15 ms·
Secret contract tied NSA and security industry pioneer
- dpratt 13y agoPerhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
- mcphilip 13y agoAssuming that the preference of which algorithm is used in an encryption standard can be influenced by $10 million, then I I'd say you read the article correctly. Very alarming...
- bowlofpetunias 13y agoNo, it sounds like no product from any American company can be trusted as long as the current regime is in place. At least that's the message that comes through loud and clear in the rest of the world.
- michaelcampbell 13y agoThat's quite a leap from the information in that article.
- venomsnake 13y agoAdd it to all previous and you have some basis. Companies that have been compromised[1] - MS, Apple, Facebook, Google, Yahoo, Carriers, Backbone providers - now they are going after security providers. From the big guys only Intel is standing. And that may as well be the next leak. Also think if they subverted some of the big guys antiviral software - it runs at ring 0 usually. [1] Blackmail, threats, bribes, lawful intercepts, warrants, NSLs
- ge0rg 13y agoThat article is merely one piece of information in a long chain (Echelon, the Snowden revelations, Lavabit), and all of them add up to the conclusion that you better not trust any US-based/originated IT security system.
- michaelcampbell 13y ago> any US-based/originated IT security system Perhaps, but the poster to which I replied said any US company, period. Could be he meant what you meant, but that's not what he said.
- tedivm 13y agoWhat makes you think the NSA isn't willing to work with countries outside of the US, either directly or through another spy agency?
- SideburnsOfDoom 13y agoWilling, sure, but probably less able, at least outside of the close allies like the UK.
- gejjaxxita 13y agoWhy less able?
- girvo 13y agoThreatening with legal punishment for noncompliance doesn't work, and neither does appealing to patriotism.
- SideburnsOfDoom 13y agoAre you seriously asking why a branch of the the USA's government has less power outside of the USA?
- enkephalin 13y agoif you consider the fact that the nsa and cia often collaborate closely, and then look at the amount of influence the cia has often displayed in the past, towards foreign countries/regimes etc., gejjaxxita's question seems quite reasonable.
- brdrak 13y agoPlus the blackmail opportunities spying affords.
- sixothree 13y agoOnly the same things that makes me think american companies would not accept money from foreign spy agencies.
- PeterisP 13y agoThe same influence approach ($10m to choose a supposedly okay algorithm) would work just as well for most similar non-American companies, it isn't claimed that RSA did this because of some mandate which would fail if they'd be headquartered in, say, France.
- im3w1l 13y agoWhy keep the contract secret though?
- PeterisP 13y agoOf course the contract must be kept secret for PR and product reputation reasons. It's just as if an antivirus company to accept a contract with a major adware distributor to keep their products marked as appropriate - legal, but best kept secret.
- benihana 13y agoThat's how I read it.
- a3n 13y agoIt sounds to me like they should be sued for selling a product that was knowingly less secure than they claimed.
- aortega 13y agoTLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit." Dual_EC_DRBG was a NIST standard.
- deleted 13y ago[deleted]
- rhizome 13y agoMore specifically, it was RSA's "BSAFE" product which is problematic and was paid to be a default.
- throwaway_yy2Di 13y agoFrom the article: "RSA adopted the algorithm even before NIST approved it. The NSA then cited the early use of Dual Elliptic Curve inside the government to argue successfully for NIST approval, according to an official familiar with the proceedings."
- yuhong 13y agoLucky Green was the first to mention this: http://lists.randombit.net/pipermail/cryptography/2013-September/005341.html http://lists.randombit.net/pipermail/cryptography/2013-Septe...
- salient 13y agoThe end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longer. All of their customers should be warned, and advised to quit them ASAP. Companies need to learn this is just unacceptable.
- jtbigwoo 13y agoSerious question: Is there an alternative? I've never seen a secure fob that wasn't from RSA.
- ggreer 13y agoI like Yubikeys: https://www.yubico.com/ https://www.yubico.com/. They show up as a USB keyboard, so you don't have to type the codes in. There are some disadvantages. Yubikeys use a shared secret instead of public key crypto. Also, the one-time password is iteration-based, not time-based. On the bright side, you can program Yubikeys with your own secrets. They may not be as secure as properly configured RSA tokens, but they're much better than authing with just a password or client cert.
- beagle3 13y agoYubikey NEO (latest revision) is like the one you already have + a java card that comes with a PGPcard app (and supposedly, you can write your own apps) They don't have a timer like the RSA key fobs, and need a USB or NFC connection - but are generally very reliable, and given their constraints. The questiion, of course, is what reason you have to believe that yubico (and for that matter, gemalto, g10code and the rest) are not similarly in bed with the NSA.
- apaprocki 13y agoTrusting trust :) This is one of, but not the main reasons why we build our own (Bloomberg B-Unit, PDF is the only good pic I see: http://www.bloomberg.com/professional/files/2013/11/b-unit_3_user_guide.pdf http://www.bloomberg.com/professional/files/2013/11/b-unit_3...)
- raverbashing 13y ago$10Mi? That's a very cheap price for trashing your companies reputation. More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.
- ericcumbee 13y agoa better price than "do it or we will destroy you".
- tedunangst 13y ago"it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year"
- batgaijin 13y agoI think Dr. Evil was at the bargaining table
- brdrak 13y ago> DRBD You mean DRBG [1], right? I hope DRBD [2] isn't backdoored. [1] http://en.wikipedia.org/wiki/Dual_EC_DRBG http://en.wikipedia.org/wiki/Dual_EC_DRBG [2] http://en.wikipedia.org/wiki/Distributed_Replicated_Block_Device http://en.wikipedia.org/wiki/Distributed_Replicated_Block_De...
- zepolud 13y ago> [...] but RSA said in a statement: "RSA always acts in the best interest of its customers [...] True, you just have to keep in mind that their customer is the NSA.
- blazespin 13y agoRSA is thinking they can claim ignorance in the case of the DRBG being weak / possibly backdoored.
- nathan_long 13y agoThey were either corrupt or incompetent. This can't look OK for them.
- wil421 13y agoI use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.
- yuhong 13y agoI don't think this fiasco is related to the tokens but yes the tokens has other problems such that it didn't need NSA to break it.
- wil421 13y agoI wasn't sure I skimmed half the article. It did have a giant image of one the tokens though.
- ben1040 13y agoIt's a bad image, because it conveys an idea that's different from the story, but I can see why they used it -- from the general public's perspective the tokens are pretty much the most recognizable symbol of RSA.
- VladRussian2 13y agoi wonder if Snowden has any detailed info on the NSA indroduced/forced backdoors (he obviously was aware about their existence in general like pretty much everybody in the world who isn't a tptacek's religious follower) and this or something like this is what keeps him alive - ie. NSA is afraid of dead man switch while other side(s) hopes that Snowden will reveal more and specifically useful for actual hacking info with time.
- x0x0 13y agoso that's the thing that scares me a nsa official just did an obvious trial-balloon of pardoning snowden in exchange for return of all the docs [1] but now that snowden is in russia, you have to assume that many nation-states have seen all these docs. so really, the nsa is worried that you and I will see them fucking amazing [1] http://www.theguardian.com/world/2013/dec/15/nsa-edward-snowden-amnesty-documents http://www.theguardian.com/world/2013/dec/15/nsa-edward-snow...
- rhizome 13y agoFrom the BSAFE product page: "RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts." [emphasis added]
- runn1ng 13y agoThis is really hilarious.
- venomsnake 13y agoWell NSA do have highly regarded crypto guys. And they do back the technology.
- angersock 13y agoTruth in advertising, that.
- icambron 13y agoTypo; they left out "door".
- deleted 13y ago[deleted]
- jeremycole 13y agoIt never claimed that those experts were working in the customer's best interest, though. ;)
- withinNwithout 13y agoLOL
- tommis 13y agoThis is going to end RSA
- jimhefferon 13y agoBut, but, but .. Canada just made prostitution legal.
- aubreyjohnson 13y agoAuthy was already on its way to doing it anyway. Glad to see it sped it up for a YC alum.
- midas007 13y agoThe reaction from the average IT architect is to just select another vendor that provides yet another closed-source, blackbox hardware security solution, backdoored by who know which government(s) &| other entities. Open source hardware is (un)fortunately a necessary requirement (verilog/vhdl, firmware sources and no blackbox SoCs), samples of which are periodically verified by destructive and nondestructive means. Very, very costly, but doable and raises confidence.
- yuhong 13y agoThis reminds me of the MS-Novell deal, which was done in a similar way and has similar problems.
- judk 13y agoBut "everyone" agreed it wasn't actually a backdoor. I wonder if that will get walked back finally.
- dpratt 13y agoI wonder if any of the executives involved with this deal will have a moment of clarity and make a public statement - "I was directly told by representatives of the U.S. Government that if we did not take this deal there would be direct and material consequences for both my company and myself. Here is the names of the people I met with, here is a log of the meetings. If I am jailed or in some other fashion publicly discredited through an otherwise seemingly unrelated matter in the future, you should always remember that I have made this public statement."
- deleted 13y ago[deleted]
- ye 13y agoThink of it from the executives perspective: Option A: keep mouth shut, make a shit ton of money Option B: become a martyr, face prison time People like Snowden are rare.
- pekk 13y agoAnd what if it were very common to take jobs just to hack the internal network, scour it for sensitive-looking data, and dump it all publicly for the sake of fame? I am pretty sure most "executives" would not be happy with that norm
- ye 13y agoMy guess is that most people educated enough and promoted enough to get access to such information wouldn't risk years of efforts for potential fame. I'd say most of the whistle-blowers want to remain anonymous.
- InclinedPlane 13y agoThose aren't the only options. Anyone with any smarts can figure out how to quietly and anonymously leak a lot of these details. The fact is that they were too cowardly to do even that though.
- smtddr 13y ago>> https://news.ycombinator.com/item?id=6942165 https://news.ycombinator.com/item?id=6942165 tptacek 5 hours ago | link I am not generally a believer in the theory that NSA actively subverts Internet standards† †(my best guess is that the standards NSA was actively subverting were about international telephony; subverting the IETF is a little like subverting the Linux kernel --- doable, but bad tradecraft) Does this count?(not trying to be sarcastic or a smart-a##), I just want to get a handle on what I should or should not trust these days. Seeing that RSA SecurID VPN dongle pic in the article scared me. I've pretty much been looking to your comments to give me a baseline.
- guelo 13y agoPersonally, I think one of the things you can't trust these days are comments by tptacek.
- napoleond 13y agoEither you're insinuating that 'tptacek is a malicious actor, or that he's incompetent. That's a pretty serious allegation to make without providing any evidence whatsoever. Do you have any? I'm sure you can dig up a few examples of things that he said which were incorrect, but very few of those will not have been followed by a correction at some point, and either way your insinuations seem to go beyond "being wrong some of the time". HN is incredibly fortunate to count members like 'tptacek as part of its community. We should be behaving in ways which encourage more comments and commenters of his ilk, not less.
- ewoodrich 13y agoUnsurprisingly you're already being down-voted. For a community that prides itself on being rational and home to spirited debate, when it comes to the NSA, any contrarian opinions (or even alternative perspectives) tend to be quickly attacked and silenced. If you read some of the first threads when the NSA revelations broke out, there are heated discussions with various viewpoints and arguments. Now, it appears that most of these users have become tired of being instantly downvoted, and instead avoid these subjects entirely. I hope that tptacek continues to participate in these security policy discussions, not only for his extensive domain knowledge, but also because he is not afraid to voice beliefs that disagree with prevailing opinion. And right or wrong, its very refreshing.
- lawnchair_larry 13y agoEagerly awaiting tptacek's retraction to his insistence that this was not a backdoor. Edit: Nevermind, apparently he already did a mere 8 hours ago, replying to my own comment. Shortly before this broke. https://news.ycombinator.com/item?id=6941366 https://news.ycombinator.com/item?id=6941366
- deleted 13y ago[deleted]
- lawnchair_larry 13y ago> Jesus, what a tool you are. I absolutely believe you: I think you read this story and eagerly awaited its implications to some random person on HN. Huh, I've seen your patience tested on HN before, which tends to elicit mostly restrained responses save for a bit of snark, but that's the first instance of actual name calling I've noticed. I'm genuinely curious how this comment annoyed you. The tone I'd expect is more of a "yeah, you got me" <kneeslap>. Instead it sounds like I'm accidentally trolling you. For what it's worth, I did legitimately get excited to run to HN to play "told you so". After months of debate over this issue across numerous threads, I'm not going to lie, vindication is momentarily exciting. > For what it's worth, my take on Dual EC (before learning more about it) was the same as noted NSA apologist Bruce Schneier. Wait, tptacek is calling Bruce Schneier an NSA apologist? Aside from being absurd, your claim that you shared the same opinion is also false. Your own comment here directly contradicts this, and you even dismiss Schneier's credentials upthread, yet appeal to his authority in your comment: https://news.ycombinator.com/item?id=6424920 https://news.ycombinator.com/item?id=6424920 "I am aware that Schneier believes Dual_EC to be backdoored. I'm aware that Dual_EC comes from NSA. I would not use Dual_EC and would flag it if I saw it in an app I assessed. But I would still, right now, with the information I have, bet against it being an NSA backdoor. Not because I trust the NSA, but because it's a very dumb backdoor." Edit: In reply to a now deleted comment by tptacek.
- wglb 13y agoYour series of comments in this thread is way below the threshold for positive contributions to any HN discussion.
- vikas5678 13y ago"RSA, now a subsidiary of computer storage giant EMC Corp, urged customers to stop using the NSA formula after the Snowden disclosures revealed its weakness." - Just shake my head at this. As news is revealed that all these companies were complicit, they cry foul and "warn" users? RSA deserves to lose all international customers who refuse to buy their products because of hidden backdoors.
- judk 13y agoQuote possible that one arm of the company was an aware of the other arms actions. Probable, in fact. If most of the company knew of the backdoor, it would have leaked.
- chime 13y agoIn case you didn't know, EMC bought RSA in 2006. Shutting down RSA just means re-branding all the products as something else.
- fiatmoney 13y agoSeems like their customers now have an excellent case for commercial fraud against RSA.
- andrewcooke 13y agothe r in rsa is ron rivest who was responsible for some very elegant ideas. his papers, that i've read, are generally very simple and clear. but he also wrote md2 [an old hash, n longer used] which contains some "magic numbers" that no-one can explain. they are supposed to be derived from pi, but no-one knows how... http://crypto.stackexchange.com/questions/11935/how-is-the-md2-hash-function-s-table-constructed-from-pi http://crypto.stackexchange.com/questions/11935/how-is-the-m... (i even emailed him, but was shrugged off; i know it's silly and paranoid, but...) anyway, i wonder what happens now to all the customers that use rsa dongles? big, international, political organisations...
- somethingnew 13y agoReminds me of http://xkcd.com/538/ http://xkcd.com/538/ except instead of a $5 wrench, it was $10 Million and a few handshakes.
- rurban 13y agoI believe we heard that some months before already. The biggest problem is IMHO their libcrypto still being used in Java and MS Windows.
- middleclick 13y agoWhat implications does this have for RSA?
- flyt 13y agoIt's Bad.
- wavefunction 13y agoHopefully the end of them. It's the only thing that matters to these mercenaries...
- PhantomGremlin 13y agoI strongly agree. Crypto is something where reputation is sine qua non. After the 2011 data breech they lost a lot of it. Now how can anyone trust them ever again?
- fragsworth 13y agoThe NSA's story about how they need to secretly do these things to fight the war on terror makes less sense with each new revelation. Terrorists don't use VPN dongles. What is really going on here?
- robszumski 13y agoTerrorists don't, but the banks that they use probably do. You've gotta break into a lot of systems before you get to the information you want.
- jlund 13y agoBusinesses use RSA VPN dongles, and the stories that are starting to surface now are more about economic espionage. "Follow the money" is a slippery slope.
- objclxt 13y agoYou are making an assumption that the primary target of SIGINT is terrorists, but in reality it's actually nation states. I think another story just came out today about GCHQ targeting EU officials and embassies.
- moocowduckquack 13y agoNation states are likely to roll their own dongles though. The folk that use these are bluechips meeting due diligence requirements.
- PeterisP 13y agoNSA also does commercial espionage to harm non-US bluechip companies, which are quite likely to use those dongles for internal data.
- jballanc 13y agoHeh...I certainly had a good chuckle at this comment. I don't honestly think that the NSA ever paid more than lip-service to the "war on terror". They've been doing the same job since long before Sept. 11, 2001. Before the "war on terror" it was the "cold war", there just happens to have been an awkward gap in between... The NSA is in the business of Signals Intelligence. Their job, plainly stated, is to have access to as much communication between non-US entities as humanly possible. What makes their job difficult is that, over the course of the last few decades, it's become increasingly the case that much of the communication between non-US entities travels via US-based channels using technology originated in the US. Somewhere along the line, when forced to balance "as much communication" and "non-US entities", the NSA clearly chose in favor of accessing those communications at any cost.
- mathattack 13y agoShouldn't this destroy RSA as a company? If your in security, and your security can't be trusted...
- mcantelon 13y agoIt should, but AT&T's still in business and their collaboration with the state to spy on customers has been known for a long time.
- mathattack 13y agoAT&T is explicitly selling "we connect you", not "we secure you."
- aagha 13y agoRSA is now owned by EMC
- socialnerdia 13y agoPrivacy: Pre-internet term(from Latin: privatus "separated from the rest, deprived of something, esp. office, participation in the government", from privo "to deprive") used to describe the ability for human beings to seclude themselves or information about themselves and thereby reveal themselves selectively.
- akulbe 13y agoPlease forgive my ignorance of these kinds of security issues.... I remember at one point, way back when, it was recommended to use RSA keys over DSA, when creating an SSH public key. Is this this the same algorithm, by the same company? Does this mean that SSH can't be trusted if you're using an RSA key, versus some other type?
- SamReidHughes 13y agoNo, it doesn't mean that at all. RSA is the same algorithm based on https://en.wikipedia.org/wiki/RSA_%28cryptosystem%29 https://en.wikipedia.org/wiki/RSA_%28cryptosystem%29 as it always was, and it and its use in openssh have received lots of scrutiny. That the company has the same name is immaterial.
- lawnchair_larry 13y agoRSA the company has nothing to do with RSA the algorithm. Well, "nothing" isn't strictly correct, but connecting them is more like the Kevin Bacon game. Rest assured that this story has nothing whatsoever to do with RSA keys.
- ye 13y agoI'd love to see a class-action lawsuit. This shit must be punished.
- deleted 13y ago[deleted]
- steven2012 13y agoWho in their right mind would use an American technology product at this point? You would be an idiot to think that it wasn't backdoored by the NSA.
- obstacle1 13y agoUnfortunately, I think there's still a pretty large market of people who just don't give a crap about being NSA'd. Nothing to hide, and all of that. That said it's likely individual consumers who are likely to have this attitude rather than businesses.
- suprgeek 13y agoNSA invents weak (Back Door present) crypto algo. Pushes RSA to make it a Default in a key function (RNG) by giving them $10 Million. NSA points to RSA as an early adopter and gets NIST to certify it. Millions of systems are now protected by an RSA product that the NSA deliberately weakened. Any sufficiently skilled rogue actor can attack virtually any business that uses these RSA products - NSA (Cyber security Command) gets even more money to "Protect" us from said Rogue actors. So all-in-all good investment on their part Edit: Spelling fixed per commenter pointing out the difference between rouge and rogue. I did imply malicious actors not red-cheeked actors (not that they are mutually exclusive).
- adriand 13y agoMinor quibble (and yes I'm as outraged by this as you are) - but "rouge" means "a red powder or cream used as a cosmetic for coloring the cheeks or lips", whereas "rogue" means "a person or thing that behaves in an aberrant, faulty, or unpredictable way", which is what you mean in this comment.
- deleted 13y ago[deleted]
- emkemp 13y agoAnother quibble: A "rouge" is also a one-point scoring play unique to Canadian Football.
- mitchty 13y agoJust a side note, rouge = red, rogue = villain/scoundrel/etc... I hate being that guy but it happened twice and triggered my have to post response. Tshuß!
- waqf 13y agoJust a side note, "Tschüß!" = bye/cheers/etc; "Tshuß!" = I can't spell German. I hate being that guy but … wait, I'm lying, I love it, but I normally try to restrain myself.
- undoware 13y ago...which is why Theo Deraadt is now suddenly everyone's best friend, despite his personality. :) OpenSSH and its mother project, OpenBSD, are now all that is left of our civilization's freedom to think. Thanks, Theo, for never selling us out; for being such an uncompromising bastard; for not being like the RSA. May Athena gird you for war against the Spartans.
- RexRollman 13y agoMost of what Deraadt says makes sense and I almost always agree with him but he can be an asshole. It has turned a lot of people off, from what I can see.
- cratermoon 13y agoWe already knew back in September that this was happening. All this story adds is details about the actual contract between RSA and NSA.
- genwin 13y agoWikipedia is updated: http://en.wikipedia.org/wiki/RSA_(security_firm) http://en.wikipedia.org/wiki/RSA_(security_firm)
- SkynetSystems 13y agoKeep an eye on it, PR people from RSA will probably be all over that in the next few days.
- dergachev 13y agoIf it only cost $10m to bribe one of the biggest security companies around, how much does it cost to bribe a single open source developer who volunteers on tools like OpenSSL? What if you add blackmail to the mix? Makes me realize that we need bitcoin-style "hack or bruteforce our encryption schemes and you can legitimately get paid lots of money" bug bounties.
- pasbesoin 13y agoThis is why you want some people who are not primarily motivated by money. (Neither necessarily ascetics.) In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. (E.g. an independent researcher can actually gain access to and participate in a large and reasonably priced health insurance risk pool. And where money is not the overriding, if not sole, determination of judicial proceedings.) Going very general in my comment, security is both a community effort and a personal responsibility. The more we "outsource" our own security ("Just trust us." -- Three Letter Agencies and private contractors), the more the price goes up while the quality of the results goes down. You get the government you pay for, or... if you are more concerned about a quality, effective government, the government you participate in. Hopefully, the pendulum is beginning to swing back from "pay for" to "participate in".
- deleted 13y ago[deleted]
- morganherlocker 13y ago> In turn, why you want a society where a decent quality of life is not just obtainable but reliable without an all-consuming level of competition with others. Is financial instability really a problem for most people qualified for this type of work? I imagine most of these people are approaching or well within the 6 figure range and that accepting some sort of bribe would just be icing on top.
- judk 13y agoLuckily, open source can't include secret code. That's the point.
- summerdown2 13y agoFrom Mikko Hypponnen: https://twitter.com/mikko/status/414147944984485889 https://twitter.com/mikko/status/414147944984485889 "I'm ashamed on behalf of the whole industry."
- Nelson69 13y agoWas this money tax free? How does that sort of thing work? I hope bsafe licensees sue. Any one know of any serious efforts to replace some of the standard cipher suites in common code? AES -> Serpent, SHA -> Whirlpool etc...
- deleted 13y ago[deleted]
- babesh 13y agoIts a sad commentary on a lack of ethics in parts of the tech industry. This industry isn't leading us where we want to go.
- gress 13y agoIt is taking us towards a libertarian utopia where those with money decide where we go.
- gejjaxxita 13y agoI'm getting a "Page Not Found" message.Here's another version of the article: http://www.reuters.com/article/2013/12/20/us-usa-security-rsa-idUSBRE9BJ1C220131220 http://www.reuters.com/article/2013/12/20/us-usa-security-rs...
- RDeckard 13y agoThat did not work for me either.
- rdl 13y agoIt's going to be interesting what this does to the RSA Conference in SF 24-28 FEB; I wonder if people will pull out, or what? I'm looking at how to incorporate this as an example in my talk.
- fantasticfears 13y agoSo RSA sells its customers for $10 million, and NSA wastes $10 million.
- deleted 13y ago[deleted]
- Bud 13y agoReuters just broke this link. So here's the new one: http://www.reuters.com/article/2013/12/21/us-usa-security-rsa-idUSBRE9BJ1C220131221 http://www.reuters.com/article/2013/12/21/us-usa-security-rs...
- nnieiss 13y agoNIST, NIST, NIST.... wait, aren't those the same guys we were supposed to trust on the 9/11 commission report....
- midas007 13y agoRSA is commercially dead. There's no excuse. Also, closed-source hardware HSMs are blackboxes that are fundamentally paranoia-inducing. There's no reason to trust that the vendor, supply chain and/or manufacturers didn't backdoor them or introduce other attack surfaces. The only way to trust an implementation is decap a sample of ASICs and match features against masks you generated... from sources you trust (whether open source or yours). If it's a black box, there's no way to trust it (all modern CPUs, N/S-bridge, memory, flash (ssd), hd controllers, on and on.) Conclusion: We need more open-source hardware that is production-quality (BSD licensed)! This would be very expensive in terms of people time, but it's necessary move since corporations can't be trusted.
- blazespin 13y agoNot necessarily. Organisations which wish to cooperate with the government (and they are legion) may still consider RSA. Though one wonders if NSA advised government organisations to avoid RSA. Hmmm.
- kabdib 13y agoNot surprised. One of the security guys who worked for General Magic (GM made an early mobile OS with some security features) told me that he had a visit from the NSA. The NSA tried to get him to leak bits of the keys in the GM protocols. "Just here and there. I've got dozens of these," said one of the NSA reps. This would have been early 90s. The NSA has been doing domestic stuff like this for a long time.
- nilved 13y agoI don't know anything about RSA as a company. What does this say about RSA as an algorithm and the company's founders?
- mbrameld 13y ago> "RSA always acts in the best interest of its customers and under no circumstances does RSA design or enable any back doors in our products. Decisions about the features and functionality of RSA products are our own." This means one of two things: Either this is a blatant lie by RSA, or RSA is not competent enough to evaluate cryptograpic algorithms. Neither possibility paints them in a favorable light.
- a3n 13y ago"under no circumstances does RSA bla bla ..." "Does." Present tense. Doesn't say anything about what happened in the past. Maybe their contract even included NSA services to launder language to be plausibly deniable, since that has also emerged as one of the NSA's core competencies.
- mrobot 13y agoI remember looking over EMC's acquisitions when all of this starting breaking. EMC acquisitions just read like someone building a surveillance system: RSA, multiple deep packet inspection companies, enterprise clustered postgres, elitigation, forensics and threat analysis, Government-risk-analysis... and if you google around you'll see they kept their investments as secret as they could. https://angel.co/emc https://angel.co/emc EMC bought every single major corporate partner technology in 2009/2010. EMC is the private honeypot for the entire program. The corporate store is EMC and only EMC. EMC and EMC ventures can go to hell for building this, knowing about it, and continually profiting from it. Profit from investment in a partner of an illegal government program specifically designed to make illegal money from human rights violations should be considered illegal. All of the major money behind EMC knew what was going on. If you did a private benefit analysis, it would be all EMC. Thank you. =)
- spikels 13y agoGoodbye RSA and thanks for all monopolistic practices and shitty products. ALL CRYPTO SHOULD BE OPEN SOURCE AND PATENT FREE!
- bostik 13y agoWhen the news about DUAL_EC_DRBG first came out, RSA defended their actions of inclusion and making it a default option by stating that it was at the time a popular choice. Back then I was aghast that a noted security company would make choices based on pure hipsterism. (My apologies to all hipsters, but in this case the word is in place.) This news on the other hand makes it clear that RSA was not only being incompetent. They were being actively malicious. We've already seen anecdotes in this thread about NSA making house calls to security product vendors as far back as the 90's, so we must assume they haven't given up that venue and are still pushing their ideas, as well as pushing the vendors. With that proof comes something a lot bigger: every single security product from a US company is now suspect. By logical extension, I will say that similar paranoia should be applied to all security products from Five Eyes countries. The long-term financial fallout should be interesting material for future chroniclers.
- wgx 13y agoWhat is the likelihood that anyone will face investigation or prosecution over this?
- SkynetSystems 13y agoBetter to use log likelihood because its such a small number.
- locusm 13y ago10M sounds like a downpayment, I dont believe RSA would lay their cred on the line for such a paltry amount.
- shocks 13y agoAre my RSA PGP keypairs now compromised? How do I tell?
- notdrunkatall 13y agoHow does this affect the average consumer?
- primelens 13y agoLouis Althusser's coinage of RSA as "Repressive State Apparatus" in Lenin and Philosophy seems deliciously ironic now.
- babesh 13y agohttp://www.techweekeurope.co.uk/news/rsas-art-coviello-anonymity-enemy-privacy-130539 http://www.techweekeurope.co.uk/news/rsas-art-coviello-anony... Paid shill Want to see money flow from federal government to RSA and EMC over time.
- davidmartin 13y agoAny European citizen know what is needed for the European Commission for Competition to put a tariff to American imports so they stop destroying the European industry making undeclared and illegal subsidies?
- deleted 13y ago[deleted]
- w_t_payne 13y agoEMC own RSA. We just purchased a bunch of EMC kit. Can we trust it?