The Glade 4.0
https://gladerebooted.net/

FBI backdoor'd OpenBSD's IPSEC implementation?
https://gladerebooted.net/viewtopic.php?f=8&t=5030
Page 1 of 1

Author:  Stathol [ Tue Dec 21, 2010 7:54 pm ]
Post subject:  FBI backdoor'd OpenBSD's IPSEC implementation?

Is anyone else following this train wreck?

Short version:

Former CTO of NSA consultant firm emails chief architect of OpenBSD with accusation that 10 years ago, FBI paid specific developers (by name) to subtly undermine and backdoor OpenBSD's IPSEC implementation. Hilarity and code audits ensue.

Personally, I'm leaning towards Perry being a nutjob, but still ... at the very least, his tinfoil is unusually shiny. Everyone specifically fingered has, of course, denied the allegations in their entirety. And now we've got a former FBI agent (E. J. Hilbert) tweeting in on the whole affair (tweeting, I say!). On one hand, he denies Perry's specific claims. On the other hand, well ... there's this:
Quote:
I was one of the few FBI cyber agents when the coding supposedly happened. Experiment yes. Success No.

Ugh. Somehow I'm not reassured.

But I suppose that's hardly any surprise. At the time, the three letter agencies were publicly lobbying for strong crypto software to be backdoored and/or key escrowed for spying law-enforcement purposes. That didn't work out too well for them, so I guess the rest is pretty predictable. At least he seems to be implying that OpenBSD (maybe other OSS as well?) were resistant to this kind of attack.

I swear, this is freaking _NSAKEY all over again.

Author:  Midgen [ Tue Dec 21, 2010 8:22 pm ]
Post subject: 

You sound surprised?

Author:  Arathain Kelvar [ Tue Dec 21, 2010 9:54 pm ]
Post subject: 

Stathol:

What?

Author:  Midgen [ Tue Dec 21, 2010 10:00 pm ]
Post subject: 

Someone is claiming that the FBI secretly paid developers to build a 'back door' in the protocol that the majority of encrypted VPN (Virtual Private Network) tunnels are built on, in the OpenBSD operating system.

Author:  Hannibal [ Wed Dec 22, 2010 7:50 am ]
Post subject: 

Wouldn't suprise me to be honest.

Author:  Midgen [ Fri Dec 24, 2010 10:24 pm ]
Post subject: 

It doesn't surprise me that someone made the claim.

It wouldn't surprise me if it were true (although some things about the nature of his claim make me dubious)

It wouldn't surprise me if the 'tried and failed' thing were true either...

It would surprise me if this were actually successfully implemented, and actually successfully USED by anyone ever.

Page 1 of 1 All times are UTC - 6 hours [ DST ]
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/