D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Who's using broken proprietary crypto?

 

On Sun, 22 Sep 2013, bad apple wrote:
Which luckily nobody outside the US uses, and nobody inside the US who
hasn't been leant on in someway does either.

Ah, fair enough - I'm not an expert of crypto implementations.

"Note the FIPS module is not really not appropriate for
where such use is not mandated as it does not have any technical
virtues (security, performance, maintainability) with respect to the
equivalent stock OpenSSL distributions."

Wow. Just wow.

That's almost as amazing as the bit in the NIST standard where they say: don't just choose any two points P and Q, choose the ones we provided in the appendix. We've checked and they're safe, trust us.

Martijn.


--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq