[Cryptography] RSA is dead.

Ralf Senderek crypto at senderek.ie
Mon Dec 23 03:40:20 EST 2013


On Mon, 23 Dec 2013, ianG wrote:

> Open Source as a guarantee of security is really just the marketing of
> the open source folk.  It certainly helps but collecting those smart
> eyeballs isn't as easy as saying it.
>
> iang

Of course open source is never a guarantee, I didn't say that. We should
not confuse a necessary condition with a sufficient one. But the RSA (Inc)
marketing implied that closed-shop trusted expert crypto is superior to
open source crypto products. And that is certainly false.

As Peter, Dirk-Willem and Jerry rightly pointed out, it is very difficult
to find crafted backdoors even in open source products. But just because
something is difficult, that doesn't mean it should not be done.

With open source it can be done. But some essential changes are needed.
Those who have the ability to check crypto code must be actively engaged
by the community / society. If there is no incentive nor any substantial
acknowledgement of this important work, if code audit is mainly seen as 
private activity with no financial rewards, then yes, we can forget
security.

                --ralf


More information about the cryptography mailing list