Bitmessage / PyBitmessage

Reference client for Bitmessage: a P2P encrypted decentralised communication protocol:
https://bitmessage.org/wiki/Main_Page
Other
2.81k stars 578 forks source link

Change encryption setup due to Prism etc. #501

Closed osos closed 10 years ago

osos commented 10 years ago

NSA is listening to everything its said.

OpenSSL is by many expert mentioned to very likely have been hijacked by NSA or others with expertise to insert vulerabilities in the code.

Thus, it should be considered to find a different encryption provider.

fiatflux commented 10 years ago

Sources?

maraymer commented 10 years ago

The article is he might have in mind is http://blog.cryptographyengineering.com/2013/09/on-nsa.html by Matthew Green who is a cryptographer and research professor at Johns Hopkins University. It's probably worth discussing, but it only questions OpenSSH and does not point to any particular critical failure or backdoor.

ralyodio commented 10 years ago

openssh is open source. i find it hard to believe a backdoor could be inserted w/o people seeing it.

maraymer commented 10 years ago

I believe the point of the article I stated is that while OpenSSH is Open Source it is a huge base of code that very few people know the details of which can inadvertently have exploits present which are not known by Open Source reviewers. Again, I'm not saying it's insecure or has a backdoor in it. What I am saying is that it's something we need (obviously this is the very reason we WANT this open source!) to have people actually checking the integrity of the code.

osos commented 10 years ago

http://www.version2.dk/blog/nsas-gennembrud-eller-noget-53787

https://twitter.com/kiniry/status/376680474632273920