[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: nsa and netscape



Bob Bruen writes:
# At yesterdays FNC  (Federal Networking Council) meeting it was 
# mentioned in passing that NSA has given Netscape a grant of $5 Million 
# (yes $5M) to beef up the security features of Netscape. More info will 
# be forthcoming on this.

david d `zoo' zuhn writes:
> FORTEZZA support is virtually required for any sort of new network
> authentication within the US DoD.  
> 
> The DoD pie is rather large, and I don't blame Netscape for trying to get
> a piece of it.  One can support FORTEZZA without giving in to GAK for
> non-FORTEZZA users.

For the moment I am inclined to agree that there's nothing terribly sinister
about this. I've just been flipping through
<a href="http://www.fnc.gov/fisp_sec_contents.html">the FNC's draft Federal 
Internet Security Plan (FISP)</a>. In particular it mentions:

------------
4.2 Internet Security Technology Development



     The IETF and other activities are currently expanding their efforts to
     develop and deploy technology standards to meet the growing security 
     needs of the Internet. However, these efforts must be accelerated and 
     facilitated by Government, since the Government has as much, if not
     more, interest in increasing the level of security capability in the 
     Internet as does any other segment of society.
[...]
Enhance Internet Application Security

     A number of key Internet applications have become central to agencies' 
     increasing Internet activities. Such key applications should be examined
     and, where appropriate, strengthened to the extent possible. Among the 
     applications that require high-priority attention are the following:
[...]
     Public Information Servers - Second only to email is the expanding use of
     Internet-based public information server methods, most visibly the World 
     Wide Web and the associated Mosaic/Linx client applications. 
     Unfortunately, there are a number of known security vulnerabilities 
     associated with the use of these applications.
----------------

I definitely do _not_ get a sense from anything in this document that 
installing GAK mechanisms is a major concern of the project. The NSA appears
to have a few people involved with the FNC, but not a great visible presence.

-Futplex <[email protected]>