4 ms·
The assumption that the NSA catches (and discloses) most flaws in major open source software requires a high suspension of disbelief.
by jtc331 3y ago
The assumption that the NSA catches (and discloses) most flaws in major open source software requires a high suspension of disbelief.
- acdha 3y agoIn particular it requires belief that the NSA ignores its mandated mission to protect U.S. infrastructure and is arrogant enough to think only they could find those problems. The federal government, state and local governments, key service providers, major utilities, etc. all rely on open source software and there’s no plausible way they wouldn’t be leaving those open to attack if they didn’t report a known vulnerability.
- lamontcg 3y agohttps://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- acdha 3y agoYes, that’s a good example of what I’m talking about. Even when they tried to subvert a cryptographic primitive, notice how they designed it in such a way that they could exploit it but other parties could not? Even making the attempt was unacceptable but I will say it’s categorically different than leaving an open source vulnerability unpatched. If they weren’t the ones who created it, they wouldn’t have noticed but not reported it – even our closest allies aren’t trusted with root on government servers.
- lamontcg 3y agoThink you've got that backwards, there's nothing fundamental about Dual_EC_DRBG that prevents anyone else exploiting it, while the xz vulnerability is gated with a specific private key.
- acdha 3y agoSame story with the constants in Dual EC: http://rump2007.cr.yp.to/15-shumow.pdf http://rump2007.cr.yp.to/15-shumow.pdf The xz vulnerability is exactly the same in that guarded sense, so I’d be completely unsurprised if the NSA was behind it but I don’t think they’d otherwise help keep it quiet. Even if it was another Fives Eyes country it’s hard to imagine them being okay with that level of risk.