[149023] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] Boing Boing pushing an RSA Conference boycott

daemon@ATHENA.MIT.EDU (Kent Borg)
Mon Jan 13 21:23:43 2014

X-Original-To: cryptography@metzdowd.com
Date: Mon, 13 Jan 2014 15:26:23 -0500
From: Kent Borg <kentborg@borg.org>
To: Phillip Hallam-Baker <hallam@gmail.com>
In-Reply-To: <CAMm+Lwg-thg92sazk8S4FpjeUDCK_Eg7f4sAQVfAJc2Bj7hgLQ@mail.gmail.com>
Cc: "cryptography@metzdowd.com" <cryptography@metzdowd.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

On 01/13/2014 02:35 PM, Phillip Hallam-Baker wrote:
> There should be a penalty, no question. But what should the penalty be?

How bad can it be?  This breach is about as bad as I can imagine. 
Someone technical at RSA must have raised an eyebrow--too bad s/he 
didn't persist more.  The most charitable guess is that management 
didn't want to know.

> We should not choose a penalty that causes collateral damage on our side.

At least not inappropriate collateral damage.  Is this one conference 
such an irreplaceable jewel that is has to continue? Could something 
better be created in the vacuum?

The name "RSA" is important here.

We have a proud example in Lavabit, and I would hope that if we saw a 
resume with Lavabit on it we would be impressed.  What will we think 
when we see a resume with RSA on it?  I think RSA should be the clear 
counter example.  Letting the RSA Conference continue with pride doesn't 
seem to underline this as firmly as I would like.

Jeeze, I feel like such an old geezer to say: "I remember when 'RSA' was 
a proud name that left me in awe!"


How important *is* this conference?  I admit I have never attended...


-kb

_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post