FBI 'planted backdoor' in OpenBSD

Rage9

Banned
Jan 7, 2008
6,061
101
0
FBI 'planted backdoor' in OpenBSD ? The Register
Allegations that the FBI may have smuggled back doors or weaknesses into openBSD's cryptography have created uproar in the security community.


Former government contractor Gregory Perry, who helped develop the OpenBSD crypto framework a decade ago, claims that contractors were paid to insert backdoors into OpenBSD's IPSec stack around 10 years ago. Perry recently warned the openBSD's Theo de Raadt of the development, years after the event, via an email that de Raadt has published in the spirit of openness.



Perry said he had waited until his ten year NDA with the FBI had expired before coming forward with the claims, which remain unsupported by secondary sources. If true the allegations mean that would have an easy way to tap into supposedly secure VPN links and other technologies based on OpenBSD's crypto stack...
 


It's not that far fetched. I mean didn't some jailbroken iPhones get hit by a worm because they left their default SSH password? It's a lot easier for the FBI to make software devs do all the hard work for them when they're paying them under the table to do it.

It's the same reason I'm wary of the warez scene (i.e. patches), who the fuck knows who's 'net I've become a part of?
 
I dont know if I think its true. Possible, of course, but I dont think its actually there. (personal opinion based on no one finding it yet.)
 
I dont know if I think its true. Possible, of course, but I dont think its actually there. (personal opinion based on no one finding it yet.)

regardless if there or not, now people will be suspicious of one possibly being there, and drop openBSD.
 
I'm a little confused, isn't all of this open source? If so wouldn't someone have found something by now ? Plz enlighten me someone...
 
Even if they did have this capability, like they have to tap phones, it doesn't mean they are free to use it whenever they want, they still need a judge to agree on probable cause. The EFF put this out today, it's sort of relevant:

It's been a great week for electronic privacy and the 4th Amendment!

In a decision issued yesterday, the Sixth Circuit Court of Appeals ruled that the government must have a search warrant before it can seize and search emails stored by third party email service providers. Closely tracking arguments made by EFF in our amicus brief, the court found that email users have the same reasonable expectation of privacy in their stored email as they do in their phone calls and postal mail.

And today, the Third Circuit Court of Appeals agreed with EFF and refused the government's request to reconsider an earlier pro-privacy decision, which held that federal magistrates have the discretion to require the government to get a search warrant based on probable cause before obtaining cell phone location records. That decision, based on EFF's briefing and oral argument as a friend of the court, has implications far beyond cell phone location privacy. It could apply to a broad range of communications records - including the content of your emails, your web search or browsing histories, as well as the location of your phone.
 
Even if they did have this capability, like they have to tap phones, it doesn't mean they are free to use it whenever they want, they still need a judge to agree on probable cause.

Your missing the overall point. If there is a known vulnerability in the encryption what's to say another government or individuals don't have the same information?

I'm a little confused, isn't all of this open source? If so wouldn't someone have found something by now ? Plz enlighten me someone...

You make a point but it's misguided. Simply because it's open source doesn't mean someone has trolled through the source and could or would ever even notice it. We are talking about probably buried encryption algorithms here.
 
Your missing the overall point. If there is a known vulnerability in the encryption what's to say another government or individuals don't have the same information?.

I get it and it sucks, but these other governments or individuals still have to be in a position to intercept and record packets in your network route, which at times, sure they may be. But data ultimately resides somewhere in unencrypted form, those datacenters/ISPs/hardware are also technically vulnerable to other governments or individuals just as much.

If it's really sensitive, there are additional measures you can take to encrypt data before it goes through any public pipes regardless of the encrypted tunnel. If it's flat out illegal, maybe you shouldn't be recording it on any digital media at all.
 
Your missing the overall point. If there is a known vulnerability in the encryption what's to say another government or individuals don't have the same information?



You make a point but it's misguided. Simply because it's open source doesn't mean someone has trolled through the source and could or would ever even notice it. We are talking about probably buried encryption algorithms here.

it has nothing to do with source code.
 
I get it and it sucks, but these other governments or individuals still have to be in a position to intercept and record packets in your network route, which at times, sure they may be. But data ultimately resides somewhere in unencrypted form, those datacenters/ISPs/hardware are also technically vulnerable to other governments or individuals just as much.

If it's really sensitive, there are additional measures you can take to encrypt data before it goes through any public pipes regardless of the encrypted tunnel. If it's flat out illegal, maybe you shouldn't be recording it on any digital media at all.

Haha, wouldn't that be the perfect world right? Just not record anything on digital media?

Granted any encryption scheme can be broken but it's another thing to have a backdoor or weakness purposely programmed in for someone.

I get your point about extra encryption, but openBSD is touted and regarded as one of the most (if not the most) secure Linux distro out there, so this is a major hit to it.
 
I'm not sure these claims will hold up, it doesn't make sense to me.

Theo and the OpenBSD crew have regular code audits, how long would have these back doors or hooks survived them, one year maybe, two year getting unlikely - ten years not likely at all.

Also you have external agencies performing audits on the code as well for their own security.
 
Haha, wouldn't that be the perfect world right? Just not record anything on digital media?
ha...well if it's illegal... just ask iceman butler.

Granted any encryption scheme can be broken but it's another thing to have a backdoor or weakness purposely programmed in for someone.
point taken, but this shouldn't ever come as a surprise considering the govt's past actions & requests.

I get your point about extra encryption, but openBSD is touted and regarded as one of the most (if not the most) secure Linux distro out there, so this is a major hit to it.
IF this is true. there are bounties being offered and matched for proof of it, let's see if anyone claims them.

It also serves as a reminder to not fall for a false sense of security, diversify and step up your security game.
 
I get your point about extra encryption, but openBSD is touted and regarded as one of the most (if not the most) secure Linux distro out there, so this is a major hit to it.

Linux doesn't have shit on OpenBSD and calling OpenBSD Linux is sacrilege. Fucking heretics.