8 ms·
It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
by pepve 13y ago
It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
- pedrocr 13y agoHow do you figure? The scandal around the NSA PRNG is indeed a backdoor, is it not?
- tel 13y agoSerious question: what's the difference? I would have followed the definition for backdoor since it relies on particular secret information relating P and Q that the NSA might have—but where should one draw the line between backdoors and vulnerabilities? Intent?
- meowface 13y agoRepeating my comment: An intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor. So yes, it's pretty much a matter of intent.
- ballard 13y agoNerd's law: A commenter C declares that concepts X and Y are completely different. Because parent commenter P failed to make this point, P is intellectually inferior to C. Hence C > P for all X and Y.
- nullc 13y agoIt's a PRNG based on a trapdoor function where apparently the NSA has the key. With that key they can recover the RNG state from just a small amount of it. Thats a backdoor by most descriptions. This isn't just a bug.
- piratebroadcast 13y agoSnowden obviously has that key as well.
- ZoF 13y agoHaha what? Not only is there no way of knowing that, but it's not even relevant.
- meowface 13y agoAn intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor.
- matsur 13y agoIt's a backdoor. The original paper describing the hole is (hopefully) entitled "On the Possibility of a Back Door in the NIST SP800-90 Dual Ec Prng"[0]. It's no longer a "possibility". [0] http://rump2007.cr.yp.to/15-shumow.pdf http://rump2007.cr.yp.to/15-shumow.pdf
- tptacek 13y agoUh, yes it is still a "possibility". Unless you have a source I missed, which is possible but please actually cite it, all we learned about Dual_EC from the NSA leak was that the algorithm was designed at NSA. Lots of crypto is designed at NSA; it isn't all presumed to backdoored.