4 ms·
Even after this you still don't think they're actively subverting encryption standards? http://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html htt
by salient 13y ago
Even after this you still don't think they're actively subverting encryption standards?
http://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html http://www.mail-archive.com/cryptography@metzdowd.com/msg123...
- tptacek 13y agoNo. I believe I know the specific people to whom Gilmore is referring, and I believe his observations to be a straightforward result of incompetence. You have to have read the IPSEC working group list posts of the time and see how the group treated real cryptographers to understand how unnecessary it would have been for NSA to have corrupted that standard. No, I don't think NSA tried to subvert IPSEC, and especially not in the way Gilmore describes.
- ef47d35620c1 13y agoWhy do you think John Gilmore is incompetent? He's very well regarded by many technologists. toad.com is probably older than many HN readers. Edit: I may have misunderstood who was being accused of incompetence. My apologies.
- nknighthb 13y ago> Why do you think John Gilmore is incompetent? That is not what he said.
- dredmorbius 13y agoIt's not what he didn't say either. The wording was poor if that wasn't his meaning.
- tptacek 13y agoYou misread me.
- dredmorbius 13y agoGiven I received no clear meaning from your statement, and you've failed to clarify it, no, you've mis-written yourself. Your statement was and is unclear. Your follow-up to which I'm responding doesn't change that.
- timdiggerm 13y agoGiven that most people understood his post, the problem may lie in the reader, not the writer.
- bbatsell 13y agoHe's saying that Gilmore was attributing to malice what Thomas believes more likely to be due to incompetence. He's not asserting that Gilmore is incompetent.
- makomk 13y agoI dunno. Packing standards bodies with incompetents and then suggesting things to those incompetents that are apparently sensible but weaken security seems like a perfectly plausible way of subverting cryptographic standards to me. Also, it probably wouldn't be terribly hard to seed a culture of disdain for real cryptographers.
- tptacek 13y agoYou follow this logic consistently and pretty soon you're blaming NSA for bad weather.
- wavefunction 13y agoDid you just use a "slippery slope" argument to argue against "slippery slopes?" I'm gonna chalk this up to "tongue-in-cheek," though I may be wrong...