TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

RSA warns developers not to use RSA products

132 pointsby pedro84over 11 years ago

6 comments

lawnchair_larryover 11 years ago
Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
评论 #6420394 未加载
评论 #6420686 未加载
评论 #6420563 未加载
评论 #6420677 未加载
评论 #6421450 未加载
评论 #6420740 未加载
评论 #6420582 未加载
ChrisAntakiover 11 years ago
&gt;&gt; So why would RSA pick Dual_EC as the default? You got me. Not only is Dual_EC hilariously slow<p>Because the NSA didn&#x27;t just backdoor the Dual_EC standard. It backdoored the technology industry, as well as the rule of law.
devxover 11 years ago
The RSA CTO&#x27;s answers are hilarious. He can&#x27;t really be that clueless as the CTO of a security firm, can he?<p>That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
评论 #6420362 未加载
评论 #6420789 未加载
评论 #6420605 未加载
评论 #6420201 未加载
评论 #6420450 未加载
评论 #6420584 未加载
SimHackerover 11 years ago
Would you trust a computer security company who didn&#x27;t hash the passwords of their users on their web site, and instead stored the plain text passwords encrypted in their database, with the keys to decrypt them on their server, because they claim that &quot;Your data are encrypted on our server, if you request the password to be sent to you by email the system knows how to decrypt the information and it will send you the Email. This is for customer convenience as many customer do not wish their password to be reset each time they have a problem.&quot;<p>Would you trust a computer security company that when you reset your password on their web site, sent you a new password that was literally the same as your email address that you signed in with?<p>If this company sold closed source encryption software, would you trust that the software was competently written and did not have back doors, if the president of the company defended their actions of not hashing passwords, and of resetting passwords to their user&#x27;s email addresses?<p>What if the president of that company had been prosecuted for computer crimes in the past, and had spend time in jail for it, because after he was first caught, he went right back to phone freaking again and got caught again?<p>Would you trust the president of the company, who is a convicted felon, who fraudulently made a lot of money by computer crime and got caught, but had most of the charges dropped and his sentence reduced, not to have made a deal with the government and promise to return their favor of giving him a more lenient sentence in exchange for certain favors in the future?<p>Can anyone guess who I&#x27;m referring to?
评论 #6423064 未加载
pepveover 11 years ago
It irks me that many people are calling this a backdoor. It&#x27;s not. It&#x27;s a vulnerability. You have to exploit it to get in.
评论 #6420545 未加载
评论 #6420615 未加载
评论 #6420724 未加载
评论 #6420498 未加载
评论 #6420482 未加载
intelliotover 11 years ago
reminds me of the State Science Institute