Home Page di InvestireOggi
Le ultime
NEWS
FINANZIARIE
Quotazioni e Grafici E.o.D. Real Time
FTSE Mib
13.155
+47.0

Rispondi
 
Strumenti discussione Cerca in questa discussione
Vecchio 15-12-2010, 17:32   #1 (permalink)
Utente Senior
 
L'avatar di Metatarso
 
Data registrazione: Jul 2008
Messaggi: 2,070
Backdoor dell'FBI in OpenBSD (e windows, linux, mac, e...)

Occhio che questa e' roba grossa

FBI 'planted backdoor' in OpenBSD ? The Register
Break out the code auditing kit
By John Leyden
Posted in Enterprise Security, 15th December 2010 13:12 GMT

Allegations that the FBI may have smuggled back doors or weaknesses into openBSD's cryptography have created uproar in the security community.

Former government contractor Gregory Perry, who helped develop the OpenBSD crypto framework a decade ago, claims that contractors were paid to insert backdoors into OpenBSD's IPSec stack around 10 years ago. Perry recently warned the openBSD's Theo de Raadt of the development, years after the event, via an email that de Raadt has published in the spirit of openness.

Perry said he had waited until his ten year NDA with the FBI had expired before coming forward with the claims, which remain unsupported by secondary sources. If true the allegations mean that would have an easy way to tap into supposedly secure VPN links and other technologies based on OpenBSD's crypto stack.

De Raadt said he had published Perry's email so that those who use potentially affected code can carry out an audit, as well as offering the opportunity for those named in the email to come forward and give their version of events.

In his email, Perry alleges that virtualisation guru Scott Lowe is on the FBI payroll, suggesting this may be behind his recent advocacy of OpenBSD at a technology for VPN and firewall installation in virtualised environments. Lowe denies the charge, saying he never worked for the Feds.

In an email exchange with reporter Robert McMillan, Perry said that attempts to plant backdoors in open source code were made by the Clinton administration to "counter to their supposed relaxation of the Department of Commerce encryption export regulations".

Perry's allegations are being taken seriously even though they don't come alongside anything substantial by way of evidence. Whether true or not, the charge of an OpenBSD backdoor has spawned a debate.

E J Hilbert, a former FBI cyber-crime agent, said attempts were made to place backdoors in open source security codes but that these were unsuccessful. "I was one of the few FBI cyber agents when the coding supposedly happened. Experiment yes. Success No," Hilbert said in a Twitter update.

Chris Wysopal, CTO of application security tools firm Veracode and former high profile member of hacker collective L0pht Heavy Industries, said that the issue of potential backdoors doesn't stop with OpenBSD: "If OpenBSD w/all their auditing was backdoored where does that leave Linux, Windows, FreeBSD, OS X. Who thinks they stopd at smallest dist?"
__________________
STOP THE LOOTING AND START PROSECUTING !
Metatarso non è connesso   Rispondi citando
Avviso pubblicitario - i seguenti Banner Pubblicitari permettono al sito di offrirvi il consueto, alto standard qualitativo.
 
Rispondi

Segnalibri

« Discussione precedente | Nuova discussione »

Utenti attualmente attivi che stanno leggendo questa discussione: 1 (0 utenti e 1 ospiti)
 
Strumenti discussione Cerca in questa discussione
Cerca in questa discussione:

Ricerca avanzata

Regole messaggi
Tu non puoi inviare nuove discussioni
Tu non puoi replicare
Tu non puoi inviare allegati
Tu non puoi modificare i tuoi messaggi

Il codice BB è Attivato
Le faccine sono Attivato
Il codice [IMG] è Attivato
Il codice HTML è Disattivato
Trackbacks are Attivato
Pingbacks are Attivato
Refbacks are Disattivato


Discussioni simili
Discussione Autore discussione Forum Risposte Ultimo messaggio
Browsers
Google Chrome 6 STABILE per Linux, Mac, Windows
Blackie PC, Tecnologia e Web, Sicurezza informatica 33 18-02-2011 19:42
Browsers
Google Chrome 5 STABILE per Linux, Mac, Windows
Blackie PC, Tecnologia e Web, Sicurezza informatica 3 27-05-2010 15:01
Linux OS
Microsoft Contributes Linux Drivers to Linux Community
giobar57 PC, Tecnologia e Web, Sicurezza informatica 9 16-08-2009 12:14
Windows Virtual PC e Windows XP Mode RC per Windows 7 giobar57 PC, Tecnologia e Web, Sicurezza informatica 0 05-08-2009 12:34
Sicurezza informatica
Backdoor.Win32.Rbot.aazi
ubu PC, Tecnologia e Web, Sicurezza informatica 10 21-04-2009 10:13


Tutti gli orari sono GMT +2. Adesso sono le 02:15.


vBulletin®
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0
(C) Copyright InvestireOggi 2000-2010