Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.folklore.computers > #160143

Re: Ransomware

From Stephen Sprunk <stephen@sprunk.org>
Newsgroups alt.folklore.computers
Subject Re: Ransomware
Date 2016-02-22 17:57 -0600
Organization A noiseless patient Spider
Message-ID <nag74i$8pt$1@dont-email.me> (permalink)
References (3 earlier) <6xHyy.19055$Nf2.1353@fx14.iad> <dj10mkFuav1U1@mid.individual.net> <naftt5$4a9$1@dont-email.me> <nag01s$c64$1@dont-email.me> <nag1tf$jag$1@dont-email.me>

Show all headers | View raw


On 22-Feb-16 16:27, Dave Garland wrote:
> On 2/22/2016 3:57 PM, Stephen Sprunk wrote:
>> On 22-Feb-16 15:19, Dave Garland wrote:
>>> It's not a program, but there's at least one website 
>>> https://www.random.org/ will provide a set of your very own
>>> random numbers. Their output has been certified by a number of 
>>> gaming-industry bodies, though not as far as they know by the
>>> NSA.
>> 
>> AFAIK, the NSA has neither authorization nor interest in certifying
>> such things unless the DOD wants to use them, and the NSA has its
>> own methods of generating random numbers for keys, so why would
>> they?
> 
> That bit was tongue in cheek. In any case, I'd trust the gambling 
> industry, which has a large financial stake in true randomness, long 
> before I'd trust the word of the NSA, who might well lie.

It depends, because the NSA has two very different jobs:

1. Protect the US's classified information
2. Collect others' classified information

When IBM submitted Lucifer as a candidate for DES, the NSA demanded one
mysterious but seemingly insignificant change before they would let NIST
accept it.  It wasn't until _decades_ later that the academics community
discovered differential cryptanalysis--and that the NSA's change had
made DES immune to it, whereas Lucifer wasn't.  IOW, they chose to fix
DES so it'd be harder for others to spy on us even though doing so made
it harder for them to spy on everyone else.

So, as long as the NSA is certifying things for _their_ use, I think we
can trust them--and they're smart enough to not bother saying something
is only good enough for _other_ people because anyone with a brain would
interpret that as meaning they've already broken it.

OTOH, this creates an interesting reverse attack: they can stop others
from using something they _haven't_ broken by pretending they have--and
could result in others switching to something they _have_ broken.

S

-- 
Stephen Sprunk         "God does not play dice."  --Albert Einstein
CCIE #3723         "God is an inveterate gambler, and He throws the
K5SSS        dice at every possible opportunity." --Stephen Hawking

Back to alt.folklore.computers | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-20 13:46 -0600
  Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-22 15:14 +0000
    Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-22 10:12 -0600
      Re: Ransomware "hgww" <hgww@gmail.com> - 2016-02-23 04:13 +1100
      Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-22 17:26 +0000
        Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-22 12:00 -0600
          Re: Ransomware sidd@situ.com (sidd) - 2016-02-22 13:19 -0500
          Re: Ransomware scott@slp53.sl.home (Scott Lurndal) - 2016-02-22 18:28 +0000
            Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-22 13:26 -0600
            Re: Ransomware Walter Bushell <proto@panix.com> - 2016-02-24 09:24 -0500
          Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-22 15:19 -0600
            Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 15:57 -0600
              Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-22 16:27 -0600
                Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 17:57 -0600
            Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-22 15:59 -0600
              Re: Ransomware Stephen Sprunk <stephen@sprunk.org> - 2016-02-22 20:54 -0600
                Re: Ransomware Dave Garland <dave.garland@wizinfo.com> - 2016-02-22 21:27 -0600
                Re: Ransomware Walter Bushell <proto@panix.com> - 2016-02-25 08:33 -0500
            Re: Ransomware Walter Bushell <proto@panix.com> - 2016-02-24 09:23 -0500
              Re: Ransomware "Osmium" <r124c4u102@comcast.net> - 2016-02-24 08:40 -0600

csiph-web