[146620] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] Opening Discussion: Speculation on "BULLRUN"

daemon@ATHENA.MIT.EDU (Perry E. Metzger)
Thu Sep 5 21:57:02 2013

X-Original-To: cryptography@metzdowd.com
Date: Thu, 5 Sep 2013 21:56:49 -0400
From: "Perry E. Metzger" <perry@piermont.com>
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
In-Reply-To: <E1VHlCI-0002zA-IL@login01.fos.auckland.ac.nz>
Cc: cryptography@metzdowd.com
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

On Fri, 06 Sep 2013 13:50:54 +1200 Peter Gutmann
<pgut001@cs.auckland.ac.nz> wrote:
> "Perry E. Metzger" <perry@piermont.com> writes:
> Does that make them NSA plants?  There's drafts for one or
> two more fairly basic fixes to significant problems from other
> people that get stalled forever, while the draft for adding sound
> effects to the TLS key exchange gets fast-tracked.  It's just what
> standards committees do.

Maybe. Yesterday I would have consistently ascribed things to
bureaucracy instead of malice. Today, I'm less sure. At the very
least, the current revelations make such things less benevolent --
whether from malice or stupidity, we can no longer sit on security
fixes on the basis that "no one will exploit them" and "they're not
important to the user".

Perry
-- 
Perry E. Metzger		perry@piermont.com
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post