Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Ex NSA person subverting cryptography joins AWS as Director of Applied Crypto (twitter.com/matthew_d_green)
81 points by DyslexicAtheist on Feb 6, 2021 | hide | past | favorite | 4 comments


it seems a fight broke out over whether the person should have been outed, with critics calling it defamation. This feels not right. There has always been a deep distrust between those of us working in the industry wanting to innovate and create more secure products, and those who get incentivized to subvert and break this work. I'm not judging them since they're also just doing "their job".

Only difference is, they have erected the biggest surveillance state that every despote around the globe is now in a rush to emulate (or has already done so - a lot of this here is already past tense). An agency that isn't accountable to anyone within the US and even less to those outside and which gets away with breaking international laws. (because why would you follow norms if you can create your own?)

Obviously such people would be viewed as a threat. They say once burned twice shy. Only in this case the industry and the public got burned hundreds off times. When people raise concerns or hold back excitement that this person now has one of the most powerful jobs in Crypto they shouldn't be reprimanded - especially by people from the industry who should frankly know better. (or maybe the real problem is these "thought leaders" are eyeing a future for themselves where they parachute from the industry into a cushy government job or perhaps consulting position.

But this isn't about calling out this one person and have them barred from entering the industry after a stint in "public service" (even if that included illegal wiretaps and dragnet surveillance), it's about the principle that anyone from these agencies receives a welcome by the industry in the first place, and _NOT_ about an individual. It's even more sinister that people defend this move by personalizing it as if a mob were chasing a poor worker who was just trying to make a living and pay their bills like the rest of us. This isn't about culture, career, gender, "wokeness" and least of all about making "infosec more inclusive", or any other garbage people might come up with to place themselves into the conversation.


https://projectbullrun.org/dual-ec/ext-rand.html contains more information about the TLS Extended Random proposal and how it relates to the backdoored Dual EC DRBG.

Also Eric Rescorla, the other author of the Extended Random draft, is now the CTO of Firefox? He's one of the foremost experts on TLS, it'd be interesting to examine his role in this.


Rescorla's role is described here https://blog.cryptographyengineering.com/2017/12/19/the-stra... and here https://sockpuppet.org/blog/2015/08/04/is-extended-random-ma...

I would only worry about Amazon here. Like deleting your account.


Bit of a leap from "every reason to believe" to "we know who the main worker of that specific program was"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: