3 ms·
There's a certain point in the security world where paranoia becomes a requirement, even though it only breeds more paranoia. An outcome of this is the require
by samplatt 3y ago
There's a certain point in the security world where paranoia becomes a requirement, even though it only breeds more paranoia.
An outcome of this is the requirement to treat all possibilities as certainties, regardless of evidence.
In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles.
- AnthonyMouse 3y agoKnowledge that this environment exists is also strong evidence that it was a backdoor. If you propose a clearly questionable security practice in some arbitrary bureaucracy, the assumption is it's incompetence because that happens all the time and no one detects it until it's already in production. If you propose a clearly questionable security practice to a cryptography standards body, the expectation is that you get laughed out of the room. Even the possibility of a backdoor would make everyone skeptical, which would be useless in a standard because no one would trust it. And yet it made it through the standards process for some reason, but there is only one plausible reason.
- thephyber 3y ago> In this way, entire sections of industry will auto-assume the backdoor was both deliberate, and used both both friendlies & hostiles. That’s fine. But they should be equally paranoid of all substitute products/services that use other recommendations from NIST, right? Are there greater than zero products on the (US) market with no encryption in the system recommended by NIST? Also, I don’t think I was limiting my thinking to a customer of the weak encryption product. I was also thinking through the lens of legal implications.