[1371] in Privacy_Forum
[ PRIVACY Forum ] Paul Baran & the history of DES
daemon@ATHENA.MIT.EDU (privacy@vortex.com)
Tue Mar 29 12:22:14 2011
Date: Tue, 29 Mar 2011 09:08:45 -0700
To: privacy-list@vortex.com
Message-ID: <20110329160845.GC2752@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: privacy@vortex.com
Reply-To: PRIVACY Forum mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit
----- Forwarded message from David Farber <dave@farber.net> -----
Date: Tue, 29 Mar 2011 08:51:44 -0400
From: David Farber <dave@farber.net>
Subject: [IP] Paul Baran & the history of DES
Reply-To: dave@farber.net
To: ip <ip@listbox.com>
Begin forwarded message:
From: John Gilmore <gnu@toad.com>
Date: March 29, 2011 3:46:37 AM EDT
To: dave@farber.net, gnu@toad.com
Subject: Re: [IP] Paul Baran & the history of DES
[for IP]
I was sorry to hear of Paul Baran's death. He hired me for a brief
consultation at PacketCable decades ago. And we had one more
interaction...
Some years ago, after I became prominent in encryption policy work,
Paul Baran sent me a cassette tape, a recording from when he was at
Stanford in the 1970s. He recorded a meeting between Stanford crypto
grad students (primarily Whit Diffie and Marty Hellman and himself)
and representatives from the National Bureau of Standards and from the
National Security Agency. Their topic was whether DES, the
then-proposed Data Encryption Standard, was too easy for a spook
agency to crack by brute force.
I digitized the tape, and Sam Bretheim transcribed it. Both are
here:
https://www.toad.com/des-stanford-meeting.html
By the way, subsequent history has shown that the Stanford students
were right and that NBS and NSA were wrong. And, more important, the
arguments that the NSA spooks were making (like "the too-short key
will never be the weakest link in the overall system's security, so
it's not worth fixing") are still wrong today. Don't mistake me - I
don't think these historical or modern NSA employees are stupid. I
think they are making self-serving arguments in the hope of tricking
the public into deploying insecure systems that NSA can penetrate.
John
_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy