Hacker News new | ask | show | jobs
by adrtessier 3829 days ago
Why the statement from Juniper, then? To try to CYA so they don't end up looking as shitty to the community as RSA did post-bribe?

EDIT: The conspiracy theorist in me would say "this is intentional, too." Changing a value to 31 from 32, or adding a single global assignment in a different function, wouldn't be caught on first review most likely, especially since where the '31' is, 31 is also used all over the code to refer to X9.31.

1 comments

Got a link to the 31/32 analysis?
I'm not sure there was a prior "31" but here's the code with the "32":

https://rpw.sh/blog/2015/12/21/the-backdoored-backdoor/