[148600] in cryptography@c2.net mail archive
Re: [Cryptography] how reliably do audits spot backdoors? (was: Re:
daemon@ATHENA.MIT.EDU (Bill Frantz)
Sun Dec 22 21:34:45 2013
X-Original-To: cryptography@metzdowd.com
Date: Sun, 22 Dec 2013 18:27:09 -0800
From: Bill Frantz <frantz@pwpconsult.com>
To: cryptography@metzdowd.com
In-Reply-To: <alpine.BSO.2.03.1312221639590.23573@astro.indiana.edu>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com
U2VlIDxodHRwOi8vemVzdHkuY2EvcHVicy95ZWUtcGhkLnBkZj4gQnVpbGRpbmcgUmVsaWFibGUg
Vm90aW5nIApNYWNoaW5lIFNvZnR3YXJlCgogICAgS2EtUGluZyBZZWUKCkEgZGlzc2VydGF0aW9u
IHN1Ym1pdHRlZCB0byB0aGUgR3JhZHVhdGUgRGl2aXNpb24Kb2YgdGhlIFVuaXZlcnNpdHkgb2Yg
Q2FsaWZvcm5pYSwgQmVya2VsZXkKaW4gcGFydGlhbCBmdWxmaWxsbWVudCBvZiB0aGUgcmVxdWly
ZW1lbnRzIGZvciB0aGUgZGVncmVlIG9mCkRvY3RvciBvZiBQaGlsb3NvcGh5IGluIENvbXB1dGVy
IFNjaWVuY2UKCnAxMzZmZiBmb3IgYW4gZXhwZXJpbWVudCB3aGVyZSByZXZpZXdlcnMgYXR0ZW1w
dGVkIHRvIGZpbmQgdGhyZWUgCmJ1Z3MgdGhhdCBoYWQgYmVlbiBpbnNlcnRlZCBpbiBzb21lIHZv
dGluZyBtYWNoaW5lIGNvZGUuCgpUaGUgcmVzdWx0cyB3ZXJlIChwMTQ4KToKCiJEYXZpZCBXYWdu
ZXIgYW5kIEkgZGVjaWRlZCB0byBpbnNlcnQgdGhyZWUgYnVncyBpbnRvIFB2b3RlIHRvCnNlZSBp
ZiB0aGUgcmV2aWV3ZXJzIHdvdWxkIGZpbmQgdGhlbS4gV2UgaW5zZXJ0ZWQgd2hhdCB3ZQp0aG91
Z2h0IHdvdWxkIGJlIGFuIOKAnGVhc3nigJ0gYnVnLCBhIOKAnG1lZGl1beKAnSBidWcsIGFuZCBh
IOKAnGhhcmQKYnVn4oCdIHRvIGZpbmQsIGFuZCBjaG9zZSBlYWNoIGJ1ZyBpbmRpdmlkdWFsbHkg
aW4gc3VjaCBhIHdheSB0aGF0CmFuIGluc2lkZXIgY291bGQgY29uY2VpdmFibHkgZXhwbG9pdCB0
aGUgYnVnIHRvIGluZmx1ZW5jZSB0aGUKcmVzdWx0cyBvZiBhbiBlbGVjdGlvbi4gVGhlc2UgYnVn
cyBhcmUgZGV0YWlsZWQgaW4gQXBwZW5kaXgKRS4KCldlIGRlY2lkZWQgdG8gaW5zZXJ0IGFsbCBv
ZiB0aGVzZSBidWdzIGluIGEgMTAwLWxpbmUgcmVnaW9uIG9mCmEgc2luZ2xlIGZpbGUsIGxpbmVz
IDExIHRvIDEwOSBvZiBOYXZpZ2F0b3IucHksIGFuZCB0b2xkIHRoZQpyZXZpZXdlcnMgdG8gbG9v
ayBpbiB0aGlzIHJlZ2lvbi4gV2UgZGlkIHRoaXMgYm90aCBiZWNhdXNlIHRoZQpuYXZpZ2F0b3Ig
d2FzIHRoZSBtb3N0IGludGVyZXN0aW5nIGluIHRlcm1zIG9mIHRoZSBwcm9ncmFtCmxvZ2ljIGFu
ZCBiZWNhdXNlIHdlIGtuZXcgdGhlIHJldmlld2VycyB3b3VsZCBoYXZlIGxpbWl0ZWQKdGltZS4g
VGhlIG5ldyB2ZXJzaW9uIG9mIHRoZSBjb2RlIHRoYXQgd2UgZ2F2ZSB0aGUgcmV2aWV3ZXJzCmNv
bnRhaW5lZCBhbGwgdGhyZWUgYnVncywgYnV0IHdlIGRpZCBub3QgdGVsbCB0aGUgcmV2aWV3ZXJz
IGhvdwptYW55IGJ1Z3MgdGhlcmUgd2VyZS4KCllvc2hpIEtvaG5vLCBNYXJrIE1pbGxlciwgYW5k
IERhbiBTYW5kbGVyIHBhcnRpY2lwYXRlZCBhcwpyZXZpZXdlcnMgb24gdGhlIHRoaXJkIGRheSBv
ZiB0aGUgcmV2aWV3LiBEYW4gd2FzIHZlcnkgZmFtaWxpYXIKd2l0aCBQeXRob24gYW5kIGZvdW5k
IHRoZSDigJxlYXN54oCdIGFuZCDigJxtZWRpdW3igJ0gYnVncyBxdWlja2x5LAp3aXRoaW4gYWJv
dXQgNzAgbWludXRlcy4gWW9zaGkgS29obm8gYW5kIE1hcmsgTWlsbGVyIGZvdW5kCnRoZSDigJxl
YXN54oCdIGJ1ZyBhZnRlciBhYm91dCBmb3VyIGhvdXJzIG9mIHJldmlld2luZy4gTm9uZSBvZiB0
aGUKcmV2aWV3ZXJzIGZvdW5kIHRoZSDigJxoYXJk4oCdIGJ1ZwoKSWFuIEdvbGRiZXJnIGFuZCBZ
b3NoaSBLb2hubyBwYXJ0aWNpcGF0ZWQgYXMgcmV2aWV3ZXJzIG9uCnRoZSBmb3VydGggZGF5IG9m
IHRoZSByZXZpZXcuIElhbiBHb2xkYmVyZyBhbHNvIGZvdW5kIHRoZSDigJxlYXN54oCdCmJ1ZyB3
aXRoaW4gYWJvdXQgdHdvIGhvdXJzOyBub25lIG9mIHRoZSBvdGhlciBidWdzIHdlcmUgZm91bmQK
b24gdGhlIGZvdXJ0aCBkYXkuCgpUaGUgcmV2aWV3ZXJzIHNwZW50IGEgdG90YWwgb2YgYWJvdXQg
MjAgcmV2aWV3ZXItaG91cnMKZm9jdXNlZCBvbiB0aGUgdGFzayBvZiBmaW5kaW5nIHRoZSBidWdz
IGluIHRoaXMgMTAwLWxpbmUgc2VjdGlvbgpvZiBOYXZpZ2F0b3IucHkuCgpDaGVlcnMgLSBCaWxs
CgotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t
LS0tLS0tLS0tLS0tLS0tLQpCaWxsIEZyYW50eiAgICAgICAgfCBTaW5jZSB0aGUgSUJNIFNlbGVj
dHJpYywga2V5Ym9hcmRzIGhhdmUgZ290dGVuCjQwOC0zNTYtODUwNiAgICAgICB8IHN0ZWFkaWx5
IHdvcnNlLiBOb3cgd2UgaGF2ZSB0b3VjaHNjcmVlbiBrZXlib2FyZHMuCnd3dy5wd3Bjb25zdWx0
LmNvbSB8IENhbiB3ZSBtYWtlIHNvbWV0aGluZyBldmVuIHdvcnNlPwoKX19fX19fX19fX19fX19f
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVGhlIGNyeXB0b2dyYXBoeSBtYWlsaW5n
IGxpc3QKY3J5cHRvZ3JhcGh5QG1ldHpkb3dkLmNvbQpodHRwOi8vd3d3Lm1ldHpkb3dkLmNvbS9t
YWlsbWFuL2xpc3RpbmZvL2NyeXB0b2dyYXBoeQ==