| To: | Jake Appelbaum <jacob,AT,appelbaum,DOT,net> |
| Subject: | Re: My response to both the analysis of CIPE by Gutmann, Slashdotand the response by the CIPE list |
| From: | Phil Scarratt <fil,AT,draxsen,DOT,com> |
| Date: | Fri, 26 Sep 2003 11:47:27 +1000 |
| Cc: | cipe-l,AT,inka,DOT,de |
| In-reply-to: | <1064495379.428.21.camel@eris> |
| Organization: | Draxsen Technologies |
| References: | <1064495379.428.21.camel@eris> |
I wanted to contribute an outsiders perspective.
I first read Peter Gutmanns analysis [1] as linked from Slashdot [2] and later I found the archive for cipe-l [3].
After reading Gutmann's short but to the point email a few points that he made seemed obvious. Some of the flaws were not so obvious. CIPE seemed to have some very simple flaws and some of the fixes were easy to implement.
I found some of it delivered in such a manner that would upset people who were highly vested in the projects he was criticizing. Perhaps it was the comment that I also found to be so amusing, something to do with sound waves. Amusing as it may be, it's still quite harsh.
I then read through the posts on Slashdot that declared CIPE to be dead. I found these to be really immature and silly considering the nature of F/OSS.
The need for some change is now, not the time for it's funeral. Thanks to the F/OSS method of development this is all very possible.
The only series of comments on Slashdot worth reading (IMHO) were by Dan Kaminsky [4].
Others want to wait for Olaf (the primary author of CIPE) to speak on
this issue before making any major conclusions [10]. Some people are
thanking for tool that has some major flaws as pointed out by a well
respected cryptographer [11]
The fact that Olaf hasn't replied is a huge problem for my assurances
that this project is on track to fix these problems, I know that I am
not alone [13]. What is more shocking to me is the lack of understanding
about a protocol/security method being broken. It seems that many people
doing small tests of their own [14] find it to be acceptable because it
will fit their clients needs. Their own greed and the ease of setup
being the bottom line.
Let us make sure that this gets fix. Let us also make sure that this
situation is handled well and discussed openly.
Fil willing-to-contribute-in-whatever-way-he-can (however little that may be)