5 ms·
Do we have a customer list of RSA? We should at least try warning them about it. Many of them probably aren't even aware of this. What banks use RSA's products?
by salient 13y ago
Do we have a customer list of RSA? We should at least try warning them about it. Many of them probably aren't even aware of this. What banks use RSA's products?
- tptacek 13y agoConservatively: all of them.
- dvanduzer 13y agoI'm far more concerned about the overlap between the name of the organization and the name of the algorithm. The political debate over "working inside the system" is certainly important to have. But the organization that makes those hardware tokens used all over the place could vanish, and it would be a minor systems integration inconvenience. The reputation hit to a fundamental algorithm is going to be confusing programmers for a long time. I don't even know how to start measuring the cost of that.
- rainsford 13y agoI think the solution to that problem should be that if a programmer doesn't understand the difference between RSA the company and RSA the algorithm or the difference between a random number generator and an asymmetric algorithm, for God's sake don't let them anywhere near any crypto code. Of course that probably won't happen since programmers who don't know what they're doing implementing crypto seems to be as popular as ever.
- dvanduzer 13y agoAhh, yes I wasn't clear enough. There are two distinct issues here. I observed more than one reaction to the original news, where a tech journalist type was clearly experiencing "reasonably informed confusion" about RSA. And then, the degree of "knowing what you're doing" is important too, because I'm pretty sure I have a better background in algebra than some professional cryptographers, but human blind spots can get pretty subtle. The difference between a PRNG and an asymmetric cipher is easy to understand. The cognitive load of associating RSA the company with RSA the algorithm (and ECDRBG the PRNG with ECC the PKI for that matter) is difficult to overcome even when you're aware of the potential bias.
- pbsd 13y agoFrom what I've seen, this whole brouhaha has done more damage to the reputation of elliptic curves than it did to the RSA algorithm.
- digisign 13y agoI don't personally have much exposure to rsa, just ssh keys and ssl certs. Are these compromised?
- willvarfar 13y agoAt first I thought your handle 'digisign' was the name of that Dutch certificate authority (DigiNotar) that got hacked last year. That would have been so funny :)
- Spooky23 13y agoForget about banks. Police, hospitals, all sorts of more impactful places.