Ubuntu QA:
BlogBrainstormPackage status
Log in
Ubuntu QA
The Ubuntu community has contributed 13850 ideas, 66216 comments, 1283827 votes

Idea #6739: Get Bruce Schneier to audio the cryptographic features



up
2
down
Written by Eldmannen the 9 Apr 08 at 20:39. Category: Security.
Related to: Nothing/Others. Status: New
Description
Get cryptography professional and demigod Bruce Schneier to audit and certify the 'Crypto API' framework in the Linux kernel, and the crypto-related stuff such as IPsec, dm-crypt, block ciphers, hash functions, /dev/random, /dev/urandom, the PRNG, etc.

Then we can have the Bruce Schneier seal of approval; "The cryptographic features of this operating system are deemed secure by Bruce Schneier!".

Attachments
No attachments.


Duplicates


Comments
steve196 wrote on the 9 Apr 08 at 20:53
This would be far too much work for a single guy, even if his name is Bruce Schneier.
Finding security holes is primarily about looking everywhere. Ubuntu has the size of a cd and that is BIG if you have to audit it.

Eldmannen wrote on the 9 Apr 08 at 21:00
I am not saying to audit EVERYTHING.

I am talking about auditing the crypto-related stuff such as the Crypto API and perhaps IPsec, dm-crypt, block ciphers, hash functions, /dev/random, /dev/urandom, and the PRNG.

glotz wrote on the 9 Apr 08 at 23:09
So Bruce Schneier is the Chuck Norris of crypto?

Eldmannen wrote on the 10 Apr 08 at 00:13
glotz,
Yes. Head on the spike!

http://geekz.co.uk/schneierfacts/

* Bruce Schneier knows Alice and Bob's shared secret.
* Bruce Schneier knows the state of Schroedinger's cat
* Bruce Schneier's secure handshake is so strong, you won't be able to exchange keys with anyone else for days.
458 votes
* When Bruce Schneier observes a quantum particle, it remains in the same state until he has finished observing it.
* Bruce Schneier got a perfect score on his comp-sci degree. Just by writing Bruce Schneier for every answer.
* Bruce Schneier memorizes his one time pads
* Bruce Schneier can reverse any one-way cryptographic hash, just by staring it in the eye
* Bruce Schneier can straighten out an elliptic curve with nothing but his teeth.

notyetroot wrote on the 10 Aug 08 at 17:08
Instead of certifying like some software company, why not actually improve it? Anyway, US law restricts cryptography that's too strong, because the government is idiotic. +0.


Post your comment