8 ms·
I wonder how much they paid to gag the researchers for the 17 months it took them to fix this.
by gamegod 7y ago
I wonder how much they paid to gag the researchers for the 17 months it took them to fix this.
- vvanders 7y agoAm I reading this correctly that they couldn't be arsed to do DTLS/TLS and so they rolled their own lame crypto?
- userbinator 7y agoI suspect it was more that they never intended to use "true encryption" but just wanted to lightly obfuscate the data. Using strong crypto in a commercial product, especially one intended for international distribution, still brings up a bunch of legal issues that they may have been trying to sidestep: https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States#Current_status https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... Having worked before (fortunately not for long) in an environment where trying to argue for "using the OS's crypto library is easy" would've been shot down with a strict "NO!" from management, I can definitely see how this situation occurred. That was a long time ago, but this may have been code left over from that era, and I'm not surprised if many more examples of such, along with people who are still in that mindset, still exist today. I've seen similar things in all manner of other software (mostly DRM-related, so I won't say more...) --- it's not a hard wall, but a shield from casual observers and "keeping the honest people honest" type of idea.
- acqq 7y ago> Using strong crypto in a commercial product, especially one intended for international distribution, still brings up a bunch of legal issues that they may have been trying to sidestep: But apparently they sell VPN software. That's their product. The obscured by not encrypted output is the information from the inside of the VPN, and more. They could not avoid solving legal issues anyway when selling VPN. They completely deserve a "doghouse" tag on Schneier's blog: "A decade ago, the Doghouse was a regular feature in both my email newsletter Crypto-Gram and my blog. In it, I would call out particularly egregious -- and amusing -- examples of cryptographic "snake oil." I dropped it both because it stopped being fun and because almost everyone converged on standard cryptographic libraries, which meant standard non-snake-oil cryptography. But every so often, a new company comes along that is so ridiculous, so nonsensical, so bizarre, that there is nothing to do but call it out." FortiGuard qualified IMHO. A big seller of VPN software to companies (2B revenue!) who is deliberately faking encryption.
- ghostpepper 7y agoIt would be funny if Fortinet, specifically, were to claim that their lack of encryption is to avoid violating export restrictions since according to their wikipedia page [0] they've been seen selling their products to repressive third world dictators [1][2] (Myanmar). [0] https://en.wikipedia.org/wiki/Fortinet https://en.wikipedia.org/wiki/Fortinet [1] https://www.nytimes.com/2005/10/12/technology/study-says-software-makers-supply-tools-to-censor-web.html https://www.nytimes.com/2005/10/12/technology/study-says-sof... [2] https://www.csmonitor.com/2007/1010/p01s01-ussc.html https://www.csmonitor.com/2007/1010/p01s01-ussc.html
- linsomniac 7y agoI'm not sure you can call XOR+static key "rolling your own crypto". :-/