Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Re:Get it FIPS certified (Score 1) 360

If you read the article then you'll see that the OpenBSD explicitly rejects FIPS certification as a goal.

FIPS certification is why OpenSSL includes the NSA backdoor DUAL EC pseudo random number generator. The code doesn't work but it's still included and can't be fixed. Anything which leads to an outcome like this... Disgust. Disgust and revulsion.

Comment "No evidence of abuse has been found" (Score 4, Informative) 359

Obviously LOVEINT is one example. But more details are coming out about how David Patraues was caught having an affair because of "metadata" collected by the NSA.
http://www.charlotteobserver.com/2013/06/17/4111871/metadata-helped-reveal-gen-petraeus.html#.Utlud2nfqCg

When Jill Kelley first reported getting threatening emails about Patraues, the FBI read all her emails as part of "a routine step".
http://www.nytimes.com/2014/01/06/us/from-petraeus-scandal-an-apostle-for-privacy.html

They didn't have a warrant to read her email, they just hacked into google and made a copy of everyone's email. If you report a crime to the FBI they read your email. Simple as that.

Comment Re:Sensationalist headline is Sensational (Score 1) 292

Typically these leaks are very small and are no danger to the public, which is why they are allowed to persist.

You didn't read the article. You didn't even read the summary. There were 12 which were dangerous. They reported them and the gas company had only fixed 3 of them four months later.

Comment Re:Has anybody seen the actual "evidence"? (Score 4, Insightful) 112

The wikipedia entry is good on this:

http://en.wikipedia.org/wiki/RSA_Security#NSA_backdoor

RSA has not disputed any of the facts but only argued that they did it out of ignorance. $10 million buys a lot of stupid. $10 million is peanuts for EMC but for RSA at the time, it was quite a bit.

Comment Re:The Case of the Dog That Didn't Bark (Score 1) 291

The NSA documents on this have been leaking for a while. There are ones that dealt with pushing DUAL_EC through NIST. The documents dealing with RSA are separate corroborating documents which fill in some details.

It's likely that the NSA documents on subverting OpenSSL will leak eventually. Anonymous government sources estimate that at the current rate the NSA leaks will take two more years before they have all been released.

Comment They're not denying the article really (Score 5, Interesting) 291

They're just claiming again that they assumed the NSA were good people.

This all happened in 2006. RSA adopted DUAL_EC. RSA was sold to EMC. NIST released the standard. Microsoft researchers showed the flaws in DUAL_EC. The flaws in DUAL_EC have been known since 2006, the only thing we didn't know was that they were deliberate.

Also it's interesting to note that an anonymous organization paid for the same DUAL_EC algorithm to be added to Open SSL. With Open SSL at least they didn't make it the default but it's not far off from what RSA did.
http://arstechnica.com/security/2013/12/nsas-broken-dual_ec-random-number-generator-has-a-fatal-bug-in-openssl/

Comment The US has this capability, of course (Score 1) 698

http://www.theinquirer.net/inquirer/news/2290640/germany-warns-against-using-windows-8-due-to-security-risks

You just revoke the keys and suddenly the machine can't boot.

It's funny how the NSA accuses China of inserting back doors but Snowden shows how the NSA inserts back doors. China hacks into systems but Snowden shows the NSA has hacked into tens of thousands of networks. And now the NSA is bragging about preventing a shutdown button when we already know it did the exact same thing.

Comment Re:problem is (Score 1) 841

We can be pretty sure that the NSA data gathering was a part of how General Petraeus was forced to resign.

The NSA shares its data with 11 other federal agencies such as the FBI (crime stoppers), IRS (tax collectors), DEA (drug wars). It may be that the FBI acted alone using already shared metadata information from the NSA. Or it may be that the NSA was more actively involved. If they were involved, that information would be classified.

Petraeus stood a reasonable chance of being elected president. The information was there because the NSA collected it. At a certain point it was decided to force him to resign. That decision was a political one because it has a political impact.

Submission + - Trans Pacific Partnership includes parts of SOPA

Error27 writes: Last month Wikileaks leaked a draft of the Trans Pacific Partnership treaty. Here is Congresswoman Zoe Lofgren's response to the leaked documents. She points out that there several troubling issues with the trade agreement. It locks countries into extremely long copyright terms. It limits fair use. It includes DRM provisions which would make it illegal to unlock your cell phone. These laws come from the Stop Online Piracy Act (SOPA) which Americans already rejected.

Slashdot Top Deals

Math is like love -- a simple idea but it can get complicated. -- R. Drabek

Working...