3 ms·
I tried that tool against my Raspberry Pi which should have a reasonably-secure SSH configuration and I got a lot of warnings about: > NIST P-curves are possib
by MrRadar 4y ago
I tried that tool against my Raspberry Pi which should have a reasonably-secure SSH configuration and I got a lot of warnings about:
> NIST P-curves are possibly back-doored by the U.S. National Security Agency
Is there any evidence of this? This seems extremely paranoid.
- LinuxBender 4y agoIs there any evidence of this? This seems extremely paranoid. I have not seen any evidence, just discussions. [1][2] [1] - https://crypto.stackexchange.com/questions/10263/should-we-trust-the-nist-recommended-ecc-parameters https://crypto.stackexchange.com/questions/10263/should-we-t... [2] - https://arstechnica.com/information-technology/2015/01/nsa-official-support-of-backdoored-dual_ec_drbg-was-regrettable/ https://arstechnica.com/information-technology/2015/01/nsa-o...
- _jal 4y agoNo smoking gun. But beyond Snowden's allegations, (a) the NSA has a history of very similar shenanigans and (b) there are readily available alternatives, so why risk it?