5 ms·
Doesn't this essay absolutely bury one of the most important parts of this scandal, that RSA used DUAL_EC as the default random number generator in their FIPS c
by jgon 11y ago
Doesn't this essay absolutely bury one of the most important parts of this scandal, that RSA used DUAL_EC as the default random number generator in their FIPS certified encryption product for almost a decade!?! I note that this is glossed over with a description so marginal I would tempted to call it dishonest if I were not trying to apply the principle of charity to its author. "RSA BSAFE had support for DUAL_EC." Support!? Uh no, it used it as the default generator.
"I lean towards “not”; the structure of these proposals makes Clyde Frog’s job needlessly harder, if only by practically ensuring that OpenSSL and Schannel would never default to enabling them. But people smarter than me are convicted of the idea that this was a backdoor attempt." Well yeah it would make their job harder unless one of the largest security companies in the world used that random generator in their flagship encryption product!!!
I feel like maybe their are better arguments for why this was not a subversion attempt, but honestly the points for seem so, so strong and the points against seem like a mountain of wishy-washy humming and hawwing and extending the principle of charity even in the face of the above mentioned giant blaring klaxon of wrong-doing. I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like.
- tedunangst 11y ago> "RSA BSAFE had support for Extended Random." Support!? Uh no, it used it as the default generator. ? Extended Random is not a random number generator.
- linkregister 11y agojgon, maybe you're also reading this on a mobile client. tptacek's first side note on the right column is that his opinion is that DUAL_EC_DRBG is an NSA backdoor. Far from burying the most important part of the scandal, he puts it front and center. This discussion is about other proposed extensions to TLS, not DUAL_EC_DRBG. It might be too late, but I recommend you edit your comment to change "Extended Random" to DUAL_EC_DRBG (the random number generator). Extended Random is an extension proposed by the NSA (Clyde Frog).
- kordless 11y ago> I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like. You have three negations in this sentence, which means it's nearly impossible to parse or understand. It's been my observation statements like these follow rationalizations about a point in which there exists dissonance. Given you seem to be disagreeing with something Thomas said or the way he said it, but not actually disagreeing with a point he made, I'd say that is the case here as well. Violations of our privacy via rationalizations of security makes me sad and bored. I think we can all agree that things could be better with the situation, and I for one appreciate Thomas' efforts in bringing the truth to light.
- mod 11y ago> I will still not say that reasonable people can't disagree over the question at hand but the arguments presented in this article don't strike me as being anywhere near strong enough to make this the sort of grey area the author would like. I didn't think it was that hard to read. It made sense on my first read, but here's my translation: "I can see how arguments exist on both sides, but I don't think the author supported his argument with enough evidence to make it very relevant."
- detaro 11y ago> "RSA BSAFE had support for DUAL_EC." That line you quote isn't in the article. The only reference to DUAL_EC and BSAFE is in the timeline and says: > Early 2004: RSA allegedly accepts payment to make Dual_EC the default in BSAFE, their crypto library.
- tedunangst 11y agojgon apparently took linkregister's advice to change "extended random" to dual_ec too literally, and changed a direct quote as well.