Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

unhappycamper

(60,364 posts)
Fri Dec 27, 2013, 08:01 AM Dec 2013

Security professionals withdraw from tech conference after NSA revelations

http://www.rawstory.com/rs/2013/12/26/security-professionals-withdraw-from-tech-conference-after-nsa-revelations/



Security professionals withdraw from tech conference after NSA revelations
By George Chidi
Thursday, December 26, 2013 13:10 EST

~snip~

“If the allegations are true, a company that’s sole purpose to build trust – and that’s what cryptography is – and they can’t be trusted, then I don’t want to be part of that,” Thomas said to Raw Story. Thomas, “Chief Breaker” of Atreidis Partners, had been lined up to speak at the annual RSA conference in February. The conference gathers computer security researchers to discuss the latest in cryptography and security.

But the RSA brand is radioactive territory after Reuters published accusations that the firm colluded with the NSA to market flawed encryption. The conference is separate from the company, he noted. “They share a name and nothing else. To punish the conference for the company is probably not fair. The problem is that they do share a name. They are furthering the RSA brand. Everyone who gets on stage is furthering the credibility of the company.”

~snip~

“On December 20th, Reuters broke a story alleging that your company accepted a random number generator from the National Security Agency, and set it as the default option in one of the your products, in exchange of $10 million. Your company has issued a statement on the topic, but you have not denied this particular claim,” Hypponen wrote in an open letter.

“Eventually, NSA’s random number generator was found to be flawed on purpose, in effect creating a back door. You had kept on using the generator for years despite widespread speculation that NSA had backdoored it. As my reaction to this, I’m cancelling my talk at the RSA Conference USA 2014 in San Francisco in February 2014.”
1 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Security professionals withdraw from tech conference after NSA revelations (Original Post) unhappycamper Dec 2013 OP
Mikko Hypponen's open letter announcing his withdrawal friendly_iconoclast Dec 2013 #1
 

friendly_iconoclast

(15,333 posts)
1. Mikko Hypponen's open letter announcing his withdrawal
Fri Dec 27, 2013, 12:57 PM
Dec 2013

(Note to mods: Published here in full as the author clearly wished to share it)

http://www.f-secure.com/weblog/archives/00002651.html

23rd of December 2013


An Open Letter to:
Joseph M. Tucci - Chairman and Chief Executive Officer, EMC
Art Coviello - Executive Chairman, RSA



Dear Joseph and Art,

I don’t expect you to know who I am.

I’ve been working with computer security since 1991. Nowadays I do quite a bit of public speaking on the topic. In fact, I have spoken eight times at either RSA Conference USA, RSA Conference Europe or RSA Conference Japan. You’ve even featured my picture on the walls of your conference walls among the 'industry experts'.

On December 20th, Reuters broke a story alleging that your company accepted a random number generator from the National Security Agency, and set it as the default option in one of your products, in exchange of $10 million. Your company has issued a statement on the topic, but you have not denied this particular claim. Eventually, NSA’s random number generator was found to be flawed on purpose, in effect creating a back door. You had kept on using the generator for years despite widespread speculation that NSA had backdoored it.

As my reaction to this, I’m cancelling my talk at the RSA Conference USA 2014 in San Francisco in February 2014.

Aptly enough, the talk I won’t be delivering at RSA 2014 was titled "Governments as Malware Authors".

I don’t really expect your multibillion dollar company or your multimillion dollar conference to suffer as a result of your deals with the NSA. In fact, I'm not expecting other conference speakers to cancel. Most of your speakers are American anyway – why would they care about surveillance that’s not targeted at them but at non-americans. Surveillance operations from the US intelligence agencies are targeted at foreigners. However I’m a foreigner. And I’m withdrawing my support from your event.

Sincerely,

Mikko Hypponen
Chief Research Officer
F-Secure




Latest Discussions»Issue Forums»National Security & Defense»Security professionals wi...