[39483] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: NYT on Netscape Crack

daemon@ATHENA.MIT.EDU (Thomas Grant Edwards)
Tue Sep 19 16:32:59 1995

Date: Tue, 19 Sep 1995 16:09:21 -0400 (EDT)
From: Thomas Grant Edwards <tedwards@Glue.umd.edu>
To: Eli Brandt <eli@UX3.SP.CS.CMU.EDU>
Cc: cypherpunks@toad.com
In-Reply-To: <9509191438.AA16172@toad.com>

On Tue, 19 Sep 1995, Eli Brandt wrote:

> It sounds as if Netscape thinks that public knowledge of the key
> generation is part of the problem.  I hope somebody on the security
> team convinces management that entropy is more important than publicity.

No matter what they say in the press, I doubt it will take more than a few
weeks to reverse engineer the new RNG seeder and figure out where the data
comes from. 

I am hoping it was more of a PR thing than a technical thing.  I hope 
that Netscape tells us their RNG seed so Cyperhpunks don't have to go to all 
the trouble.  If they tell us, we can let them know if it is a reasonable 
mechanism or bogus.

-Thomas



home help back first fref pref prev next nref lref last post