4 ms·
> Even more importantly, RSA did not issue a denial (though I concede that they may have later on, I just haven't googled it yet): Here is RSA's denial (emphas
by dbloom 12y ago
> Even more importantly, RSA did not issue a denial (though I concede that they may have later on, I just haven't googled it yet):
Here is RSA's denial (emphasis added):
"RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use."
https://blogs.rsa.com/news-media/rsa-response/ https://blogs.rsa.com/news-media/rsa-response/
Yes, this leaves leeway for "oh, we just didn't know that they were backdooring us". But do you have proof that RSA was actually aware of the consequences of implementing the NSA's "suggestions" (and did it anyway for the $$$), and not just really naïve about it?
- danso 12y agoI'm going to re-assert that I'm not an expert on this specific issue, and so I'll just repost the EFF's reasoning: https://www.eff.org/deeplinks/2014/01/after-nsa-backdoors-security-experts-leave-rsa-conference-they-can-trust https://www.eff.org/deeplinks/2014/01/after-nsa-backdoors-se... The EFF, on its part, is not basing its stance just on the existence of intentional wrongdoing, but on what it regards as carelessness by RSA to not fix a protocol that was publicly questioned in 2007. That this protocol was questioned is not under debate. And that the protocol was flawed is also not under debate. So again, you can say, "Well how was RSA supposed to know that those Microsoft researchers were onto something? And how do you expect RSA to figure it out after just five years?" But that's a different deal than we have with Github. The only evidence we have of Github's collective wrongdoings are that Horvath felt that she had to quit. We do have (implicit) evidence that the co-founder did something wrong, because he offered his resignation. But he has made it adamantly clear that what he screwed up in had nothing to do with gender-based discrimination. Which is purportedly the issue that Ada Initiative is most incensed about. What we have now, though, is that there were clearly bad management problems at Github. And if Ada Initiative wants to boycott a company for having such internal strife, then that's their right. But that sounds about as right as someone ripping on Ada Initiative (which some did) for this incident of internal strife and miscommunication: http://en.wikipedia.org/wiki/Ada_Initiative#Violet_Blue.27s_security_presentation http://en.wikipedia.org/wiki/Ada_Initiative#Violet_Blue.27s_...