3 ms·
Did the FBI give any reason/leverage as to why you should comply with their ask? If you are writing about it here, I'm assuming it wasn't an NSL (national secu
by dotBen 9y ago
Did the FBI give any reason/leverage as to why you should comply with their ask?
If you are writing about it here, I'm assuming it wasn't an NSL (national security letter) and so would you be open to publishing a copy of it publicly? Would be great to get sunlight on that.
- drawkbox 9y agoProbably in an old desk somewhere, it wasn't an NSL but I wish I would have held onto it, I would have captured it on my phone if smart phones were around then. It basically said if you are going to keep using PGP or custom encryption for the app that they would like to meet with us to discuss since we were connecting to government financial endpoints. Then it said if we use RSA that this would not be a needed discussion. It was very strange and eerie all in all and we did not want to rock the boat. Since we were small/medium agency/company we just complied as we were just helping smaller/medium companies sell stuff like Ukuleles and hats to AAFES so it was not a big issue. The key of the app was the EDI/AS2 integration that didn't use the PGP or custom crypto as it had to use certain algos RSA/DSA/TripleDES/FIPS/strong hashing for Drummond Group interoperability certification. The certification of interoperability and crypto communication was required to trade with Wal-mart, govt/AAFES etc.
- lazaroclapp 9y agoTo be fair, naively and given the use case you described, that sounds to me like in this particular instance they are trying to ensure that the encryption being used is "secure enough" for the govt. rather than "not too secure". It just so happens that the bureaucracy's definition of "secure enough" is a keyword whitelist that happens to have 'RSA' there and not 'PGP'.