Re: Allegations regarding OpenBSD IPSEC

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: patrick keshishian
Date: Wednesday, December 15, 2010 - 2:01 pm

On Wed, Dec 15, 2010 at 12:36 PM, Damien Miller <djm@mindrot.org> wrote:

seriously?

# - that the OpenBSD Crypto Framework contains vulnerabilities
#   which can be exploited by an eavesdropper to recover plaintext
#   from an IPSec stream,

There is a big assumption about the alleged backdoor or
leak; i.e., that it is used to directly extract "plaintext"
out of an IPSEC stream. OK. Maybe reasonable.

# - that these vulnerabilities can be traced directly to code
#   submitted by Jason Wright and / or other developers linked
#   to Perry, and

Do they really have to be linked back to Perry? Is that
really the important factor in the alleged backdoor's
existence?

# - that the nature of these vulnerabilities is such that there
#   is reason to suspect, independently of Perry's allegations,
#   that they were inserted intentionally-for instance, if the
#   surrounding code is unnecessarily awkward or obfuscated and
#   the obvious and straightforward alternative would either not
#   be vulnerable or be immediately recognizable as vulnerable

Oh, so the alleged backdoor if present _must_ be in
the form of obfuscated code. Oooookay...


# - Finally, I pledge USD 100 to the first person to present
#   convincing evidence showing that a government agency
#   successfully planted a backdoor in a security-critical
#   portion of the Linux kernel.

So not only one has to find the alleged backdoor, but
also link its author to a "government agency" .. via
how I wonder, payroll stub, signed contract, confession?
OK, Maybe not too unreasonable, but it still gives a nice
loophole for blogger to recant on his bounty.

# - In all three cases, the vulnerability must still be present
#   and exploitable when the evidence is assembled and presented
#   to the affected parties. Allowances will be made for the
#   responsible disclosure process.

Must still exist? So proving that at some point the
alleged backdoor existed and was placed in there by
an FBI/NSA pawn isn't good enough, but the alleged
backdoor must still exist. Nice...

# - Exploitability must be demonstrated, not theorized.

Ahh... must be demonstrated. So not only you need
to show there is an alleged leak but also you must
know the means by which the NSA or FBI intended to
use the alleged leak.

But OK.
--patrick
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Allegations regarding OpenBSD IPSEC, Theo de Raadt, (Tue Dec 14, 3:24 pm)
Re: Allegations regarding OpenBSD IPSEC, Bob Beck, (Tue Dec 14, 3:52 pm)
Re: Allegations regarding OpenBSD IPSEC, Damien Miller, (Tue Dec 14, 6:30 pm)
Re: Allegations regarding OpenBSD IPSEC, Brandon Mercer, (Tue Dec 14, 8:26 pm)
Re: Allegations regarding OpenBSD IPSEC, Otto Moerbeek, (Tue Dec 14, 11:48 pm)
Re: Allegations regarding OpenBSD IPSEC, Gregory Edigarov, (Wed Dec 15, 3:20 am)
Re: Allegations regarding OpenBSD IPSEC, Brandon Mercer, (Wed Dec 15, 3:40 am)
Re: Allegations regarding OpenBSD IPSEC, Stuart Henderson, (Wed Dec 15, 3:54 am)
Re: Allegations regarding OpenBSD IPSEC, Peter N. M. Hansteen, (Wed Dec 15, 12:33 pm)
Re: Allegations regarding OpenBSD IPSEC, patrick keshishian, (Wed Dec 15, 1:25 pm)
Re: Allegations regarding OpenBSD IPSEC, Peter N. M. Hansteen, (Wed Dec 15, 1:31 pm)
Re: Allegations regarding OpenBSD IPSEC, Damien Miller, (Wed Dec 15, 1:36 pm)
Re: Allegations regarding OpenBSD IPSEC, Ted Unangst, (Wed Dec 15, 1:54 pm)
Re: Allegations regarding OpenBSD IPSEC, patrick keshishian, (Wed Dec 15, 2:01 pm)
Re: Allegations regarding OpenBSD IPSEC, Marc Espie, (Thu Dec 16, 4:30 pm)
Re: Allegations regarding OpenBSD IPSEC, Brandon Mercer, (Thu Dec 16, 5:10 pm)
Re: Allegations regarding OpenBSD IPSEC, Carson Harding, (Thu Dec 16, 7:27 pm)
Re: Allegations regarding OpenBSD IPSEC, Pawel Veselov, (Fri Dec 17, 3:25 am)
Re: Allegations regarding OpenBSD IPSEC, Kevin Chadwick, (Fri Dec 17, 4:11 am)
Re: Allegations regarding OpenBSD IPSEC, Andres Perera, (Mon Jan 3, 1:03 pm)