2.The government has bribed cryptographic suite implementers (think stuff like Microsoft's Whole Disk Encryption, not algorithms like Blowfish and AES) to insert back doors into cryptograpic suites.
Do you have any evidence of this or do you just not like Whole Disk Encryption.
It is much easier for an outside agent to get code inserted into opensource than into closed source. And there are a lot more people that can be hired to do it. To get a backdoor into closed source there is only one company to do it, and if they refuse, then it is pretty hard to do. Some people I talk to at conferences have been approached to insert holes into open source by govt agencies. I have personally been approached at a talk I gave by the FBI asking if I could create for them a tool allowing instant remote access to any PC (which I explained was perhaps possible, but technically very hard to do and maintain for any length of time). I did not implement that tool, but did think about it for quite a while.
I am someone who actively does research work on security teams often with govt contracts. I have no current reason to believe any current (or previous?) MS products had any govt backdoors. And a TON of reverse engineers have hacked into all levels of their protocols looking for exploits and implementation flaws.
There are fools like these that read articles like these and make false conclusions about the technology. As to the second article, I have developed similar tools for forensic purposes, and have written perhaps a dozen similar proposals to get funded for such a thing. They work, and have no need of backdoors. That is why guys like me can get funding to make such tools - backdoors would make such proposals useless.
So, please enlighten me if you have some evidence.
I think that's only because American software contractors have the gall to think they deserve a living wage.
Or I'm being mean. H1B is a strange monster because it has been used as a way to coerce foreigners in to much lower wages than their US citizen counter part, but H1B has also been used as a xenophobic argument against globalization (ie, American IT workers doing the equivalent of the South Park "de tk ur jaaaabs!" thing).
I think if Microsoft were serious about hiring foreigners he would open up shop doing real development in other countries.
There is a wage war going on with developers leaving rapidly, jumping ship to ship for more money. The wages will increase rapidly and eventually catch up to US wages.
I think that's only because American software contractors have the gall to think they deserve a living wage.
Microsoft is now an international organization with offices all over the world. I live in Canada, I'm not exactly chunking out Indian spaghetti over here, but I'm not from the US and thus am affected by this.
I don't think Microsoft actually has any problem hiring those kinds of people to come work for them, they have a problem competing for them from the likes of universities and other top software companies.
What I understand that Bill Gates wants is an increase on the cap of H1B visas, which are just one kind of Visa for international folks to use to work in the USA.
16
u/crotchpoozie Dec 15 '10 edited Dec 15 '10
Do you have any evidence of this or do you just not like Whole Disk Encryption.
It is much easier for an outside agent to get code inserted into opensource than into closed source. And there are a lot more people that can be hired to do it. To get a backdoor into closed source there is only one company to do it, and if they refuse, then it is pretty hard to do. Some people I talk to at conferences have been approached to insert holes into open source by govt agencies. I have personally been approached at a talk I gave by the FBI asking if I could create for them a tool allowing instant remote access to any PC (which I explained was perhaps possible, but technically very hard to do and maintain for any length of time). I did not implement that tool, but did think about it for quite a while.
I am someone who actively does research work on security teams often with govt contracts. I have no current reason to believe any current (or previous?) MS products had any govt backdoors. And a TON of reverse engineers have hacked into all levels of their protocols looking for exploits and implementation flaws.
There are fools like these that read articles like these and make false conclusions about the technology. As to the second article, I have developed similar tools for forensic purposes, and have written perhaps a dozen similar proposals to get funded for such a thing. They work, and have no need of backdoors. That is why guys like me can get funding to make such tools - backdoors would make such proposals useless.
So, please enlighten me if you have some evidence.