[Discuss] Good and Bad Crypto

Richard Pieri richard.pieri at gmail.com
Wed Apr 23 12:04:22 EDT 2014


Derek Martin wrote:
> Unless they hack the vendor and steal the source.  White hats aren't
> going to do that.  Or... unless the NSA or some other organization has
> paid off the vendor to intentionally include weaknesses for them to
> exploit.  Or... unless the attacker works for the vendor and is taking
> advantage of flaws he already knows exist.  Or... unless someone who
> works for the vendor who feels slighted decides to post the source on
> some black hat site.  Or... unless some criminal organization pays
> someone at the vendor to steal the source code for them.  Or...

What's your point? That hiding the code is of zero relevance to the 
security of that code?

-- 
Rich P.



More information about the Discuss mailing list