|
|
Log in / Subscribe / Register

Practical security for 2014

Practical security for 2014

Posted Jan 10, 2014 21:23 UTC (Fri) by raven667 (subscriber, #5198)
In reply to: Practical security for 2014 by walex
Parent article: Practical security for 2014

While its true that an absence of evidence is not _proof_ of absence it is still a datapoint which suggests absence, and a corollary is that absence of evidence is not evidence for any arbitrary theory you can think up. Absence of evidence is definitely not proof that everything is far more dire and secret than feared, that's cold war, team b thinking and it has been proven false.

> dozens of agents planted at each of the important IT companies ready to code them into those
products.

There is a significant difference between suspecting the general outlines of NSA capabilities based on the various leaks and whistleblowers over the years and suspecting anything you want based on precisely nothing. The Snowden documents have confirmed and made clear with concrete evidence what was previously only suspected and hinted at before, but it was suspected based on real data.


to post comments

Practical security for 2014

Posted Jan 10, 2014 22:55 UTC (Fri) by PaXTeam (guest, #24616) [Link] (4 responses)

> it is still a datapoint which suggests absence

no it doesn't. it does suggest someone's inability to collect said evidence though. so your corollary doesn't follow either. as for the GP, this is exactly how i'd do it and i have no reason to believe that i'm smarter than those whose daily bread and butter is to run said agencies and associated agendas.

> but it was suspected based on real data.

what real data?

Practical security for 2014

Posted Jan 11, 2014 16:05 UTC (Sat) by filipjoelsson (guest, #2622) [Link] (3 responses)

There was a Windows service pack some years ago where they forgot to remove debug symbols. One of them was for a function called "NSA_ backdoor". Does that qualify as a data point? ;-)

Practical security for 2014

Posted Jan 11, 2014 17:55 UTC (Sat) by PaXTeam (guest, #24616) [Link] (2 responses)

it qualifies as urban legend or less flatteringly, utter BS :). but you're welcome to post the pdb as evidence.

Practical security for 2014

Posted Jan 13, 2014 8:07 UTC (Mon) by filipjoelsson (guest, #2622) [Link] (1 responses)

I'm sorry to say I don't have the pdb handy. But if it's really an urban legend, you might wanna edit the Wikipedia article to that effect: http://en.wikipedia.org/wiki/NSAKEY

Oh, and I'm also sorry I got one detail wrong. According to Wikipedia, its name was _NSAKEY.

Now, Microsoft declared that they had not shared the key with the NSA, but it was still an event that aroused suspicion at the time. As such it does qualify as a data point.

Practical security for 2014

Posted Jan 13, 2014 11:35 UTC (Mon) by PaXTeam (guest, #24616) [Link]

yes i know about _NSAKEY. what you have yet to explain is what it has to do with "what was previously only suspected and hinted at before". hint: about nothing ;).


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds