<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Did the FBI plant backdoor vulnerabilities in OpenBSD IPSEC?</title>
	<atom:link href="http://www.gfi.com/blog/did-the-fbi-plant-backdoor-vulnerabilities-in-openbsd-ipsec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gfi.com/blog/did-the-fbi-plant-backdoor-vulnerabilities-in-openbsd-ipsec/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=did-the-fbi-plant-backdoor-vulnerabilities-in-openbsd-ipsec</link>
	<description>Brought to you by GFI Software</description>
	<lastBuildDate>Fri, 13 Sep 2013 13:27:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Emmanuel Carabott</title>
		<link>http://www.gfi.com/blog/did-the-fbi-plant-backdoor-vulnerabilities-in-openbsd-ipsec/comment-page-1/#comment-29114</link>
		<dc:creator>Emmanuel Carabott</dc:creator>
		<pubDate>Thu, 05 May 2011 14:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=3106#comment-29114</guid>
		<description><![CDATA[Hi Chris,

Since I posted this article the code review of IPSEC has finished and no backdoor was found so this either never happened or updates removed the backdoor. There is a minute chance that a really clever side channel vulnerability was introduced but in this case I find it highly unlikely something like that would have been missed by the openbsd community especially after such a claim.

As for the NDA, well I&#039;m not so sure that back then introducing a backdoor would have broken any laws; however, one must remember that this is the FBI we are talking about. Even in the modern times when the whole wiretapping thing was deemed illegal, the government simply changed the laws to allow it and had it applied retroactively. I&#039;m not saying that the FBI is above the law or anything of the sort, it&#039;s just that I can understand that when an organization is tasked to do something questionable and then abide by an NDA, it would do so without questioning its legality and would certainly not try to go around it.]]></description>
		<content:encoded><![CDATA[<p>Hi Chris,</p>
<p>Since I posted this article the code review of IPSEC has finished and no backdoor was found so this either never happened or updates removed the backdoor. There is a minute chance that a really clever side channel vulnerability was introduced but in this case I find it highly unlikely something like that would have been missed by the openbsd community especially after such a claim.</p>
<p>As for the NDA, well I&#8217;m not so sure that back then introducing a backdoor would have broken any laws; however, one must remember that this is the FBI we are talking about. Even in the modern times when the whole wiretapping thing was deemed illegal, the government simply changed the laws to allow it and had it applied retroactively. I&#8217;m not saying that the FBI is above the law or anything of the sort, it&#8217;s just that I can understand that when an organization is tasked to do something questionable and then abide by an NDA, it would do so without questioning its legality and would certainly not try to go around it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Lorrel</title>
		<link>http://www.gfi.com/blog/did-the-fbi-plant-backdoor-vulnerabilities-in-openbsd-ipsec/comment-page-1/#comment-29061</link>
		<dc:creator>Chris Lorrel</dc:creator>
		<pubDate>Mon, 25 Apr 2011 18:41:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gfi.com/blog/?p=3106#comment-29061</guid>
		<description><![CDATA[Oh, boy! This is so sick! I can&#039;t believe it - not that the FBI are the nicest guys who always play by the rules but this sounds just incredible. I don&#039;t think that the community of an OS as popular as openBSD is, wouldn&#039;t have noticed such a major issue. All this backdoor talk seems like a cheap sensation to me. I am not a lawyer but can a NDA include clauses that break the law?]]></description>
		<content:encoded><![CDATA[<p>Oh, boy! This is so sick! I can&#8217;t believe it &#8211; not that the FBI are the nicest guys who always play by the rules but this sounds just incredible. I don&#8217;t think that the community of an OS as popular as openBSD is, wouldn&#8217;t have noticed such a major issue. All this backdoor talk seems like a cheap sensation to me. I am not a lawyer but can a NDA include clauses that break the law?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

 Served from: www.gfi.com @ 2013-09-15 06:10:16 by W3 Total Cache --