The maintainers of the security-conscious FreeBSD operating system have declared that they will no longer rely on the random number generators in Intel and Via's chips, on the grounds that the NSA likely has weakened these opaque hardware systems in order to ease surveillance. The decision is tied to the revelations of the BULLRUN/EDGEHILL programs, wherein the NSA and GCHQ spend $250M/year sabotaging security in standards, operating systems, software, and networks.
"For 10, we are going to backtrack and remove RDRAND and Padlock backends and feed them into Yarrow instead of delivering their output directly to /dev/random," FreeBSD developers said. "It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more."
In separate meeting minutes, developers specifically invoked Snowden's name when discussing the change.
"Edward Snowdon [sic] -- v. high probability of backdoors in some (HW) RNGs," the notes read, referring to hardware RNGs. Then, alluding to the Dual EC_DRBG RNG forged by the National Institute of Standards and Technology and said to contain an NSA-engineered backdoor, the notes read: "Including elliptic curve generator included in NIST. rdrand in ivbridge not implemented by Intel... Cannot trust HW RNGs to provide good entropy directly. (rdrand implemented in microcode. Intel will add opcode to go directly to HW.) This means partial revert of some work on rdrand and padlock."
“We cannot trust” Intel and Via’s chip-based crypto, FreeBSD developers say [Dan Goodin/Ars Technica]
Late last month, the Boston Globe published a blockbuster scoop revealing the existence of "Quiet Skies," a secret TSA program that sent Air Marshals out to shadow travelers who were not on any watchlist and had committed to crime, on flimsy pretenses like "This person once visited Turkey."
In King County (which encompasses Seattle), the number of people living in their cars surged by 46% in the past year; and other big cities are catching up: LA, San Francisco, Portland, etc.
Canadian border guards' terminals give them secret access to Tuscan, a database maintained by US spy agencies of suspected terrorists; the database has some 680,000 names in it and if you match one of those names, Canadian border and immigration officials are empowered to "detain, interrogate, arrest and deny entry" to you.
Drones are undeniably cool, but not all of us have the Top Gun-level piloting skills required to fly them—unless you’re using TRNDlabs’ new Spectre Drone. Designed new and expert pilots alike, this drone is loaded with fly assist features to make piloting easy, all the while you explore using its built-in HD camera. It’s available in the […]
Whether you’re set to give the toast at your best friend’s wedding or a presentation at work, you’ll be relying on those public speaking lessons you slept through during high school. Scary thought, right? Thankfully, the Public Speaking Bundle is loaded with hacks, tips, and techniques that will get you speaking more naturally and with confidence, […]
The Adobe Creative Cloud suite is the foundation on which many creatives build their careers, but some of its programs, like Photoshop and InDesign, are notoriously complex, making it difficult for aspiring designers, photographers, and the like to break into their field. But, don’t get discouraged. The Pay What You Want: Adobe CC A-Z Lifetime Bundle […]