Hacker News new | ask | show | jobs
by pavritch 2794 days ago
The ciphers are public. Providing source for this specific implementation of "user interface" did nothing more than indicate sizes of file headers, etc. No customers were put at risk. All I did was save the NSA maybe a few hours of time during a critical moment. Do you really think they couldn't have figured out there is a 4K file header (see, I've said it here, no harm).
1 comments

Can you explain how you can prove you are talking to the NSA by call foo ask to be transferred to bar, ask to speak to baz?

Logically the fact that you called into the navy base indicates you are talking to them but by the time you get transferred how do you know who you are ultimately talking to?

Couldn't you be talking to anyone who works at the navy or works with someone who works at the navy? One great thing about court orders is that its trivial to authenticate them and they get the exciting task of making sure the person asking for them is a legitimate actor on legitimate business.

If a random private wanted to fool you couldn't they have had you call in in such a way as you would trivially be talking to a known party who will ultimately transfer you said party? Hey this joker is going to be transferred to your extension asking to speak to john doe at the NSA send him to my extension please.

Considering that we now know that intelligence apparatus was used to spy on love interests how do you know you were collaborating with a legitimate legal operation as opposed to illegal spying on citizens?

Likely you aren't in a position to judge right which is why we have you know judges and court orders and such ceremony.

I respond to random calls that seem strange by hanging up and telling them to send me something official in the mail.

Neither the people who claim they would like me to give me a fortune I inherited overseas, the guy who claimed I won the lottery, or the guy that claimed to be the IRS demanding immediate payment have followed up yet.

At best your judgement is questionable.

Here's how I looked at it -- they are 1000x smarter than me on matters of encryption. It was totally unlikely I knew something they didn't. At most, I saved them a few hours on a matter of life and death, and I had minutes to make that decision. And recall, back then, people felt differently about the NSA. If this was a total spoof - the reality is I didn't give anything up. I didn't invent the encryption ciphers. I just packaged common ciphers in a user interface people really liked.

But in response to the people here who think I was tricked. That's not the case. What I didn't put in the post was that a team from the NSA visited me in California a few months later. But again, had I been tricked, it wouldn't have mattered.

You remembered to mention the coffee cup but you forgot to mention the team from the NSA that visited you to confirm the authenticity of what sounds on the face like a story of you getting scammed.

I'm sorry this is utterly beyond belief.

Are you OK with a freedom of information request regarding the NSA's request for your participation in helping the NSA break into your customers machines?

If I understand correctly such a request could be made by anyone running your software.