3 ms·
Matthew Green's blog on why it happened and how it escaped detection is a really good read. https://blog.cryptographyengineering.com/2017/10/16/falling-through-
by trustzone 9y ago
Matthew Green's blog on why it happened and how it escaped detection is a really good read. https://blog.cryptographyengineering.com/2017/10/16/falling-through-the-kracks/ https://blog.cryptographyengineering.com/2017/10/16/falling-...
- davidkuhta 9y ago> Representation of the 4-way handshake from the paper by He et al. Yes, I know you’re like “what?“. But that’s why people who do formal verification of protocols don’t have many friends. +1 for a good read, really enjoyed his writing style. For those unfamiliar, Matthew Green is a cryptography researcher and professor at Johns Hopkins. Edit: TIL John's' Hopkins ty /u/dEnigma
- dEnigma 9y agoIt's actually "Johns Hopkins". The story behind the name is somewhat interesting: http://www.hopkinsmedicine.org/about/history/history1.html http://www.hopkinsmedicine.org/about/history/history1.html
- ghettoimp 9y ago"One of the problems with IEEE is that the standards are highly complex and get made via a closed-door process of private meetings. More importantly, even after the fact, they’re hard for ordinary security researchers to access." While I'm sure this can't take much of the blame, it sure strikes a chord. The IEEE standards process seems insanely archaic and broken in the open-source era.
- rphlx 9y agoIt is, arguably, pretty broken even in some closed-source arenas. For instance if your objective is to have the IEEE first define thorough, carefully reviewed standards which are then closely and widely implemented throughout an entire industry, 25G and 50G Ethernet were abject failures.
- nieve 9y agoIt's been years since I was involved with the organization side of the Standards Association, but there was a lot of frustration among staff because the vendors (and stakeholders in general) often had a vested interest in keeping the process broken. IEEE as a whole had a weird relationship with Standards as well. A somewhat related example is that it took staff years to get permission from all the vendors to release the full MAC address allocation database after agreeing to keep it non-public. In general you can probably assume that people who work for Standards are even grumpier about the whole nightmare than people outside the process. It's sort of a perverse form of regulatory capture where the "agency" is still trying to do the right thing, but they're locked in by their constituency.