Re: [Nolug] alleged FBI backdoor in OpenBSD crypto code

From: Mark A. Hershberger <mah_at_everybody.org>
Date: Wed, 15 Dec 2010 13:57:39 -0500
Message-ID: <87fwtylv8c.fsf@everybody.org>

Alex Levy <mrbones102@gmail.com> writes:

> Wait wouldn't such a code have been brought to light years ago? Being that
> the program(s) are/is open source, you have access to the source code right?
> So know one was like "hey what the hell is this extra stuff in here?"

Sure, if they were sending the decrypted stream to some fixed address.

However, as others in the thread noted (see
http://marc.info/?l=openbsd-tech&m=129237675106730&w=2), it would be
possible (and bugs like this have occurred in the past) to enable a
third party to snoop on the IPSec traffic and use embedded information
to decode it.

Mark.

-- 
http://hexmode.com/
War begins by calling for the annihilation of the Other,
    but ends ultimately in self-annihilation.
___________________
Nolug mailing list
nolug@nolug.org
Received on 12/15/10

This archive was generated by hypermail 2.2.0 : 12/15/10 EST