5 ms·
Why we have to boycott RSA
- sneak 13y agoFrom the article: "Sadly, I haven't spoken at RSA in many years. Had I been accepted to talk this year, I'd certainly be canceling it."
- ics 13y ago> I mention this because people on Twitter are taking the stance that instead of boycotting RSA that we should attend their conference, to represent our views, to engage people in the conversation, to be "ambassadors of liberty". This is nonsense. It doesn't matter how many people you convince that what the RSA did is wrong if that doesn't change their behavior. If everyone agrees with you, but nobody boycotts RSA's products/services, then it sends the clear message to other corporations that there is no consequence to bad behavior. It sends the message to other corporations that if caught, all that happens is a lot of talk and no action. And since the motto is that "all PR is good PR", companies see this as a good thing. DO BOTH. This is the real world. People have to compromise to send a unified message. Don't refuse to help one group who shares your goals because they have a different idea of how to achieve it. If you are in a position where you can boycott and voice your opinion to their faces, do it. Maybe you're right and they don't give a shit about what you say. Who cares? Let the other people there know, and let them know that there are more of you out there.
- gpcz 13y agoIt would take too much secret coordination, but the coolest thing would be if all the world's encryption experts/academics colluded to talk at RSA's conference with seemingly-plausible topics, but then have everyone just deliver a speech on RSA's actions before leaving the podium. Then again, getting in would require writing legitimate papers that RSA could still publish in their proceedings to make the conference look successful.
- rdl 13y agoI can't imagine anyone voluntarily using any of RSA's products after the patent expired. RSA SecurID was pretty mediocre, too (acquisitions being the way of horrible companies with cash and no products). They had a huge brain drain as soon as the market picked up at all post-dotcom period, too.
- rhizome 13y agoI think it may be useful to think in terms of contract law as well, where companies looking to integrate with each other set restrictions on the security technologies that each other is allowed to use under the terms of the contract. This could cover both interoperability and end-user and admin access (e.g. SecurID).
- murphysbooks 13y agoWhat About EMC? Should they bear any of the burden or only the subsidiary? What about those companies that use RSA products and services? These are just questions. Not advocacy.
- salient 13y agoDo we have a customer list of RSA? We should at least try warning them about it. Many of them probably aren't even aware of this. What banks use RSA's products?
- tptacek 13y agoConservatively: all of them.
- dvanduzer 13y agoI'm far more concerned about the overlap between the name of the organization and the name of the algorithm. The political debate over "working inside the system" is certainly important to have. But the organization that makes those hardware tokens used all over the place could vanish, and it would be a minor systems integration inconvenience. The reputation hit to a fundamental algorithm is going to be confusing programmers for a long time. I don't even know how to start measuring the cost of that.
- rainsford 13y agoI think the solution to that problem should be that if a programmer doesn't understand the difference between RSA the company and RSA the algorithm or the difference between a random number generator and an asymmetric algorithm, for God's sake don't let them anywhere near any crypto code. Of course that probably won't happen since programmers who don't know what they're doing implementing crypto seems to be as popular as ever.
- dvanduzer 13y agoAhh, yes I wasn't clear enough. There are two distinct issues here. I observed more than one reaction to the original news, where a tech journalist type was clearly experiencing "reasonably informed confusion" about RSA. And then, the degree of "knowing what you're doing" is important too, because I'm pretty sure I have a better background in algebra than some professional cryptographers, but human blind spots can get pretty subtle. The difference between a PRNG and an asymmetric cipher is easy to understand. The cognitive load of associating RSA the company with RSA the algorithm (and ECDRBG the PRNG with ECC the PKI for that matter) is difficult to overcome even when you're aware of the potential bias.
- cpt1138 13y agoVia this logic, shouldn't we boycott Yahoo, Google, and Facebook too?
- tptacek 13y agoWhy would you boycott companies that spent millions of dollars fighting NSA because of an allegation that another company took millions of dollars to hep NSA?
- cpt1138 13y agoWell these companies are giving information to the NSA one way or another. Its a slippery slope argument, but anyone that doesn't refuse to give up the information e.g. Lavabit is complicit in aiding the NSA. Whether they get paid for it or not seems irrelevant.
- ars_technician 13y agoGoogle inexplicably shutting down isn't a realistic option though. The damage to society in unusable email, Android phones, etc would be far worse.
- notacryptwizard 13y agoI think that a reasonable person would consider {Apple, Google, Lavabit, ...} receiving a National Security Letter coercion, and therefore not "complicit". "Complicit" would be Verizon or AT&T, who to this day still sell phone call metadata to the NSA.
- Zigurd 13y agoThose companies appear to be hoping the NSA toothpaste goes back in the tube. It won't. Until they deliver open source client software that uses end-user-controlled strong encryption, they are not making their users secure. But that means putting their users out of the reach of law enforcement, too, and they are scared to do that. They need to face the choice: Enable real privacy, or lose your customers.
- oroup 13y agoI'd go further. I think there needs to be a class action suit brought by customers who purchased a security solution and got snake oil. I'm sure the RSA license limits liability but I think there's a case to be made that this isn't just negligence but willful criminal acts and the limitations should be set aside. The case itself would probably be pretty damaging ("Tell us, what did you think the $10m was buying?"). I think RSA would go pretty far to avoid a trial.
- us0r 13y agohttps://www.eff.org/files/filenode/20111229_9C_Hepting_Opinion.pdf https://www.eff.org/files/filenode/20111229_9C_Hepting_Opini... "II. The 2008 Amendments to the FISA While the underlying actions were pending in district court, and partially in response to these suits, Congress enacted the FISA Amendments Act of 2008, Pub. L. No. 110-261, 122 Stat. 2435, codified at 50 U.S.C. § 1885a. Among the amendments is § 802, an immunity provision and related procedures that are triggered if the United States Attorney General certifies to one or more of five conditions. In such case, no civil action may be maintained “against any person for providing assistance to an element of the intelligence community.” § 802(a)." This to me says such an action would not even get off the ground let alone them having to answer the "what did you think the $10m was buying" question.
- rhizome 13y agoYou should also paste the five conditions for completeness: 1. any assistance by that person was provided pursuant to an order of the court established under section 103(a) directing such assistance; 2. any assistance by that person was provided pursuant to a certification in writing under section 2511(2)(a)(ii)(B) or 2709(b) of title 18, United States Code; 3. any assistance by that person was provided pursuant to a directive under section 102(a)(4), 105B(e), as added by section 2 of the Protect America Act of 2007 (Public Law 110–55), or 702(h) directing such assistance; 4. in the case of a covered civil action, the assistance alleged to have been provided by the electronic communication service provider was— A) in connection with an intelligence activity involving communications that was— i) authorized by the President during the period beginning on September 11, 2001, and ending on January 17, 2007; and ii) designed to detect or prevent a terrorist attack, or activities in preparation for a terrorist attack, against the United States; and B) the subject of a written request or directive, or a series of written requests or directives, from the Attorney General or the head of an element of the intelligence community (or the deputy of such person) to the electronic communication service provider indicating that the activity was— i) authorized by the President; and ii) determined to be lawful; or 5. the person did not provide the alleged assistance.
- fintler 13y agoRSA is a subsidiary of EMC. This means that a boycott of Greenplum, Pivotal, VMWare, Isilon, Mozy, and MANY others would probably be included. I just don't see an effective boycott of this scale happening -- especially when most of their customers just care about the product cost and benefit. Also, it can probably be argued that trying to secure your systems against a targeted intrusion from the NSA using technical means is pointless and a waste of money (throwing money at the EFF might be more effective). Having said that, is there an good alternative to SecureID? The only thing that seems to come close is CRYPTOCard, but it looks like they have closer ties with the NSA than RSA does. A yubikey also looks nice, but I don't like how it needs to be plugged in as a keyboard -- a device that is kept physically separated from the login machine would be ideal. OTP apps on a multi-purpose device (mobile phone) also isn't something I consider to be secure.
- ZoFreX 13y agoIn terms of effectiveness: Boycotting all EMC subsidiaries > boycotting just RSA > doing nothing Nothing wrong with keeping it small scale and only boycotting RSA, if the alternative is doing nothing at all.
- ballard 13y agoMy bad, the parent comment's logic contains multiple fallacies: False dichotomy of a slippery slope all-or-nothing boycott with the all option there is another false dichotomy of "limited alternatives." Sounds like rationalization BS for doing nothing to me. If the options were so "limited," why isn't there more crowdfunding of open source hardware &| software security modules?
- fintler 13y agoSince you feel there are other alternatives, do you know of any hardware tokens that haven't been influenced by the NSA? A device with a broken usage model (USB or writable SmartCard interface) isn't acceptable since it defeats the entire purpose of using it in the first place.
- eliteraspberrie 13y agoA boycott is symbolic, and that is important. But I doubt it will be effective in changing their corporate priorities. RSA makes its money from government contracts, or from other government contractors, not from privacy-minded individuals like us. Instead, I propose that it be unlawful for companies which have been thoroughly hacked to bid on government cybersecurity contracts, at least for some period of time. After the SecurID hack, RSA should have been blacklisted for, say, a year. BSAFE should not be anywhere near a government or defence network. PS: The analogy to Vichy France isn't great. It was not a matter of French technocrats collaborating just to save their jobs; it was real counter-revolutionaries fighting to bring down the Third Republic from within.
- us0r 13y ago"In some cases the companies had no choice (Verizon)" This is how wrong so many people are. Verizon's CEO has flat out said "they are our largest customer" (i.e - go fuck yourself).
- kerkeslager 13y agoBranding this as a boycott implies that this is an expression of protest, that this is a moral issue. I agree that it is, but a lot of people don't. The morality of the NSA, and of cooperating with the NSA, is a matter of national debate. However, it is not a matter of debate that the RSA backdoor of BSAFE was and is not open merely to the NSA. It is an objective fact that anyone can take advantage of a backdoor like this. As such, even if you think that the NSA is right, even if you think that cooperating with the NSA is correct, this is not the way to do it. It might make business sense to do business with a security company that cooperates with the NSA. It does not make business sense to do business with a security company which is proven to produce vulnerable software. Whether or not it's an ethical problem is subjective. The fact that it's a business problem is objective. This comment misses the mark: > Also, it can probably be argued that trying to secure your systems against a targeted intrusion from the NSA using technical means is pointless and a waste of money The BSAFE backdoor does not simply make companies vulnerable to targeted intrusion from the NSA. It makes every technology which uses Dual EC_DRBG vulnerable to any hacker who knows how to use the vulnerability. This is a pseudorandom number generator, which means that it affects almost every primitive cryptographic operation. A company which would introduce such a vulnerability for the NSA may or may not be an ethical company, but it certainly is not a company qualified to provide security. EDIT: It looks like I messed up my understanding of the way in which Dual_EC_DRBG was broken. See the responses to my post for details.
- kzrdude 13y agoYes. RSA should lose customers because RSA didn't do their job properly -- they didn't select algorithms that were in their customers' best interest, despite all the facts being in the open.
- notacryptwizard 13y ago> vulnerable to any hacker who knows how to use the vulnerability I must have missed this part of the news cycle. Can you explain how anyone other than the NSA can take advantage of Dual EC_DRBG? Did P and Q or whatever it was get leaked as well?
- 13y ago
- puppetmaster3 13y ago+1. 411 - http://rsaconference.com http://rsaconference.com
- jmspring 13y agoI initially read this as boycotting RSA products like BSAFE, rather than the conference. Aside from their secure ID products, do people use many RSA products?