Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I say this a lot, but: there was a conspiracy theory that NSA had infiltrated the IETF during the original IPSEC standardization effort and injected the "TLS BEAST" CBC IV chaining vulnerability, which is funny because we actually know exactly how that happened (professional academic cryptographers took out a petition to get the bug fixed and were shouted down by standards body gadflies who literally rejected the premise that there was such a thing as a professional academic cryptographer). This is really easy to see once you've done an engagement on DSIG security! Standards bodies are more than capable of fucking things up entirely on their own. If anything, NSA would risk making protocols stronger by intervening in their natural processes.
 help



"Never attribute to malice what is adequately explained by stupidity". Or, in this case, design-by-committee by a bunch of people who haven't written ten lines of code in as many years. There have been several other cases where absolute no-brainer fixes, like one or two lines of code changed, to long-standing security problems, were filibustered, or blocked by WG chairs, for no explainable reason, and they can't all have been paid by the NSA to do that.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: