3 ms·
Are people really so quick to forget? https://www.miracl.com/press/backdoors-in-nist-elliptic-curves https://www.miracl.com/press/backdoors-in-nist-elliptic-cu
by lugg 7y ago
Are people really so quick to forget?
https://www.miracl.com/press/backdoors-in-nist-elliptic-curves https://www.miracl.com/press/backdoors-in-nist-elliptic-curv...
Their goals are at the very least nationalist.
As a non US citizen why should I trust them at all?
Their main directive errodes my privacy on most levels in most sense of the words.
- kbenson 7y agoAll I said is that they may have complex goals, while pointing out selinux was also contributed primarily by them. I take it that means your position is that they only contribute code for the purpose of exploiting people for national security, and selinux is also suspect?
- mort96 7y agoI mean, being primarily contributed by the NSA is a great reason to not use SELinux, especially if you're outside of the US. AppArmor exists and does a lot of the same job, so why not use the safer option?
- closeparen 7y agoThey're a spy agency, they're presumably capable of not signing their work.
- ENOTTY 7y agoThe chief problem with AppArmor is that its primary mechanism of identifying objects in the system (to which relevant policy rules are applied) relies on paths. In Linux, paths are not usable as strong identifiers because Linux provides a variety of ways to alias those objects. Additionally, some objects that deserve scrutiny from a mandatory access control perspective don't map cleanly to paths.
- ganzuul 7y agoHas that changed? A decade ago when I looked at their charter they were supposed to strengthen security; not weaken it.
- mankeysee 7y agolmao at trusting their "charters" to gauge their real aims
- AmericanChopper 7y agoTheir two missions are Signals Intelligence and Information Assurance. The contributions they make to security technology and standards are going to be equally as effective no matter what country you’re a citizen of. If you think the work they release is motivated by an intention to compromise your security, then you must also believe they are trying to do the same thing to the US federal government. A goal which hardly seems very nationalist.
- lugg 7y agoBoth of those missions are at odds with improving security. Try harder.
- AmericanChopper 7y agoInformation Assurance is not at odds with improving security. It is literally the NSAs mandate to improve the security of the federal government (and other US entities). You’re making an assumption that in order to gather signals intelligence, that they need to trick people into using compromised cryptography. A fact that is not in dispute is that huge portions of the US federal government implement NSA recommendations and standards. For your assumption to be true, the NSA must be intentionally weakening federal systems. Nothing about that seems nationalistic to me.
- cf498 7y agoDid you already forget how long they knew of EternalBlue instead of immediately forcing patches?