Ask HN: Questions about subversive programmers, NSA inside Mozilla?
http://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_york_times_uses_webrtc_to_gather/
https://webrtchacks.com/dear-ny-times/
In that thread, I noticed something very interesting, that apparently one of the same guys involved in the NSA backed Pentagon paper touting Extended Random on top of Dual Elliptic Curve, Eric Rescorla, is now working at Mozilla, and has some say in keeping the WebRTC setup in Mozilla working like it is.
https://bugzilla.mozilla.org/show_bug.cgi?id=959893
http://www.reuters.com/article/2014/03/31/uk-usa-security-nsa-rsa-idUKBREA2U0U620140331
So far any attempts to get a comment out of Mozilla about hiring someone who was known to participate in weakening crypto has been met with silence as far as I can tell.
The question that this brings up in my mind is what should companies and communities built around those companies do with programmers who have been involved in such subversions? It's entirely possible Eric Rescorla was unaware of the purposeful weakening proposed in the 2008 paper, and that it was the NSA contributor who performed this function, but the fact that Mozilla declines to comment on the matter and that this is a person who has quite a bit of say over a very commonly used browser raises concern.
As leaks like Snowdens become more and more prevalent, how should programmers who have been known to be potentially hostile to user privacy or other user concerns be treated, both by the community and by the companies that employ them?