3 ms·
As in most of these technological failures, the problem may just be between the keyboard and chair. I never cease to be amazed at the seemingly insurmountable o
by eksith 13y ago
As in most of these technological failures, the problem may just be between the keyboard and chair. I never cease to be amazed at the seemingly insurmountable odds people defeat to ensure something breaks somewhere in the least predictable way possible. In such an atmosphere, deliberate sabotage or sci-fi caliber cracking hardware are the least of your worries.
- ordinary 13y agoAs in most of these technological failures, the problem may just be between the keyboard and chair. What slightly complicated matters is that it is not certain who's occupying said chair: a user or a developer.
- makomk 13y agoThe trouble is, well-done deliberate sabotage is very hard to distinguish from incompetence. (It appears there is definitely deliberate sabotage out there - see for instance http://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html http://www.mail-archive.com/cryptography@metzdowd.com/msg123... which sadly didn't make the front page here.)
- harrytuttle 13y agoThat should be on the front page. Thanks for linking.
- salgernon 13y agoJohn Gilmore has been involved in this space, and fighting for "us" for a long time. I'd previously submitted this, but it failed to get traction: http://www.toad.com/des-stanford-meeting.html http://www.toad.com/des-stanford-meeting.html
- MichaelGG 13y agoExcellent link, thanks. And it is very hard to distinguish. Many other IETF RFCs are incredibly complicated and add idiotic "features" and stuff just for the sake of it. Mitigating factor in this particular case is that some of the things proposed, like using the same IV for each packet, would definitely be found out by people other than the NSA. That would go against the NSA's goals.
- snowwrestler 13y agoDescriptions like this one make me wonder if the apocryphal "huge breakthrough" in encryption by the NSA is in their ability to simulate and analyze the implementation of complex crypto computer systems. (Rather than in the base mathematics.) They are deterministic systems after all, and giving researchers the means to look at them more abstractly could make it a lot easier to pick where to attack, or where to concentrate spycraft to introduce weaknesses that would be hard for mere mortals to detect on their own.
- harrytuttle 13y agoThat's a good hypothesis. It's definitely possible if you consider things like verified compilers. It shouldn't be beyond them to apply this to crypto implementations.
- epsylon 13y ago> The trouble is, well-done deliberate sabotage is very hard to distinguish from incompetence. Behold the Underhanded C contest, where the aim of the contest is to deliberately create vulnerabilities disguised as genuine bugs. http://underhanded.xcott.com/ http://underhanded.xcott.com/