3 ms·
Thanks for your feedback, but please re-read my example more carefully. In my example, I talked about organizations distancing themselves from RSA (the company
by dbloom 12y ago
Thanks for your feedback, but please re-read my example more carefully.
In my example, I talked about organizations distancing themselves from RSA (the company), not the NSA (the US govt agency).
And as far as I know, no formal, independent investigation has found RSA guilty of allegations that they knowingly weakened their encryption after the NSA paid them to do so. So it doesn't meet the criteria you just mentioned.
- danso 12y agoAh, damn my misreading of initials. But to your more specific scenario...we are still talking about a much different level of evidence. OK, let's agree that RSA has not been found "guilty" by any authority. But the allegations do not come from just...well, whoever we might call the original accuser (Snowden? Greenwald?). Independent reports have alleged substantial claims and findings. For example, this is via Reuters, who is also sourcing reports to a group of academics: http://www.reuters.com/article/2014/03/31/us-usa-security-nsa-rsa-idUSBREA2U0TY20140331 http://www.reuters.com/article/2014/03/31/us-usa-security-ns... > (Reuters) - Security industry pioneer RSA adopted not just one but two encryption tools developed by the U.S. National Security Agency, greatly increasing the spy agency's ability to eavesdrop on some Internet communications, according to a team of academic researchers. Reuters reported in December that the NSA had paid RSA $10 million to make a now-discredited cryptography system the default in software used by a wide range of Internet and computer security programs. The system, called Dual Elliptic Curve, was a random number generator, but it had a deliberate flaw - or "back door" - that allowed the NSA to crack the encryption. A group of professors from Johns Hopkins, the University of Wisconsin, the University of Illinois and elsewhere now say they have discovered that a second NSA tool exacerbated the RSA software's vulnerability Even more importantly, RSA did not issue a denial (though I concede that they may have later on, I just haven't googled it yet)...they refused to comment even on the possibility that the NSA made a payment to them regarding the controversial issue. > We could have been more skeptical of NSA's intentions," RSA Chief Technologist Sam Curry told Reuters. "We trusted them because they are charged with security for the U.S. government and U.S. critical infrastructure." Curry declined to say if the government had paid RSA to incorporate Extended Random in its BSafe security kit, which also housed Dual Elliptic Curve. This is quite different than Github. Github not only commented (and took the obvious stance that harassment is wrong) on the allegations a day or so after they were public, but they have launched an independent investigation, and they have asserted that the investigation did not uncover anything for them to cop to. Now you may say that their investigation was a farce...but this, again, is where things stand until more accusers/evidence come out. And it is at this state of uncertainty that Ada Initiative has decided to take a strong position.
- dbloom 12y ago> Even more importantly, RSA did not issue a denial (though I concede that they may have later on, I just haven't googled it yet): Here is RSA's denial (emphasis added): "RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use." https://blogs.rsa.com/news-media/rsa-response/ https://blogs.rsa.com/news-media/rsa-response/ Yes, this leaves leeway for "oh, we just didn't know that they were backdooring us". But do you have proof that RSA was actually aware of the consequences of implementing the NSA's "suggestions" (and did it anyway for the $$$), and not just really naïve about it?
- danso 12y agoI'm going to re-assert that I'm not an expert on this specific issue, and so I'll just repost the EFF's reasoning: https://www.eff.org/deeplinks/2014/01/after-nsa-backdoors-security-experts-leave-rsa-conference-they-can-trust https://www.eff.org/deeplinks/2014/01/after-nsa-backdoors-se... The EFF, on its part, is not basing its stance just on the existence of intentional wrongdoing, but on what it regards as carelessness by RSA to not fix a protocol that was publicly questioned in 2007. That this protocol was questioned is not under debate. And that the protocol was flawed is also not under debate. So again, you can say, "Well how was RSA supposed to know that those Microsoft researchers were onto something? And how do you expect RSA to figure it out after just five years?" But that's a different deal than we have with Github. The only evidence we have of Github's collective wrongdoings are that Horvath felt that she had to quit. We do have (implicit) evidence that the co-founder did something wrong, because he offered his resignation. But he has made it adamantly clear that what he screwed up in had nothing to do with gender-based discrimination. Which is purportedly the issue that Ada Initiative is most incensed about. What we have now, though, is that there were clearly bad management problems at Github. And if Ada Initiative wants to boycott a company for having such internal strife, then that's their right. But that sounds about as right as someone ripping on Ada Initiative (which some did) for this incident of internal strife and miscommunication: http://en.wikipedia.org/wiki/Ada_Initiative#Violet_Blue.27s_security_presentation http://en.wikipedia.org/wiki/Ada_Initiative#Violet_Blue.27s_...
- jdp23 12y agoExcellent example!