Davorin Vlahovic
2010-12-15 12:01:01 UTC
De Raadt received the email from Gregory Perry, currently the CEO of
GoVirtual Education. Ten years ago, while he was CTO at NETSEC, Perry did
some consulting work for the FBI's GSA Technical Support Center. Perry's NDA
expired recently, and as such, he decided to contact De Raadt about what he
had learned ten years ago.
"My NDA with the FBI has recently expired, and I wanted to make you aware of
the fact that the FBI implemented a number of backdoors and side channel key
leaking mechanisms into the OCF, for the express purpose of monitoring the
site to site VPN encryption system implemented by EOUSA, the parent
organization to the FBI," Perry details in the email, "Jason Wright and
several other developers were responsible for those backdoors, and you would
be well advised to review any and all code commits by Wright as well as the
other developers he worked with originating from NETSEC."
"This is also why several inside FBI folks have been recently advocating the
use of OpenBSD for VPN and firewalling implementations in virtualized
environments," he adds, "For example Scott Lowe is a well respected author in
virtualization circles who also happens top be on the FBI payroll, and who
has also recently published several tutorials for the use of OpenBSD VMs in
enterprise VMware vSphere deployments."
http://www.osnews.com/story/24136/_FBI_Added_Secret_Backdoors_to_OpenBSD_IPSEC_
GoVirtual Education. Ten years ago, while he was CTO at NETSEC, Perry did
some consulting work for the FBI's GSA Technical Support Center. Perry's NDA
expired recently, and as such, he decided to contact De Raadt about what he
had learned ten years ago.
"My NDA with the FBI has recently expired, and I wanted to make you aware of
the fact that the FBI implemented a number of backdoors and side channel key
leaking mechanisms into the OCF, for the express purpose of monitoring the
site to site VPN encryption system implemented by EOUSA, the parent
organization to the FBI," Perry details in the email, "Jason Wright and
several other developers were responsible for those backdoors, and you would
be well advised to review any and all code commits by Wright as well as the
other developers he worked with originating from NETSEC."
"This is also why several inside FBI folks have been recently advocating the
use of OpenBSD for VPN and firewalling implementations in virtualized
environments," he adds, "For example Scott Lowe is a well respected author in
virtualization circles who also happens top be on the FBI payroll, and who
has also recently published several tutorials for the use of OpenBSD VMs in
enterprise VMware vSphere deployments."
http://www.osnews.com/story/24136/_FBI_Added_Secret_Backdoors_to_OpenBSD_IPSEC_
--
Some men see things as they are and say: Why?
I dream things that never were and say: Why not?
-- Tatsuya Ishida
Some men see things as they are and say: Why?
I dream things that never were and say: Why not?
-- Tatsuya Ishida