Saturday, December 28, 2013

Techie Code of Omerta For Colluding With NSA

With RSA, a big and respected name (actually initials) in cryptography, currently getting flayed in the public press for taking $10 million from the NSA and, in return, embedding a dodgy, NSA-compromised random number generator a.k.a. DUAL EC EBRG in its products (RNGs help generate encryption keys; a compromised RNG yields a limited, more crackable set of keys), a few observations:

First, as is probably recalled, the compromised character of the NSA RNG was revealed in a previous tranche of the Snowden documents in September, and an embarrassed RSA quickly issued a recommendation that users cease using that particular RNG.

Second, even back in October, there were rumblings about possible financial considerations playing a part in RSA's willingness to include the RNG in its products.  Here's a snip from a piece I wrote at the time:

[On a recent episode of Science Friday] Ira Flatow asked Philip Zimmerman [creator of the PGP open-key e-mail encryption system] why RSA would have done such a thing. There was a long, awkward silence and some awkward laughter before Zimmerman slid into the passive voice/third person zone:
ZIMMERMAN: And yet RSA did a security - did use it as their default random number generator. And they do have competent cryptographers working there. So.

FLATOW: How do you explain that?

ZIMMERMAN: Well, I'm not going to - I think I'd rather not be the one to say.

(LAUGHTER)

FLATOW: But if someone else were to say it, what would they say?

ZIMMERMAN: Well, someone else might say that maybe they were incentivized. 
Maybe Mr. Zimmerman had an advance peek at the relevant Snowden documents.  I think it more likely that he had already heard some tittle-tattle in his high tech circles but was not interested in calling down a corporate and legal sh*train upon himself by openly accusing the RSA of taking government money (interesting legal question: is it slanderous to allege that a US corporation engaged in a legal transaction with the US government?).

Third, Blame the Suits!  Per the Reuters expose:

No alarms were raised, former employees said, because the deal was handled by business leaders rather than pure technologists.

"The labs group had played a very intricate role at BSafe [the product line that was compromised by the RNG], and they were basically gone," said labs veteran Michael Wenocur, who left in 1999.

Actually, outside security analyst Bruce Schneier and others had raised serious concerns about DUAL EC EBRG in 2007 in a public forum and, as Zimmerman pointed out, RSA had competent cryptographers in the building.  DUAL EC EBRG was provided as only one option, albeit the default, and security-savvy users would be able to select another, better RNG.  And RSA cryptographers could further console themselves with the awareness that, even if Clueless Enduser kept DUAL EC EBRG as a default, probably the only entity with the message collection and analysis capability to exploit it effectively was America's own NSA.

In other words, it wasn't just RSA Chief Executive and Designated Villain Art Coviello sneaking down into the lab and inserting the lethal code while the techies obliviously shipped the compromised product.

Fourth, I think there is a growing awareness that a significant element of the Snowden story is the collusion between Big Tech and the NSA, fueled by the awareness that both sides want the same thing: a thoroughly backdoored Internet open to individual data profiling and surveillance penetration (and tolerate the resultant security breaches as cost of doing business/collateral damage).

I wonder if the story will get any more traction, since there are sizable vested economic, political, and ideological interests extending all the way to the Oval Office that are engaged in perpetuating the image of a benign, democratic/populist information order dedicated to information security.  The constituency interested in seeing Google and the other tech giants share the blame for ruining the Internet--and in the process evaporating a few hundred billion dollars of personal wealth, market cap, and stock options--is, on the other hand, powerless and vanishingly small.

Inside the tech industry, the attitude seems to be one of damage control i.e. media initiatives to convince the public that the Internet companies care about YOU and hate helping out that nasty old government.   As to the question of whether a corporate Snowden will emerge, the attitude seems to be, as Phil Zimmerman--a genuine and battered hero of the encryption wars in the 1990s--put it: "I think I'd rather not be the one to say."  Maybe the code of omerta lives on in the tech industry.

Fifth, I find it amusing and somewhat irritating that, ever since I wrote about RSA in October, I am bombarded with RSA pop-up ads on my own blog and across the web.  It's the Internet equivalent of a golden retriever that pursues me down the street driven by the irresistible urge to sniff the seat of my trousers.  Make it stop!

238 comments:

«Oldest   ‹Older   201 – 238 of 238
hubert said...

It's good work and effort for this article. This is really helpful for me in my problem solving. Thanks a lot for Sharing! You also shear it with anyone.
https://crackgive.com/chief-architect-premier-x12-crack/

crackeyfull said...

Great job this really helps me IDM Crack
Cracked Pc software
IDM crack serial number

freecrackfile said...

Many thanks for sharing this informative and interesting post with us. wintousb-enterprise-crack/

ralndo said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the

past 6 years, but I had no idea of solving some basic issues. I do not know how to

Download Cracked Pro Softwares
But thankfully, I recently visited a website named Crack Softwares Free Download
vfxAlert Pro Crack

Sony Pitter said...

I offer to visit my website. I hope you do too. I hope you like this Article.https://thepcsoft.com/driverdoc-license-key-crack-latest/

porn hub said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the

past 6 years, but I had no idea of solving some basic issues. I do not know how to

Download Cracked Pro Softwares
But thankfully, I recently visited a website named Crack Softwares Free Download
freedlcrack.com
ApowerEdit crack

ralndo said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the

past 6 years, but I had no idea of solving some basic issues. I do not know how to

Download Cracked Pro Softwares
But thankfully, I recently visited a website named Crack Softwares Free Download
BuildBox Office Crack

Crack Repack said...

I am very happy to read this article. Thanks for giving us Amazing info. Fantastic post.
Thanks For Sharing such an informative article, Im taking your feed also, Thanks.serial tweakbit pcrepairkit

Crack Repack said...



I am very happy to read this article. Thanks for giving us Amazing info. Fantastic post.
Thanks For Sharing such an informative article, Im taking your feed also, Thanks.easy video maker registration key

cracksoftwarefreedownload said...
This comment has been removed by the author.
eagle crack said...
This comment has been removed by the author.
NoorCracks said...

FlexiCam Netflix Video Downloader Crack
Driver Updater Crack
IntelliJ IDEA Download For Windows
PowerDirector Ultra Crack
DS4Windows Free Download
RescuePRO Deluxe Crack
Adobe Animate CC 2022 Crack

NoorCracks said...


Razer Cortex Game Crack

Unknown said...

TeamViewer Crack

NoorCracks said...


Auslogics Crack

Unknown said...

MHAPHILIAS

Last said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the past 2 years, but I had no idea of solving some basic issues. But thankfully, I recently visited a website named Urlcracks.com that has explained an easy way to install all All the Crack software for Windows and Mac.

MediaMonkey Gold Crack
WhatsApp For PC Crack
Comfy File Recovery Crack
Origin Pro Crack
Mosaizer XV Crack

NoorCracks said...


GA BACKPACK
GA BACKPACK
https://gabackpack.com/dr-fone-crack-2021-code/

serials bank
serials bank
SolidWorks Viewer Crack Reddit

yahao house said...

hd tune pro 5.75 full download is an HD/SSD utility that contains various functions ranging from driving performance measurements to securely erasing all data.

Last said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the past 2 years, but I had no idea of solving some basic issues. But thankfully, I recently visited a website named Urlcracks.com that has explained an easy way to install all the Crack software for Windows and Mac.

3uTools Crack
Jitbit Macro Recorder Crack
Nitro Pro Crack
Bulk Image Downloader Crack
CleanMyMac X Crack

Maya Anglou said...

Very good article! We will be linking to this particularly great post on our website. Keep up the good writing.
FontLab Studio Crack
EaseUS Data Recovery Wizard Crack
Rhinoceros 3D Crack
AnyTrans Crack
Global Mapper Crack
IM-Magic Partition Resizer Crack
Spotify Premium Crack
AutoCAD Crack
O&O Defrag Professional Crack
Auslogics BoostSpeed Crack

Maya Anglou said...

Very good article! We will be linking to this particularly great post on our website. Keep up the good writing.
REAPER Crack
IObit Malware Fighter Crack
WYSIWYG Web Builder Crack
Dr.Fone Crack
Wondershare PDFelement Crack
ActivePresenter Pro Crack
iMyFone LockWiper Crack
GlarySoft Malware Hunter Crack
LizardSystems Wi-Fi Scanner Crack
EaseUs Todo Backup Crack

Maya Anglou said...

Very good article! We will be linking to this particularly great post on our website. Keep up the good writing.
DriverMax Pro Crack
Apowesoft Screen Recorder Pro Crack
BitDefender Antivirus Free Crack
EmEditor Professional Crack
Avira Internet Security Pro Crack
Virtual DJ Crack
WinCatalog Crack
Advanced System Repair Pro Crack
Adobe Media Encoder Crack
Movavi Photo Editor Crack

Last said...

I guess I am the only one who came here to share my very own experience. Guess what!? I am using my laptop for almost the past 2 years, but I had no idea of solving some basic issues. But thankfully, I recently visited a website named Urlcracks.com that has explained an easy way to install all All the Crack software for Windows and Mac.

Notepad Crack
DxO PhotoLab Crack
FortKnox Personal Firewall Crack
Skype Crack
iSumsoft ZIP Password Refixer Crack

Hoorain Rehman said...

Very good article! We will be linking to this particularly great post on our website. Keep up the good writing.

Extreme Picture Finder Crack
Flip PDF Corporate Edition Crack
Google Chrome Crack
iDevice Manager Pro Crack
IVT BlueSoleil Crack
Typing Master Pro Crack
KeepVid Pro Crack
K-Lite Codec Pack Standard Crack
Loaris Trojan Remover Crack
Microsoft Windows ISO Downloader Crack

Hoorain Rehman said...

I like your all post. You have done really good work. Thank you for the information you provide, it helped me a lot.

Windows 10 Full
Grand Theft Auto V
Chimera Tool Premium Crack
Waves Bundle Crack
SketchUp Pro Crack
Adobe Illustrator CC Latest

Hoorain Rehman said...

I read this article! I hope you will continue to have such articles to share with everyone! thank you! You can Visit my website

Windows 10 Full
Grand Theft Auto V
Chimera Tool Premium Crack
Waves Bundle Crack
SketchUp Pro Crack
Adobe Illustrator CC Latest
Microsoft Office Pro Crack
Reallusion Character Creator Crack
Adobe Premiere Pro Crack
Autodesk AutoCAD Activation Key

SOFTWAREZ GURU said...


very informative post. I will use the suggestions discussing here for optimizing my new blog site.This post will be very helpful for the begaineer SEO worker who are new in this field.
softwarezguru.com
Sony Catalyst Production Suite Crack
Mixcraft Crack
EaseUS Partition Master Crack

SOFTWAREZ GURU said...


very informative post. I will use the suggestions discussing here for optimizing my new blog site.This post will be very helpful for the begaineer SEO worker who are new in this field.
softwarezguru.com
Ertugrul Ghazi Crack
Adobe Photoshop Lightroom CC Crack
Bandicam Crack

zawarkanju said...


hy bro thanks for the graet sharing of (keywords) i love this software thanks alot bro....
softwarekick.net
PUBG PC Crack
Driver Easy Pro Crack

k said...

Great set of tips from the master himself. Excellent ideas. Anyone wishing to take their blogging forward must read these tips.Thank you
metaverse381.com
global-ugrad

k said...

Great set of tips from the master himself. Excellent ideas. Anyone wishing to take their blogging forward must read these tips. Thank you
metaverse381.com
escape-from-tarkov

SOFTWAREZ GURU said...


very informative post. I will use the suggestions discussed here to optimize my new blog site. This post will be very helpful for beginner SEO workers who are new in this field.
softwarezguru.com
Grow Castle APK Mod Crack
Football Manager Crack

k said...

Great set of tips from the master himself. Excellent ideas. Anyone wishing to take their blogging forward must read these tips.Thank you
metaverse381.com
latest-technology-trends-2023

SOFTWAREZ GURU said...


very informative post. I will use the suggestions discussed here to optimize my new blog site. This post will be very helpful for beginner SEO workers who are new in this field.
softwarezguru.com
Output Thermal Crack
Native Instruments Kontakt Crack

ahmad said...

very informative post.I will use the suggestions discussing here for optimizing my new blog site.This post will be very helpful for the begaineer SEO worker who are new in this field.Keep posting this type of helpful post.With best wishes.
softwarezguru.com
Serato DJ Pro Crack
BurnAware Professional Premium Crack
iMazing Crack

ahmad said...

very informative post.I will use the suggestions discussing here for optimizing my new blog site.This post will be very helpful for the begaineer SEO worker who are new in this field.Keep posting this type of helpful post.With best wishes.
softwarezguru.com
Massive X Crack
Cubase Crack

Hoorain Rehman said...

Outlook Recovery Toolbox Crack
X Mirage Pro Crack
IObit Malware Fighter Pro Crack
MorphVOX Pro Crack
Wondershare Dr.Fone Crack

«Oldest ‹Older   201 – 238 of 238   Newer› Newest»