[149042] in cryptography@c2.net mail archive
Re: [Cryptography] Boing Boing pushing an RSA Conference boycott
daemon@ATHENA.MIT.EDU (Bear)
Tue Jan 14 13:57:22 2014
X-Original-To: cryptography@metzdowd.com
From: Bear <bear@sonic.net>
To: Kent Borg <kentborg@borg.org>
Date: Tue, 14 Jan 2014 10:36:00 -0800
In-Reply-To: <52D43B89.3090101@borg.org>
Cc: "cryptography@metzdowd.com" <cryptography@metzdowd.com>,
Phillip Hallam-Baker <hallam@gmail.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com
On Mon, 2014-01-13 at 14:16 -0500, Kent Borg wrote:
> On 01/13/2014 10:23 AM, Phillip Hallam-Baker wrote:
> > Unless someone shows evidence that RSA actually knew they were being
> > punked, the boycott makes no sense.
> If we can't make selling security pay, we can maybe make selling
> insecurity cost. There are a lot of other suits watching this, seeing
> how RSA fairs. I want them to see something gruesome, something that
> worries them. (The same way I want a banker or two who nearly dumped us
> into DEPRESSION to go to jail, so others will think twice.)
I tend to agree. If RSA doesn't go down in flames over its utter
failure, then people will learn from that fact that security is a
joke industry. That's a problem we already have badly enough with
the failure after failure after failure revealed by the Snowdon
files.
I don't think that there is any real hope of building a secure
infrastructure for the world if the world learns by this example
that an industry leading security company can completely fail in
its primary mission without consequence.
That would be a vote of no confidence in the entire security
industry, like an acknowledgement that there can never be security
and there's no point in even trying.
That said, I don't think a conference boycott is specific enough.
A conference boycott hurts everyone at the conference. And most
of them have not been complicit (or merely incompetent, which is
nearly as bad) in betrayal of the public.
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography