1995-09-19 - Re: NYT on Netscape Crack

Header Data

From: Thomas Grant Edwards <tedwards@Glue.umd.edu>
To: Eli Brandt <eli@UX3.SP.CS.CMU.EDU>
Message Hash: c67f37f84dd9ecbd4468ee0986216cdfce7f889c96246bff56f10da705147333
Message ID: <Pine.SUN.3.91.950919160626.8469G-100000@hertz.isr.umd.edu>
Reply To: <9509191438.AA16172@toad.com>
UTC Datetime: 1995-09-19 20:09:56 UTC
Raw Date: Tue, 19 Sep 95 13:09:56 PDT

Raw message

From: Thomas Grant Edwards <tedwards@Glue.umd.edu>
Date: Tue, 19 Sep 95 13:09:56 PDT
To: Eli Brandt <eli@UX3.SP.CS.CMU.EDU>
Subject: Re: NYT on Netscape Crack
In-Reply-To: <9509191438.AA16172@toad.com>
Message-ID: <Pine.SUN.3.91.950919160626.8469G-100000@hertz.isr.umd.edu>
MIME-Version: 1.0
Content-Type: text/plain


On Tue, 19 Sep 1995, Eli Brandt wrote:

> It sounds as if Netscape thinks that public knowledge of the key
> generation is part of the problem.  I hope somebody on the security
> team convinces management that entropy is more important than publicity.

No matter what they say in the press, I doubt it will take more than a few
weeks to reverse engineer the new RNG seeder and figure out where the data
comes from. 

I am hoping it was more of a PR thing than a technical thing.  I hope 
that Netscape tells us their RNG seed so Cyperhpunks don't have to go to all 
the trouble.  If they tell us, we can let them know if it is a reasonable 
mechanism or bogus.

-Thomas







Thread