NSA Paid RSA $10 Million to Use Flawed Security Standard

Page 2 - Seeking answers? Join the Tom's Guide community: where nearly two million members share solutions and discuss the latest tech.
Status
Not open for further replies.

Adroid

Distinguished
Jul 2, 2009
16
0
18,560
It's frustrating that not only do our tax dollars fund organizations that at the highest level have blatant disregard for the will of the majority or due process of law, but further the class action lawsuits that will continue to be filed for illegal and heinous actions of the same, which our tax dollars indefinitely go to.

America is suffering cancers of many different types. Lawbreaking within the goverment should be dealt with swiftness and finality. People within this organization should lose their jobs for this type of nonsense.

We should cut funding of the NSA and have organizations that are more closely monitored by the law abiding citizens of this country. And while Security organizations might be necessary, there is currently an imbalance of power, and a complete absence of checks and balances within these types of organizations.
 

jtd871

Distinguished
Jan 26, 2012
7
0
18,510
Anybody remember the "Total Information Awareness" goal/program of the NSA from a few years back? I do. Not surprising that they pursued it with diligence.

(Shout-out to the government analyst(s) who are reading all my posts!)
 

Vignesh Kamath

Honorable
Oct 6, 2013
1
0
10,510
It used to be "you can find GOD everywhere" but now its "you can find NSA everywhere",I think even GOD would have given some privacy to humans but NSA will never even consider it.
 
G

Guest

Guest
Oh, and what happens to innocent people after that? Nothing. They can watch my a#@ all day. I dont care about that, if there is just one plot stopped/one person not getting hurt.

No one would be on Snowdens side, if he had leaked our sub technology to china for example. Just because "you" like the information, doesn't change that he is a traitor.
 

cndg

Estimable
Feb 14, 2014
1
0
4,510
RSA was not "Duped" - they wilfully *REMOVED* their existing RNG code and **REPLACED** it with Dual_EC_DRBG. No security programmer would *EVER* do that, when the usual way of folding in new random sources is XOR (so you get the strengths of all, and the weaknesses of none).RSA knew *EXACTLY* what they were doing, and why, when they chose not to do that.Not to mention the bleeding obvious - the NSA told them to, supplied the code, paid $10M, and based it on asymmetric crypto. The *only* kind of "random" you get from elliptic curves is stuff that can be un-randomized later with the private key.How stupid do they think we are?
 
Status
Not open for further replies.