Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

tl;dr: Don't take security advice from organizations whose job is spying on you.

I don't know about anyone else. But the NSA is one of the last organizations I'd let give me security advice. I wouldn't put it past them to purposefully omit a pointer or two in the hope that those who follow the guide to the letter not knowing any better will leave a way in. Based on the other comments the advice is banal rubbish. Perhaps this is purposeful.



Part of the NSA's mandate is protecting US interests and communications as well. My personal favourite example of this is the changes they recommended to DES while it was being established that strengthened DES against differential attacks, a class of attacks that was not publicly known of until years later http://en.wikipedia.org/wiki/National_Security_Agency#Data_E...


A more secure society wouldn't have secret agencies operating in peacetime. Why? Because their mandates, budgets, policies are also secret and subject to mission creep.


Except that this specific document comes with good advice and rationale. There is nothing here that indicates a secret agenda. It's not as if the document is telling you to install a backdoor for them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: