrong then and are still as wrong now.
>>> The question that never seems to be asked, is why did September 11 happen
You must be kidding me. One has to be unusually dense or unwilling to hear to ignore the deafening choir of non-interventionists and generic America-is-root-of-all-evil crowd blaming America for what happened at 9/11. Of course, it only tells us about them, not about why this heinous atrocity has really happened. The solution there is simple - these terrorists saw America as their enemy, and given the opportunity to deal a heavy blow to the enemy - opportunity enabled in some measure by complacency of the American administration, who for a long time thought terror is something that happens in bad places like Middle East but can't happen in America, despite many warnings to the contrary - given that opportunity, they struck their blow. One doesn't need any more complicated theory than that. As for why they chose America as their enemy - one doesn't need too much theory in that either, given that ideologists of Al-Qaeda explain it all by themselves. Their goals as religious fanatics dreaming of subjugating other people to their rule are incompatible with America's role as a world power strategically and with America's support of people unwilling to accept radical islamist rule tactically. Of course Al-Qaeda is the enemy of America - what else could they be, given that their premises are diametrically opposed to every premise this country is built on?
>>> Bombing and invading hasn't worked.
What you're calling "worked"? To make the strategy, you first have to define the goal. If the goal is "to ensure America is never the target of a terrorist attack", the solution is simple - America must cease to exist. If America exists, it can be target of a terrorist attack, and there's no known way to prevent it with 100% certainty. One, however, can make it harder to do, and for that there are many various plans, both good and bad.
So strictly speaking, the US is the bigger evil because it is doing all those things right now, and has the capability of destroying the world through nuclear holocaust.
> Again, depends on the people. If Al-Qaida kills 3000 Americans in 9/11, and then Americans kill 10000 Al-Qaida fighters after that, I'd say good job, they only should have done it earlier, so we would have 3000 less victims.
This line of reasoning. This here. That is evil.
"Depends on the people", oh my god.
By the way the US has already killed far more than 10,000 in response to the WTC attacks. And not just "fighters" either.
And if you still somehow can say this was warranted--I have no (nice) words if you do--ask yourself why they hijacked those planes in the first place. It wasn't because "mwuahaha let's do something evil against those unfaithful white men dogs" (the hijackers themselves maybe were told something like this, a variation on your "it depends on the people"), but the actual cause was the US' meddling in the Middle East in earlier decades (during the Gulf Wars and before) that ended up killing their guys. Which made them decide that a mission like this was a completely reasonable response. Someone might have even claimed something ridiculous like "we should have done a 9/11-type attack much earlier, and save all those victims" (which makes about as much sense as your claim that killing 10,000 AQ fighters sooner would somehow have prevented 9/11).
They have about as much claim of being the "good guys" as the US. Which is, none whatsoever.
No, it is not.
>>> This line of reasoning. This here. That is evil.
But I if under "evil" you understand "defending yourself against attack" then I can understand why you call the US "evil". However, it is your private meaning of the world "evil", unknown to the rest of the world.
>>> "Depends on the people", oh my god.
Of course it does. One is justified to use violence in defense against attack. I'm surprised it needs to be explained.
>>> By the way the US has already killed far more than 10,000 in response to the WTC attacks.
The US killed people in war, it is true. That, unfortunately, the only way to fight wars. If you invent some way to win wars without killing anybody, be sure to tell, it would be most wonderful invention. Until you do that, that's the way we have. When attacked, there's only two ways to behave - submit to the attacker or fight back. I don't think submitting would be a good option.
>>> the actual cause was the US' meddling in the Middle East
Very funny word that "meddling". Like "I shot this guy because he was meddling with my robbery and was trying to stop me, so I'm completely in the right". Of course US is "meddling" - without that "meddling" real evil - you know, guys like Hitler, Hussein, Pol Pot, etc. - would feel much freer to perpetrate their evil deeds. "Meddling" is the only moral thing to do if you see people's rights violated and freedoms infringed.
>>> Which made them decide that a mission like this was a completely reasonable response.
The fact that it seemed reasonable to them means nothing. Everybody thinks their behavior is reasonable - murderers, robbers, rapists, thieves, serial killers - all of them think they're very reasonable people in unusual circumstances that make them do those things. There are very few people that say "I'm evil to do this, but I will still do it". Yet it is evil to do what they do, and your relativism and attempt to present it as if there's no right and wrong but only somebody's opinion can only lead to a moral bankruptcy.
> No, it is not.
??? Yes it is!
It's replaced countries leaders with ones more suitable to US interests. Thrown entire countries into a state of war. That's destabilizing.
I'm going to hope we can agree that throwing bombs on people is hurting them?
Finally, if providing terrorist organisations (AQ was an "ally" back then) with weaponry isn't "inciting violence", then I don't know what is. Also quite destabilizing to the region btw.
> Of course US is "meddling" - without that "meddling" real evil - you know, guys like Hitler, Hussein, Pol Pot, etc. - would feel much freer to perpetrate their evil deeds. "Meddling" is the only moral thing to do if you see people's rights violated and freedoms infringed.
I'm going to ask you to be a bit more skeptical than that. You do know that the US gov / military has routinely lied about their intents to the US people right? So you should at least give some consideration to the following:
Saving the poor people of the Middle East from those evil dictators was not the reason for getting involved at all.
Gaining political and military control over one of the largest deposits of fossil fuels, of course is.
Why do I believe this is the case? Because there's TONS of terrible evil being committed to poor people all over the world, many of these things would be quite the low hanging fruit to get involved with. But instead, the US picks this rich and relatively well-armed hornet's nest to get sucked in by. Oops.
Judging that in the category of "saving people from evil / having their rights violated and freedoms infringed", it's pretty much an abject failure. With those very same resources they could have saved so much more lives if they really cared for that, at the cost of so much less lives of American soldiers, if they even cared for THAT.
There are so many really real evil guys in the world, committing really really bad atrocities on the people they sit on top of, in countries you really never hear about because they're poor and far away and not really interesting (untrue, Tajikistan is super interesting).
Also it's super easy propaganda-wise to paint the cause for fighting in a far-away country as something heroic and moral, when it's really about oil, power and control. There's a few more motivating factors besides those, but none of them amount to "because we're the good guys".
Finally to address your point about relativism and moral bankruptcy. IF I could truly and honestly believe that the US primary goal in the Middle East is to save these people from evil dictators and provide them with freedom and human rights (c'mon! it can't even provide those to US citizens at home!), if I could believe that to be true, then I'd probably be mostly in agreement with you, really. Doing good is a good thing.
It's just that, from the outside, it seems pretty obvious that the US is not there with the intent to do good to the people, but to control the natural resources and sources of power.
Every time you seen people all "yay! the evil dictator is gone!" it turned out to be a photo-op, didn't you notice? Didn't you see the zoomed-out version of that well-directed scene where they toppled Saddam's statue? Tanks! Cameras! Action! Most non-actor people were instead wondering "when will the US stop occupying our country". The REAL celebrations you won't see, will happen when your soldiers finally leave (aka, never).
Then offense is just offence.
In actual life, the 800-pound gorilla is beating the shit out of monkeys, invades their villages, pushes them diplomatically, installs his lackey-monkeys in power in their jungles, and steals their resources.
And he counts any nick or scratch on his body (inflicted by the monkeys tiny hands) as worthy of the lives of 10,000 monkeys -- which he considers almost subhuman and even talks openly of "bombing them back to stone age".
Oh, and he maintains that he's the righteous and good one in all this, and it's doing it for their own good.
The best solution is to prevent the problems; I hope you understand while reading this article (which went here on HN some time ago):
http://news.yahoo.com/german-police-used-only-85-bullets-aga...
NSA did this to advance their mission, not to make a few extra bucks.
http://arstechnica.com/tech-policy/2013/12/white-house-nsa-a...
Conspiracy doesn't mean aliens and Disney being frozen.
It just means people/organisations doing something together in secret.
What the NSA and partners have done is very much a conspiracy -- by definition.
As the great writer Gore Vidal once put it, "Americans have been trained by media to go into Pavlovian giggles at the mention of 'conspiracy' because for an American to believe in a conspiracy he must also believe in flying saucers or, craziest of all, that more than one person was involved in the JFK murder."
Money is a powerful conditioning force, and humans miss the "obvious" things that are influencing them all the time.
http://lists.randombit.net/pipermail/cryptography/2013-Septe...
The particularly relevant portion is this:
"This was $10M wasted. While this vendor may have had a dominating position in the market place before certain patents expired, by the time DoD/NSA paid the $10M, few customers used that vendor's cryptographic libraries.
There is no reason to believe that the $250M per year that I have seen quoted as used to backdoor commercial cryptographic software is spent to any meaningful effect."
Interestingly the mailing list post doesn't seem to mention the use of RSA's adoption as a factor in the NIST standard, so it's possible that while their knowledge was more advanced than the public's they didn't know about that side-effect.
http://www.nytimes.com/2011/06/04/technology/04security.html...
Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke.
lawnchair_larry's comment is equivalent to questioning the president or a major celebrity, which oftentimes isn't a personal grudge.
That makes for a wonderful experience really. I interact with this nameless entity and each post is largely valued by its responses (I often leave an article open for a few hours to let the comments ripen a bit, that also adds a lot).
For the record, this is incorrect. In past interactions he has stated his concerns over certain of NSA's "misbehavior".
So far I have disagreed with tptacek when it comes to what's backdoored and not. But I can understand his reasoning, and it's quite sensible.
True, you just have to keep in mind that their customer is the NSA.
"RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts." [emphasis added]
Does this count?(not trying to be sarcastic or a smart-a##), I just want to get a handle on what I should or should not trust these days. Seeing that RSA SecurID VPN dongle pic in the article scared me. I've pretty much been looking to your comments to give me a baseline.
HN is incredibly fortunate to count members like 'tptacek as part of its community. We should be behaving in ways which encourage more comments and commenters of his ilk, not less.
If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments. Now, it appears that most of these users have become tired of being instantly downvoted, and instead avoid these subjects entirely.
I hope that tptacek continues to participate in these security policy discussions, not only for his extensive domain knowledge, but also because he is not afraid to voice beliefs that disagree with prevailing opinion. And right or wrong, its very refreshing.
Always mixed with a steady groan of "enough of NSA stories" and "none of this is surprising". The heated discussions were in no small part about wether this was even the problem it was made out to be and wether it should even be discussed (to this extent).
Not that I agree with downvoting instead of replying, or with bashing tptacek (Everybody loves telling experts "I told you so". Doesn't make us experts tho :P), but I don't agree with your narrative either. It's not falsifiable, anyway. People might just as well have given up on trying to downplay this, and walked away instead, which would be even worse. Why speculate. Bashing and downvoting for disagreement without argument sucks either way.
Don't really have a dog in this fight, but: up until today, there was no evidence "the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products".
Were people wrong to be suspicious?
There is a large area missed called psychological bias. People who has close friends working in highly controversial areas has a tendency to become a bit irrational in the view of the controversy. An attack on the NSA becomes an attack of the friend. If NSA is immoral and wrong, the friends choice of occupation must be wrong, thus the friend must be wrong, thus an attack on NSA is an attack of the friend.
He's rational to a fault--unfortunately, that means that when facts change he may be left with egg on his face. I don't think there's anything wrong with how he's handled this stuff.
And here, ladies and gents, is exactly why we'll continue to inhabit an exploitable world forevermore.
It's okay to provisionally trust the word of someone who has previously and clearly demonstrated actual competence.
That said, I seldom trust anything I cannot verify. In matter s of crypto, that often means that I accept some things as magically working, and accept that the magic could wear off at any minute. Same thing with CPUs. I know generally how they work, and understand bitwise logic, but for the most part, they're just magic boxes that I've got enough experience with to have an expectation of.
In matters of the government, the fault I find with tptacek's arguments (and I hadn't even realized that it was a thing until this thread, but now I'm caught up) is that I think it is naive to trust the government. The federal government is something that our founding fathers encouraged us to be suspicious of. They specifically prescribed that, in order for our democracy to thrive, that we should be ever vigilant in regards to those we entrust with power.
Assuming good faith on the part of the NSA is naive, whether or not they're acting scandalously. Assuming good faith on the part of any politician is naive.
That isn't to suggest that we should never trust anything the government does, but if there's ever the potential for abuse, we should expect that potential to be abused at some point. If there's a loophole that could be exploited in any way, we should expect that it will be.
This diatribe isn't really directed at this comment, per se, but at your "have to trust __something__" comment, which I completely agree with as a generality. As humans, we routinely put trust into a great deal of people and things all the time, but I disagree that a government, even a pristine, flawless, immaculate government, is deserving of that trust, and it is our duty as citizens to thoroughly distrust it.
> Jesus, what a tool you are.
How very civil and gracious.
You're clearly talking about a different tptacek, widely known on this site for his coarsely abrasive, impossibly high friction, social interactions and not admitting he's wrong on issues trivial or important. He's also widely known for a being an expert in his field.
All that being said, I agree with you that this site is more valuable with him on it and regularly participating. He's one of the actual experts in their field that makes this a much better forum than any other. IMHO, it's well worth the comment burn to talk and debate (friendly or not) with somebody of his caliber.
And being wrong every once in a while (regardless of his rightness in this case) does not make him either incompetent or malicious. It just makes him human.
What are you talking about? Whatever caricature you're illustrating here is not Thomas Ptacek.
With the way you've been talking, I would've suspected you were a newer member, but you've been around for three years or so. So I simply have no idea what you're talking about.
Would you please point out precisely which comments you take issue with? https://www.hnsearch.com/search#request/comments&q=by%3Atpta...
I think the thing to remember about Thomas, and me, and everyone else, is that we're all human, and we all have different moods which influence our behavior. Thomas's, on average, is exemplary.
I'm talking about the same tptacek who I've personally butted heads with where he couldn't even accept being wrong about how to make stew (looking back, that was exactly 1 year ago to the day!)
I respect tptacek very much for his domain knowledge and expertise. He has great theories on hiring practices and cooking among others. He's one of the names I look for on HN.
But he requires lots of care and effort. I have to mentally peel back about half of his posts to remove the snark and assholery and get to the juicy bits. But those bits are usually there and usually worth the effort to get to.
That's okay, I'm a grown up and can deal with high friction in order to enjoy interacting with somebody who's truly intelligent. tptacek is just one of those types that comes with lots of smarts and lots of difficult personality and that's okay.
And for the record I'm also aware that I can be rather high friction and assholish as well, and not nearly as insightful as tptacek.
I'm logically one of the last people to defend him here having butted heads with him so much, but in fact I deeply value his presence here.
> How would you feel if you saw someone talking like that about you?
I'd probably agree with them. I'm not a high-school kid afraid of how my peers will see me and neither is tptacek. I've said as much about his communication style to him directly.
I highly doubt that tptacek doesn't have enough self-awareness to know that he's a high maintenance debate partner. There's no reason to paint him as a saint, he's just a guy. A very smart guy, but he has his foibles and flaws, which are far outweighed by his contributions. But to ignore those more difficult parts of his personality does him a disservice by not seeing him in his entirety.
I respect the entire person (as much as I can see through the limited lens of HN) not just the parts I think are praiseworthy.
In cryptography, you either prove it is safe or you consider it broken. Your choice should be considered broken until you prove otherwise.
Edit: Oh, you're the Telegram employee who designed the contest. I encourage you to read moxie's blog post, and Schneiers rebuttals to crypto contests that are probably linked all over your other threads.
I don't think there's any attempt to sell snakeoil here, this is a case of a road to hell being paved with good intentions. To people not well versed in cryptography the things Pavel is saying and the approach Telegram is taking all seem completely reasonable, and the people who do do crypto and are responding might as well be talking a different language. To them the flaws and red flags are so obvious that their responses are incredulous, which has led to the vitriolic back and forth we've seen - neither side can comprehend the other's position. This is Dunning-Kruger[0].
[0] http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
Also note that it's not a case of one random crypto guy saying that Telegram's approach is flawed, but a case of virtually the entire crypto community saying that the approach is flawed. Does this not ring alarm bells for you? How can you judge that the Telegram guys know their stuff and aren't leading you down the garden path or are themselves deluded?
With your backing, there is a real chance for Telegram to bring secure communications to the masses. This is indisputably a noble goal, but the areas that Telegram should be innovating in are in UI and features - not cryptography. There is no such thing as mostly correct, 'good enough' cryptography, either the system is secure, or it's insecure - there is basically no middle ground. If you fail, it's a bit more serious than your typical software bug - innocent people can literally die - the very people that need this the most are the most at risk. These are the reasons Telegram have been met with such a frosty reception here. Because they come across as arrogant in an area where arrogance is the absolute least desirable trait.
What I was saying in the comment above, however, had nothing to do with the contest. I expressed concern about tptacek's aggressive promotion of one algorithms (branded as "modern") over the other (claimed as "anachronistic") without any substantial proof. https://news.ycombinator.com/item?id=6941934
This is really alarming.
https://vk.com/roem?w=wall-20537665_23327
Here's an unedited Google Translate translation (I read it, and I think it conveys the message):
As I see it , there is not so much Anonymus as creators local competitor - TextSecure under Android . Telegram gathered a lot of users , and they're rightly fuss . The boys are torn between argument " either too new algorithm , why is it , if there is a proven " and your " algorithm either too old , why is it when new ." Nevertheless , trade on HN gives thousands of registrations Anglo-Saxons and tons of references .
I think the debate will be a good end to the competition announcement decoding traffic Telegram. Let's say I was ready to open all of my correspondence traffic since registration in Telegram and give $ 200,000 to anyone who will decipher it and tell you how . As a result Telegram or detect and close the loophole for special services, or - more likely - will receive another proof of the inviolability of their protocol
Here's another comment of his further down:
Я помню первый обзор о ВКонтакте на Хабрахабре, кажется, в 2006 году. Эксперты делились комментариями вроде "кто они такие", "еще одна соцсеть не нужна" и "на php пишут только нубы". Неудивительно, что HackerNews, построенный примерно тех же принципах (карма, ранжирование), создает чувство deja vu.
Тем не менее, будет здорово, если там объявятся не только любители поговорить, но и те, кто реально прочитает документацию к MTProto.
Which roughly translates to:
I remember the first reviews of VK back in 2006. The experts were saying "who are they?", "we don't need another social network", "only noobs write in php". It is not surprising that HN is built on the exact same principles (karma, rankings), brings up a deja vu.
However, it would be great if someone who actually read the MTProto docs can show up, and not just those who like to talk.
That aside, your challenge smacks of snake oil. I gave an analogy earlier that captures the essence of the complaints:
Suppose I am selling fire-proof safes. These are designed to protect your documents and valuables from thieves and from fire and other events.
The normal way people set up tests is to put some documents and valuables in a box and actually try to break it (MythBusters style, bringing out cool machinery and trying different ways). For fire resistance, there is a rating system (https://en.wikipedia.org/wiki/Fire-resistance_rating) and a standard way to test.
The Telegram proposition is: we are going to place the safe in Fort Knox. If you can't break the safe that is in Fort Knox, then clearly our safe is secure.
People are arguing that in order to break the safe, you have to break into Fort Knox. And for all intents and purposes that's not going to happen. You could have put a cardboard box in Fort Knox but no one can tell the difference because of the way you structured the challenge.
In that sense, you aren't testing the real-life security.
Why do you think they put it there?
Thanks, Theo, for never selling us out; for being such an uncompromising bastard; for not being like the RSA. May Athena gird you for war against the Spartans.
Option A: keep mouth shut, make a shit ton of money
Option B: become a martyr, face prison time
People like Snowden are rare.
I realize it's an argument from ignorance fallacy, and maybe there are such ways, but I'm not aware of them.
In all honesty, Snowden is a 30 year old single dude, and as far as I know, he doesn't have kids. Do you think he would have done what he did if he had a family to look after?
In my opinion a person's first responsibility is to their family. So yeah, if you're married (like these executives probably are) and you're facing the choice between option A and option B, you should absolutely pick option A.
Good relationship with parents.
I'd say that is a lot to give up, in order to take the risk of being a whistleblower.
http://www.telegraph.co.uk/news/worldnews/northamerica/usa/1...
Snowden's actions were brave, regardless of his family status, and I don't wish to downplay that even one iota, but yes, if he had a wife and three kids, it likely would have made his actions even more of a longshot.
Maybe not having kids is actually the morally correct choice, then?
Classy.
>You would let your children go hungry and live a worse life
No. Read what I wrote. The words are right there.
If the choice is "have children and commit evil to feed them" and "don't have children and don't commit evil", I choose the former. As should, I think, any right-thinking person.
The question is probabilistic. What are the chances that the former happens? What are the chances that the latter happens?
Choose accordingly.
The question is also systemic. There exists the possibility that forces larger than the individual have decided to normalize the nuclear family (and also romanticize the vision of having said family) in order to serve evil ends. What is the probability that that is the case? As time goes on, it looks far more probable than we once thought. People like you think families are in themselves beautiful. Any means justify the ends of preserving them. Seems like an excellent tool for keeping a population right where you want them.
Look up the history of the nuclear family. Notice it didn't exist pre-industrialization. Why's that?
You're taking humans -> have children for granted. I'm arguing against that dogma. Because as paradoxical as it may sound, it is trite dogma at this point in wealthy societies. We don't need these additional people, we don't need this extravagant life. It's not a matter of survival anymore. So what is it all accomplishing? What's the end?
>Having a family can be a beautiful thing.
For my morality, concerns of beauty don't trump concerns of humanity. If my having children perpetuates a cycle of exploitation, murder, pain, suffering, etc. etc. etc, then I don't have children. Regardless of how "beautiful" my experience of those children may be. It really is that simple.
And if a (wo)man tells me "I just did it to feed my kids" after committing some reprehensible act, I sympathize, because (s)he made a terrible decision in having children to start with. But I still condemn him/her.
Look at what happened to Qwest CEO Joseph Nacchio after challenging illegal NSA warrantless wiretapping requests. (Hint: he just got out of federal prison about two months ago.)
http://online.wsj.com/news/articles/SB1000142405270230398390... Mr. Nacchio said he still believes his insider-trading prosecution was government retaliation for rebuffing requests in 2001 from the National Security Agency to access his customers' phone records. His plans to use that belief as a defense at trial never materialized; some of the evidence he wanted to use was deemed classified and barred from being introduced. To Mr. Nacchio, the revelations of former NSA contractor Edward Snowden, who leaked documents saying the agency monitors the email and phone records of Americans, have justified his own stance. He contended the NSA's request was illegal. "I feel vindicated," he said. "I never broke the law, and I never will."
Or maybe: How was his position any different than yours, if you had a request from the NSA that you wouldn't want to fulfil, knowing that rejecting it could destroy your company, what would you do?
NSA approached Nacchio and Qwest to do what they were doing with AT&T and Verizon. Qwest had previously helped the NSA intercept all comms in Salt Lake City during the Olympics but told the NSA they weren't interested in cooperating. Nacchio sells some stock. Qwest is suddenly dropped as the favored vendor for a huge government contract leading to a drop in Qwest's share price and earnings.
The US federal goverment's position was that Nacchio knew the contract was going to get dropped and cashed out early - insider trading. Nacchio contended that he was just selling stock and that the government had pulled the contract to entrap and prosecute him in the current case.
Despite being specifically prohibited from trading based on insider information, Nacchio first became aware that their earnings guidance was "a huge stretch", that to meet them would involve growing revenue from a line of business that had been failing to grow revenue and that had actually been underperforming that year, that they had (apparently) lost important contracts, and that it had become essentially impossible for them to hit their numbers. Then, after learning all that, but before any of it was disclosed to investors, Nacchio dumped over $100MM worth of his stock.
Nacchio controlled the earnings targets for Qwest. He set them dishonestly high and allowed them to be released to the public over the objections of many of his own executives. The stock performed as a result. Then, when it became obvious that the public would soon learn that those projections were impossible to meet, he sold his stock for $100MM.
Nacchio went down within a year of Enron and just a few years after Worldcom. It was the end of an era in which the big accounting firms had conspired with large corporations to swindle the public out of billions of dollars. Nacchio was a crook, not a Fourth Amendment hero.
Are the executives at JPMC crooks? I don't know. If they are, which is not outside the realm of possibility, they should go down too. But what JPMC people do has nothing at all to do with the fact that Qwest's executives defrauded the public to the tune of over $100MM.
Yes. (Edited for reasons)
So perhaps this guy is indeed a slimeball.
Fabricated up claims are by their nature nearly indistinguishable from real ones, and outright fabrication isn't the only unethical recourse: there is always panopticon powered selective prosecution— how many felonies have you committed this month?
Regardless, we can observe now that the result will be time in prison and tptacek on HN diligently countering any claim of governmental misconduct. The insight here isn't related to Nacchio's character, it's that claiming that the government is retaliating for failing to comply with their unlawful demands doesn't provide protection.
RSA, much like NIST, can not, and should not be trusted any longer. All of their customers should be warned, and advised to quit them ASAP. Companies need to learn this is just unacceptable.
There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better than authing with just a password or client cert.
They don't have a timer like the RSA key fobs, and need a USB or NFC connection - but are generally very reliable, and given their constraints.
The questiion, of course, is what reason you have to believe that yubico (and for that matter, gemalto, g10code and the rest) are not similarly in bed with the NSA.
Speaking of "trust", Bloomberg lost quite a lot of it when their reporters spied on their customers.
Bloomberg Spying Went On For Years After Execs Knew: Report http://www.valuewalk.com/2013/08/bloomberg-spying-went-on-fo...
You were probably just as horrified as most of the other employees at Bloomberg when that info became public. The bad apples cost Bloomberg a lot of reputation. My point is that "trust" is very elusive, very easy to lose, very hard to gain.
OTOH, are the "bad apples" at Bloomberg who condoned that behavior still in positions of power? Did they even get a slap on the wrist? If I were at Goldman, JPM, Citi, etc. I wouldn't "trust" Bloomberg until I saw some higher up people fall on their sword for that fiasco.
* My preference anyway to RSA.
They sell Gemalto IDProve 100 tokens and support Yubikey, but advise using their patent pending push based 2FA authentication because: "Login requests are signed with an asymmetric PKCS#1 v1.5 key pair, which provides a stronger identity assertion than passcodes and prevents “RSA-style” breaches." From https://www.duosecurity.com/duo-push
They're used by companies like Facebook, Twitter, Sony, Arbor Networks, MIT, etc.
So yes, RSA has some strong competition.
At least that's the message that comes through loud and clear in the rest of the world.
Companies that have been compromised[1] - MS, Apple, Facebook, Google, Yahoo, Carriers, Backbone providers - now they are going after security providers. From the big guys only Intel is standing. And that may as well be the next leak.
Also think if they subverted some of the big guys antiviral software - it runs at ring 0 usually.
[1] Blackmail, threats, bribes, lawful intercepts, warrants, NSLs
Perhaps, but the poster to which I replied said any US company, period. Could be he meant what you meant, but that's not what he said.
It's just as if an antivirus company to accept a contract with a major adware distributor to keep their products marked as appropriate - legal, but best kept secret.
Terrorists don't use VPN dongles.
What is really going on here?
"Follow the money" is a slippery slope.
The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access to as much communication between non-US entities as humanly possible. What makes their job difficult is that, over the course of the last few decades, it's become increasingly the case that much of the communication between non-US entities travels via US-based channels using technology originated in the US. Somewhere along the line, when forced to balance "as much communication" and "non-US entities", the NSA clearly chose in favor of accessing those communications at any cost.
The core cause there would seem to be sharing comm channels with foriegn actors--the same thing that makes our position with regards to the 'net so awesome also means that the NSA is kind of forced to get involved closer to home. It's a tricky tradeoff.
[1] http://www.theguardian.com/uk-news/2013/dec/20/gchq-targeted...
The story isn't about VPN dongles, it's about a backdoor in an encryption product sold by RSA.
Even if you're right, Airbus does.
One of the security guys who worked for General Magic (GM made an early mobile OS with some security features) told me that he had a visit from the NSA. The NSA tried to get him to leak bits of the keys in the GM protocols. "Just here and there. I've got dozens of these," said one of the NSA reps.
This would have been early 90s.
The NSA has been doing domestic stuff like this for a long time.
More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.
You mean DRBG [1], right? I hope DRBD [2] isn't backdoored.
[1] http://en.wikipedia.org/wiki/Dual_EC_DRBG [2] http://en.wikipedia.org/wiki/Distributed_Replicated_Block_De...
This news on the other hand makes it clear that RSA was not only being incompetent. They were being actively malicious. We've already seen anecdotes in this thread about NSA making house calls to security product vendors as far back as the 90's, so we must assume they haven't given up that venue and are still pushing their ideas, as well as pushing the vendors.
With that proof comes something a lot bigger: every single security product from a US company is now suspect. By logical extension, I will say that similar paranoia should be applied to all security products from Five Eyes countries.
The long-term financial fallout should be interesting material for future chroniclers.
Also, closed-source hardware HSMs are blackboxes that are fundamentally paranoia-inducing. There's no reason to trust that the vendor, supply chain and/or manufacturers didn't backdoor them or introduce other attack surfaces. The only way to trust an implementation is decap a sample of ASICs and match features against masks you generated... from sources you trust (whether open source or yours).
If it's a black box, there's no way to trust it (all modern CPUs, N/S-bridge, memory, flash (ssd), hd controllers, on and on.)
Conclusion: We need more open-source hardware that is production-quality (BSD licensed)! This would be very expensive in terms of people time, but it's necessary move since corporations can't be trusted.
a nsa official just did an obvious trial-balloon of pardoning snowden in exchange for return of all the docs [1]
but now that snowden is in russia, you have to assume that many nation-states have seen all these docs. so really, the nsa is worried that you and I will see them
fucking amazing
[1] http://www.theguardian.com/world/2013/dec/15/nsa-edward-snow...
That said it's likely individual consumers who are likely to have this attitude rather than businesses.
anyway, i wonder what happens now to all the customers that use rsa dongles? big, international, political organisations...
Dual_EC_DRBG was a NIST standard.
"RSA adopted the algorithm even before NIST approved it. The NSA then cited the early use of Dual Elliptic Curve inside the government to argue successfully for NIST approval, according to an official familiar with the proceedings."
Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.
In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. (E.g. an independent researcher can actually gain access to and participate in a large and reasonably priced health insurance risk pool. And where money is not the overriding, if not sole, determination of judicial proceedings.)
Going very general in my comment, security is both a community effort and a personal responsibility. The more we "outsource" our own security ("Just trust us." -- Three Letter Agencies and private contractors), the more the price goes up while the quality of the results goes down.
You get the government you pay for, or... if you are more concerned about a quality, effective government, the government you participate in.
Hopefully, the pendulum is beginning to swing back from "pay for" to "participate in".
Is financial instability really a problem for most people qualified for this type of work? I imagine most of these people are approaching or well within the 6 figure range and that accepting some sort of bribe would just be icing on top.
EMC bought every single major corporate partner technology in 2009/2010. EMC is the private honeypot for the entire program. The corporate store is EMC and only EMC. EMC and EMC ventures can go to hell for building this, knowing about it, and continually profiting from it. Profit from investment in a partner of an illegal government program specifically designed to make illegal money from human rights violations should be considered illegal. All of the major money behind EMC knew what was going on. If you did a private benefit analysis, it would be all EMC. Thank you. =)
http://www.reuters.com/article/2013/12/21/us-usa-security-rs...
https://twitter.com/mikko/status/414147944984485889
"I'm ashamed on behalf of the whole industry."
I'm looking at how to incorporate this as an example in my talk.
This means one of two things: Either this is a blatant lie by RSA, or RSA is not competent enough to evaluate cryptograpic algorithms. Neither possibility paints them in a favorable light.
"Does." Present tense. Doesn't say anything about what happened in the past. Maybe their contract even included NSA services to launder language to be plausibly deniable, since that has also emerged as one of the NSA's core competencies.
I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company?
Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?
Well, "nothing" isn't strictly correct, but connecting them is more like the Kevin Bacon game. Rest assured that this story has nothing whatsoever to do with RSA keys.
I hope bsafe licensees sue. Any one know of any serious efforts to replace some of the standard cipher suites in common code? AES -> Serpent, SHA -> Whirlpool etc...
Crypto is something where reputation is sine qua non. After the 2011 data breech they lost a lot of it. Now how can anyone trust them ever again?
Paid shill
Want to see money flow from federal government to RSA and EMC over time.
This shit must be punished.