TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

RSA warns developers not to use RSA products

132 点作者 pedro84超过 11 年前

6 条评论

lawnchair_larry超过 11 年前
Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
评论 #6420394 未加载
评论 #6420686 未加载
评论 #6420563 未加载
评论 #6420677 未加载
评论 #6421450 未加载
评论 #6420740 未加载
评论 #6420582 未加载
ChrisAntaki超过 11 年前
&gt;&gt; So why would RSA pick Dual_EC as the default? You got me. Not only is Dual_EC hilariously slow<p>Because the NSA didn&#x27;t just backdoor the Dual_EC standard. It backdoored the technology industry, as well as the rule of law.
devx超过 11 年前
The RSA CTO&#x27;s answers are hilarious. He can&#x27;t really be that clueless as the CTO of a security firm, can he?<p>That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
评论 #6420362 未加载
评论 #6420789 未加载
评论 #6420605 未加载
评论 #6420201 未加载
评论 #6420450 未加载
评论 #6420584 未加载
SimHacker超过 11 年前
Would you trust a computer security company who didn&#x27;t hash the passwords of their users on their web site, and instead stored the plain text passwords encrypted in their database, with the keys to decrypt them on their server, because they claim that &quot;Your data are encrypted on our server, if you request the password to be sent to you by email the system knows how to decrypt the information and it will send you the Email. This is for customer convenience as many customer do not wish their password to be reset each time they have a problem.&quot;<p>Would you trust a computer security company that when you reset your password on their web site, sent you a new password that was literally the same as your email address that you signed in with?<p>If this company sold closed source encryption software, would you trust that the software was competently written and did not have back doors, if the president of the company defended their actions of not hashing passwords, and of resetting passwords to their user&#x27;s email addresses?<p>What if the president of that company had been prosecuted for computer crimes in the past, and had spend time in jail for it, because after he was first caught, he went right back to phone freaking again and got caught again?<p>Would you trust the president of the company, who is a convicted felon, who fraudulently made a lot of money by computer crime and got caught, but had most of the charges dropped and his sentence reduced, not to have made a deal with the government and promise to return their favor of giving him a more lenient sentence in exchange for certain favors in the future?<p>Can anyone guess who I&#x27;m referring to?
评论 #6423064 未加载
pepve超过 11 年前
It irks me that many people are calling this a backdoor. It&#x27;s not. It&#x27;s a vulnerability. You have to exploit it to get in.
评论 #6420545 未加载
评论 #6420615 未加载
评论 #6420724 未加载
评论 #6420498 未加载
评论 #6420482 未加载
intelliot超过 11 年前
reminds me of the State Science Institute