Layered Security
2015-12-22 17:40:49.404673+00 by Dan Lyke 2 comments
Why we need layered security
And, seriously, if you haven't been keeping up with the revelations from the Juniper backdoors story, in this entry, and you're technically minded, take a look at A Few Thoughts on Cryptographic Engineering: On the Juniper backdoor.
To sum up, some hacker or group of hackers attacker noticed an existing backdoor in the Juniper software, which may have been intentional or unintentional -- you be the judge! They then piggybacked on top of it to build a backdoor of their own, something they were able to do because all of the hard work had already been done for them. The end result was a period in which someone -- maybe a foreign government -- was able to decrypt Juniper traffic in the U.S. and around the world.
Note that side-effect from prng_reseed()
.