32 karma · joined June 20, 2010
[ my public key: https://keybase.io/flyryan; my proof: https://keybase.io/flyryan/sigs/fwvJ5PmXoNblZiWTRaTD1YHpJA53OCcIiTPY65KPmm8 ]
The real way to fix security issues isn't to find new exploits and expose them. It's to architect new ways to prevent whole families of exploits from being possible. I've only really seen Project Zero do one sort of recommendation in this way. Outside of that, I don't feel that them finding 0days and releasing them is actually a significant improvement on security because they aren't even close to plugging all of the holes (or even enough to really make a difference).
[1] https://www.blackhat.com/docs/us-15/materials/us-15-Wardle-W... [PDF Warning]
There is a difference between releasing data that is strictly related to the public interest and taking massive amounts of data, including information about very sensitive operations and diplomatic discussions and releasing them without regards to the damage they may cause. It's reckless.
When someone says "the NSA couldn't even stop the Boston Marathon bombing", they are implying that the NSA SHOULD have been able to. But for the NSA to be able to stop it, they would have to be collecting data on US citizens inside the USA.
You can't have it both ways. You can't blast the NSA for not being able to stop Boston but then also be against them doing domestic collection. The fact that they couldn't stop Boston shows that they weren't spying on Americans (even though one was on watchlists).
there has been an attack -see! the NSA can't even prevent single incident X and are doing NOTHING to protect us!
there hasn't been a large scale terrorist attack in north america in 13 1/2 years -there is no evidence that NSA is doing anything to protect America!
[1] https://www.schneier.com/blog/archives/2013/12/more_about_th...
The point the original commentor was trying to make is that this type of work is much more preferable to the mass collection that you're referring to from the Snowden documents.
The FBI (who is responsible for all intelligence conducted in the USA, against foreigners or Americans) is absolutely required to get a search warrant.
The iPhone is one of the most popular phones in the world. Is it that crazy that the CIA is interested in them for intelligence gathering purposes?
That's a big IF and one that will be almost impossible to prove. I don't see how the case holds any merit if they can't prove this happens.
I found this note interesting. How big is the secret value used to compute the Q constant? Is it a single static value or does it vary? Would it be possible to brute force this? I'm not a crypto expert and want to understand this a bit better.
One of the big arguments about the NSA introducing weaknesses into these algorithms is "this makes them insecure for everyone and flaws exploited by the government could be exploited by anyone", but this makes it sound like ONLY the NSA could exploit this.
I'm not saying this is better. I just think, if true, it's an interesting discussion point in the debate.
[Cross-posted and answered at /r/netsec]: http://www.reddit.com/r/netsec/comments/1u5jvw/dual_ec_drbg_...