HN user

woodman

1,585 karma
Posts0
Comments810
View on HN
No posts found.

Evidence of the NSAKEY being a backdoor includes some description of how the backdoor might work...

It would only work one way with an API relying on a PKI with a single CA, zero transparency, and trusted keys named after spy agencies suddenly appearing out of nowhere. I'm gonna bail here, because I'm now not sure if you honestly don't know what the CAPI was in relation to the NSAKEY - or if you're trying to waste my time by getting me to explain the most basic principles of public key infrastructure.

The entirety of the NSAKEY evidence is "it has NSA in the name."

Your comparison is out of line because of ridiculous characterizations like this. Microsoft said that it was a backup key, which either means that they have the most poorly implemented scheme for backing up cryptographic materials ever devised, or they don't mean what most people think when they hear the word "backup". Microsoft then claimed that the backup was necessary for passing the export control review, which is a bold lie to tell since the Export Administration Regulations are available for review to everybody. One thing not included in the EAR that might influence Microsoft's conduct in trying to get permission from the USG to reach global customers: executive orders. The government had a hard limit at 56-bits and was proposing that anybody wanting to export crypto beyond that needed to participate in their push for private-key escrow, which they were calling "key-recovery". Recovery... sounds kind of like a backup plan...

I provided links in my response to the parent comment.

The demand for evidence in the wake of all the NSA leaks is laughable.[0] What does evidence of the NSAKEY being a backdoor look like to you, a provably malicious CSA shim, signed by the key, hand delivered by James Clapper?

I'll tell you what it looks like to me:

After the debug symbol is found, Microsoft gives a seemingly very stupid explanation for it[1]: "It is a backup key. Yeah, uhhhh... during the export control review - the NSA said that we had to have a backup key, so we named it after them..." After being challenged on the plausibility of their backup scheme they refuse to provide any further explanation.

Here is the funny part: Microsoft might be technically telling the truth about it being a "backup". Consider what else was going on around this period: ridiculous export controls on key-length, the clipper chip... and finally: government managed private-key escrow[2]. At that time the export regulations did not specify a backup requirement, and yet Microsoft claims otherwise. You know who else was talking a lot about backups? The Whitehouse, in its proposal for allowing the export of key-lengths above 56-bits - so long as applicants implement "key-recovery".[3] Somehow I don't think that we share the same definition of the word "backup".

Also, ECI Sentry Raven[4], have fun with that.

[0] https://assets.documentcloud.org/documents/784280/sigint-ena...

[1] https://cryptome.org/nsakey-ms-dc.htm

[2] https://web.archive.org/web/20000818204903/https://csrc.nist...

[3] https://epic.org/crypto/key_escrow/key_recovery.html

[4] https://archive.org/details/nsa-sentry-eagle-the-intercept-1...

It was a debugging symbol that a Microsoft developer either negligently or heroically included in a public release... so that explains away the "nobody would be so stupid" argument. You are aware of how the Intel ME killswitch was located right? A commented xml file included with the flashing software helpfully informed anybody willing to look that a field was related to the NSA's High Assurance Platform program. This was after ten years of security researchers pointing at the fact that this was a backdoor. For whatever reason both Intel and the NSA were happy to let the public remain needlessly vulnerable all that time... But yeah, I'm just like one of those water fluoridation loons. The NSA wasn't at all hamfisted in the intentional weakening of elliptic curves and blatant RSA bribery, this isn't an obvious pattern emerging.

This is one of those situations that makes me wonder at how obvious the right way to go is, and how unlikely that is to happen. Offense/defense costs are not even close to being symmetrical, it is insane that the USG would advance the state of the art in electronic warfare - while not even pretending to try and match the effort in defense. This is why we abandoned our biological weapons program, we were effectively developing the technology for incredibly cheap weapons of mass destruction that any banana republic could mimic... not unlike the rootkit leaks.

This, unfortunately, occurs so infrequently that it can safely be ignored by 99.9% of the economy. Businesses have really enjoyed having their cake and eating it too with the transition away from a highly involved acquisition process that generally resulted in a tailored solution that the USG owned, to the present COTS policy that allows them to then go on to sell software to people that have already effectively paid for it through taxes. While there was an impressive amount of bureaucracy and an infinitely self referential system of standards in the old method, it did lead to some pretty interesting side effects: Ada[0], IDEF[1], MIL-STD-498[2], etc.

The most recent liberation of useful taxpayer funded software that I can think of was over ten years ago, when NIST released NFIS2 - the fingerprint software that the FBI relied on. They of course had to be crappy about it and wrap it in export controls that limited its utility, but it was interesting to see all the work that internal development had done - very polished, with man pages going back to '97. Ah the memories: software classified as munitions, the clipper chip...

[0] http://archive.adaic.com/pol-hist/policy/naig94-1.txt

[1] https://en.wikipedia.org/wiki/IDEF#The_IDEF_modeling_languag...

[2] https://en.wikipedia.org/wiki/MIL-STD-498

[3] https://web.archive.org/web/20041206072946/http://fingerprin...

> "If every investor..."

This is already a thing, and it is starting to look like an incredibly bad idea. Well over a year ago I had lunch with my financial advisor and he tried to sell me on a portfolio balanced on some kind of social responsibility metric (female board member ratio, carbon credits, etc). At the time I thought it was just a new way to separate morons from their money, but now I'm starting to think that the US markets are setting themselves up for a fungibility attack. I remember, many years ago, the debate on bitcoin tainting - keeping a register of illegally obtained coins (and leaf transactions) and refusing to accept them. That is obviously an attack on the utility of the currency - a unit of value.

So what is the metric here, what is the new unit of value? The best case outcome is a Tower of Babel pandemonium, worst case is an irreversible further consolidation of kingmaking power.

Google "Richard Prince copyright". This is not a new issue, not even close.

BTW... She is using a still[0] from a video that CNN owns the copyright to, and section 3 of their tos[1] explicitly forbids doing what she is doing - with the unnecessarily stated exception "as otherwise expressly permitted under copyright law". You really want to take that exception away from her? I can pretty easily argue that her use is transformative, can you? How does this differ from what she is complaining about?

[0] http://www.erynnbrook.com/white-feelings-for-charlottesville... [1] https://www.cnn.com/terms

ctrl+f 'transformative'... No matches.

I'm surprised by the sympathy I'm seeing for this position. You people know that she is effectively complaining about fair use, right? This is not something that can be budged on, even in deference to the feelings of a "writer/feminist/educator". Fair use is the only thing that stands between us and massive intellectual property cartels guiding the public consciousness through selective enforcement. Wanna go back to network television? Because this is how you do it.

I'm curious, how are you defining "the like"? The list of people denied service looks a lot more like those you wouldn't want preceding your Coca-Cola ad buy. Why would Patreon care? Because payment networks care.

   8chan
   Encyclopedia Dramatica
   BitChute
If you expand the scope beyond Patreon and include Paypal then you can throw in:
   Wikileaks
   Numerous Antifa chapters
   World Socialist Web Site
As somebody who has been involved with bitcoin since 2012, I can tell you from first hand experience that when Visa declares you a persona non grata - a large number of businesses quickly do the same. Yes, the full list of Patreon service denials includes a lot of unsympathetic figures - but you'd be a fool to think that this behavior doesn't shift with the Overton window (welcome back to the world of crypto currency, Dwolla, betcha feel silly for screwing up that perfect opportunity Paypal gave you).

I'd say the former, but it really doesn't matter - the point is the subjectivity of collective "good" and "correctness". Also, a lot of people are under the impression that these things are numerically based - the democratic tyranny of the majority... this is not the case. We see the same thing play out in the slow failure of competing interest to guard against lobbyist abuse, it is an issue of motivation - not quantity or legitimacy.

Ouch, feeding probabilistic models training data scored with a gradient of truthfulness tags generated by humans and all their biases... surely this won't end horribly and simply serve as a method to algorithmically institute the tyranny of the majority.

If you really want to do this (You really don't, I assure you - you'll hate the end result), you've got to reach back through the AI winter and drag the granddaddy of NLP, propositional logic, into modern AI development. We'll see this employed by lawyers long before journalists.

https://en.wikipedia.org/wiki/Attempto_Controlled_English

I think you're right about the lack of power being the biggest contributor to the problems we had - which remained even after they tried to reduce the feature set (emergency magazine-well, user selectable gas tube aperture).

I think it was a poor idea in the first place to push a beltfed machinegun down to the fireteam level. People generally have a misconception about what machineguns are for - while volume of fire certainly figures into effective suppression, accuracy is more important. An effectively employed machinegun should be treated like some kind of sniper shotgun, where you can put 50% of your shots into a vehicle sized target a mile away. You aren't going to be doing that while playing the I'm-up-he-sees-me-I'm-down game.

Hopefully it gets better with time for you. My complaint wasn't with pain, but numbness. I developed this problem very early on, in SOI, and kept it to myself because I knew that it would get me medically discharged. Thankfully I never had to explain to anyone why I'd go to the lengths I did in order to avoid handling grenades. After 2 years of civilian life my knees and lower back stopped bothering me, but 15 years later: my hands still feel like they're falling asleep.

It sounds like you never got to use the original SAW barrel. We got issued those stubby paratrooper barrels while in Iraq, which are nice for maneuverability, but it was at the cost of accuracy. The M249 was always a piece of junk when it came to reliability, which is why weapons guys are there with 240s.

So long as the tempo is kept up for flanking maneuvers, and everybody doesn't try to establish a fixing base of fire simultaneously, it sounds like a warrant officer had a really good idea in returning to something resembling the WWII pacific loadout (minus the flamethrowers).

I disagree. The USMC doctrine on this matter has remained the same for generations, so that doesn't explain the increasing loadout. Also, and I don't know what the official Army guidance is on matter, but we took over an AO where an Army unit had previously been responsible. They regularly got ambushed, and regularly broke contact.

One development that I heard about a couple of years ago, which should certainly ease the burden, is that the Corps dropped the M249 in favor of a heavy barrelled M16. That is a lot less weight, considering how every fireteam had previously been equipped with a belt fed machinegun (5.56, but still).

For a long time I was pretty irritated about landing in a line company instead of a mounted weapons company... but after a combat tour, where the majority of KIA was from roadside IEDs, I didn't mind walking so much. The loadout did get more and more ridiculous though - after some officer got shot in the heart through his armpit, we all got issued side SAPIs that added weight, interfered with room clearing mobility, and cut off circulation in our arms. Backpacker syndrome [0] was also pretty common.

[0] https://en.wikipedia.org/wiki/Brachial_plexus_injury

I actually wrote an essay that dug pretty deep into this topic, many years ago, after I finished my enlistment as a Marine infantry machinegunner - likely the most overburdened MOS. I'm surprised this didn't get a mention in the article, especially considering the latest developments: women in combat roles. The significant difference between male and female upper body strength is going to be impossible to ignore under combat loads.

In WWII they leaned on understanding from British occupations across the world.

Nah. The Corps has had plenty of opportunity to acquire the experience organically:

"During about 85 of the last 100 years, the Marine Corps has been engaged in small wars in different parts of the world." --Small Wars Manual (1940 Edition)

Running through the list of the Corps' most revered heroes... I can't think of a single one that didn't face an enemy that employed guerilla warfare tactics. Chesty Puller started out fighting an insurgency in Haiti and then Nicaragua. Before that SgtMaj Daly fought in the Boxer Rebellion. Smedley Butler fought Cuban insurgents in the Spanish–American War (later writing "War Is a Racket"). Archibald Henderson fought in the Seminole Wars...

The Corps has more experience with asymmetric warfare than the stereotypical military campaign. It also has a very long institutional memory where best practices are developed and passed down - I don't remember ever hearing somebody cite British colonialism during a period of instruction, we had our own colonialism to refer back to: the banana wars.

Where, in the Netherlands? I can't think of a way to say this that doesn't sound rude, so I'll just say it: how informed is your opinion? Roughly how big a company are we talking? Have you managed security, or managed security managers?

I ask because a long time ago I worked at a multinational that had facilities all over Europe. I'd have remembered if we got pushback from local management on this matter, but then I suppose they always could have been lying about their security programs... there isn't really a good way to audit law enforcement outreach - until something goes wrong.

You would be surprised how much effort businesses put into building a relationship with local police, that is a big part of a security director's job. The more people they have on site, or the higher their inventory value, the more they are willing to spend on the local PD. I've seen areas built on company property that are effectively police sub-stations, giving cops a place to do paperwork and take a break, in order to cheaply keep them nearby. I've seen off duty cops hired for show up jobs, just to guarantee timely incident response. I've seen local PDs negotiate a fee schedule... it ain't a bribe if there is a "fee schedule". No, companies aren't doing this in order to break strikes or otherwise oppress employees - there is just a ton of risk when you concentrate hundreds of people in a small place that you're legally responsible for. I have seen some interesting results come out of it though: one holiday night a copper thief got onto the facility roof to plunder the AC units, one call from the off duty officer resulted in the immediate dispatch of a police helicopter and nearly a dozen cruisers. This is from an American perspective, but I'd be surprised if it was different anywhere else in the world.

Where do I do that?

"I assume 'diversity of thought' refers to expressed thoughts..."

First, I am struggling over how to identify 'diversity of thought' during the interview process.

I think we've covered this pretty well, so your struggle isn't over the "how" - but the "why".

Is it something different than "can come up with innovative solutions" or "out of the box thinking" or "creative problem solver"?

It is no different, with one exception: it is measured in relation to your existing organization. If all your programmers are proponents of the functional programming paradigm, hiring another Haskell programmer, while relatively novel to the rest of the industry - likely does little to increase your organizations diversity in thinking (without additional screening parameters).

These seem like two different interpretations of that phrase...

They are: one is selecting for proxies, presumably as a shortcut. The other is directly addressing what is desired. I'm always amazed at how proponents for such selection mechanisms are totally oblivious to how ridiculously prejudice it is.

...I lean towards ubernostrum's down-voted comment that "diversity of thought" seems often used as a euphemism for "put up with assholes" (my interpretation).

Clearly.

Which means you end up biased towards rules lawyers. Which may be what you want, but bear in mind that you are presenting one performance goal while you have withheld a secret goal that you are actually looking for.

Boom, point proven. You have at that point learned something about that candidate's way of thinking, select on it or don't. If that was a hidden goal then it worked, if it wasn't then disregard.

Here's a less secret goal: the test is meant to see if you know what modern C++ is like...

Not a diversity of thought test.

...and if you have a good idea of what the POSIX mindset is like (so you don't end up asking pointless rules-lawyer questions).

That is a diversity of thought test. Is the candidate willing to, in the face of ambiguity, insert his own opinion instead of speaking up?

Which of these possible secret goals should the interviewee try to optimize?

As I said earlier: the one that, in your experience, indicates an ability to do the task that the candidate is hired for. Should there be a tie, the one that arrived at a solution that you did not anticipate. And no, that doesn't mean you should hire a guy who insists on sorting files using Node.js, just because he was the only one... you can't determine rationale based only on language selection. If he does it in shell script, ask why. You may learn that binary compatibility concerns are higher on his priority list due to some past experience that you wouldn't have considered.

...the essential problem remains - does "diversity of thought" differ from "highly competent and creative problem solver"?

Yes, but first I'll point out that "highly competent" is an unrelated concept. Because effectively nobody has unbounded useful creativity over an entire problem domain, you want to select individuals who's constraints overlap as little as possible - thereby covering more of the problem domain. Personal example: I took over a database from the engineering department because the guy maintaining it retired. I was horrified when I looked inside, the architect was obviously a PLC programmer - using triggers and views to form a hellish logic ladder. I was trying to figure out how I'd be able to untangle everything into a more tradition normalized database when I got a request from one of the engineers to insert a new trigger to account for some upcoming process change, I told him how much I didn't want to do that and asked if I could spend a day with him in order to get a better grasp on their problem domain - he was annoyed, but agreed. Well it turns out the old engineer wasn't totally insane, the problem domain was pretty much unbounded and constantly changing: new metrics, new datatypes, new requirements - totally normal for their department. Whereas I would have used a Domain-key normal form in that situation, he just created a new table and added a trigger. Both styles work, each has different weaknesses and strengths. Neither of us would have arrived at the other's solution. Diversity of thought.

In my description, the first argument is a filename. The contents of the file are a set of lines, terminated by a \n.

Lol, even your attempt at clarification adds confusion. The ambiguity this time: is the set of lines terminated by \n, or is each line in the set terminated by \n, or is the file terminated by \n? Yes, I'm pretty confident that I know what you mean - but I have seen 0x1f used for stuff like this in production, bad things would have happened had I just made an assumption.

Otherwise the desire to sort the contents makes no sense.

Sure it does: if instead of interpreting the explicit mention of '\n' to mean line termination within the file, one interpreted it as the termination of the first parameter. Again, one can guess the intent due to convention - but it is ambiguously phrased and immediately led to two competing possibilities of intent in my mind. Maybe that is because I think differently from you...

This was in the context of hiring, and I gave my operational definition...

That is actually a helpful reminder - the context of the conversation is a blog entry that struggles over the objectives of quotas and the utility of using race and sex as a proxy for diversity quality beyond... race and sex.

Presenting a solution, or an attempt at a solution, is an expression of one's thoughts.

Yes... are you trying to defend your prior conflation of behavior and thought?

Example 1 ... do you hire for more general diversity of thought and expect more overhead to train people in COBOL?

That depends entirely upon your organization's capabilities and priorities. Hypothetically lets say that the bank's long term objectives don't include a migration from COBOL, the IT department doesn't have a long history of successful inhouse training, and being a bank - is generally risk averse. First, filter for candidates that demonstrate an acceptable level of competency in COBOL. Second, filter for candidates that have skills and interests that are not organic to your team - but could feasibly be useful (in your mind, that is all we've got). Third, ask the candidates for examples of times that they've come up with novel solutions to difficult problems. Here is a personal example: I once accidentally landed a contract when I was having lunch with a friend and his boss, I was later told the clincher was my long exposition on fault tree analysis in ballistic missiles. The contract involved the integration of time management and security systems.

You seem to be struggling with the prioritization of diversity of thought over skills that are actually need to perform a job. Here is a hint: the first order of business is getting somebody who you imagine can do the job (skills, job history, etc). If you have more options that positions, of those people, select the one who demonstrates the ability to reason in a way unique to your team.

Example 2.

You hire the guy who points out that you did a poor job of framing the problem. Not only did you describe it in a way that could be interpreted to demand an implementation that spits in the face of POSIX utility conventions (newlines as argument delimiters), but you also failed to establish a success metric (time, maintainability, performance, etc).

Surely that's even more diverse thinking - and completely within the test protocol as given.

You described a bunch of potential implementations, not different ways of thinking. The protocol you gave wouldn't be useful to measuring diversity of thought, unless you modified it to include the possibility for interviewer-interviewee interaction, where you might get some clues about their thought process. "What is the success metric?", "Are the sorted values bounded?", "Is the source untrusted?", "How does this fit into the larger process flow?"

That is, should I do something which I know is less maintainable simply because I know it's more obscure and thus shows my diversity of thought?

No, even in the cartoon funhouse of an example you provided - they might already have a Python weirdo running amuck, you'd add nothing. You don't know that ahead of time.