back
87 comments
I think Lotus Notes has a fascinating history, cryptographic shenanigans asides. As far as I'm aware it is still the most successful "offline first" / "local-first" application platform in widespread use today, complete with multi-master document replication, highly-configurable conflict resolution and rapid application development. These were revolutionary capabilities during the dialup era. The email client just happens to be the most popularly recognised groupware application outside of individual corporate firewalls.

The original vision was very lofty: https://web.archive.org/web/20180225100127/http://www.kapor....

"Notes should take the first major crack at the area of idea processors, textual databases, and hypertext systems."

I would love to see where an open source equivalent built for the modern age could take us... (CouchDB gave it a good shot!)

Still, I believe it's wrong to distract here from all the other important topics addressed by Ray Ozzie, who was aware of all the important issues even in 1996, and for historical context of the NSA key from the title, here is the relevant part from his speech he gave in 1996, about how Lotus implemented what was legally required from them:

"As you know, the U.S. government has defined its "maximum tolerance level" for exportable unescrowed cryptography at 40 bits. That is, because they generally permit the export of 40-bit products, the U.S. government is clearly already willing to deal with a 40-bit work factor in order to examine encrypted communications outside of this country.

So, the system that we're shipping in Lotus Notes Release 4 overseas is one that presents different work factors to different parties, hence the name.

Against crackers -- against the run-of-the-mill adversary trying to break a message -- the work factor is 64 bits, just like it is in the U.S. That is, in the new International Edition of Lotus Notes, bulk data keys are now 64 bits just as they are in our North American Edition that's sold in the U.S. and Canada.

But when the U.S. Government needs access to a communications stream overseas encoded by the international edition of Lotus Notes, they are no worse off - and no better off - than they are today - they have to crack 40 bits."

Since then, the goals of different interest groups haven't changed, and we all now about many new possibilities and about the surveillance actually being done and the dangers that the changes brought and can bring.

Other comments here in the other threads are about these more recent issues and the readers should note them too.

Duly noted - sorry for diluting attention.

Connecting both aspects though: arguably the failure of subsequent technologies to fulfill the decentralized Notes vision has facilitated the rise of extreme centralization and greatly exacerbated our privacy problems.

This compromise was also used by WebTV in Japan in 1997. I vaguely recall that client/server comms were protected by 56 bit symmetric encryption, and that in international mode, 16 bits of the session key were explicitly sent in cleartext to respect the 40 bit limit. WebTV in the USA was full strength crypto, at least as strong as the little MIPS processor in the settop box could manage.
I was in IT support during the Notes era working alongside notes devs. It was a grand vision. Perhaps too grand. Notes was supposed to do much more but I never saw it actually deliver in production. And between Exchange and GroupWise it got its ass kicked.
It couldn’t survive under IBMs care as they declined, which was a shame.

I worked in places that did everything from comprehensive correspondence management to configurators for factory systems. It’s a pretty powerful set of tools.

The Microsoft world was much more primitive until the mid 2000s. GroupWise and Notes shops didn’t have the ridiculous mailbox size limitations that Exchange had up until about a decade ago. Even today, the dumpster fire that is SharePoint is arguably inferior to what Notes was shipping in 1996 in some ways.

Notes within IBM fulfilled it's vision. distributed app running on the platform making large use of replication and delivered as needed where the norm.

it suffered of development inconsistency if anything, much like java applets

turns out if some platform access is too easy, everyone starts publishing crapware

Not open source, but it strikes me that Notion.so, Coda and AirTable might be examples of centralized, online "Notes-replacements", all inspired by how Google Docs (Writely) let you collaborate and perform conflict resolution in the cloud a bit over a decade ago.
Can't speak for the others, but Notion.so conflict resolution is significantly less sophisticated than Google Docs' operational transforms (I think that's what they're using).
CouchDB is still thriving. It's adopting FoundationDB in 4.0... https://www.youtube.com/watch?v=SjXyVZZFkBg good talk on that here at FoundationDB Summit
This backdoor would be the equivalent of a combined outlook and a .net app being compromised.

It might be hard to imagine the scope that notes encompassed in its day... it simultaneously provide mobile, offline first apps with usable data replication.. among a few features that might be surprising:

Notes had a few more unique features that modern devs might cringe to hear isn’t all that new:

- Notes provided early Nosql/relational data. Everything was a document and have fun stitching it all together in views. The NotesSQL layer would add an ODBC based layer to simulate relational dbs.

- When Lotus added Domino to Notes, it was among the first that could deliver the same Lotus Notes code to a web application. Early write once, deploy anywhere (woda). Existing apps that only ran inside Notes now worked in a web browser.

All this.. for a piece of software that was originally an email server and built workflow around it. all compromised.

"[O]riginally an email server" gets it rather backwards. It was more like a BBS/forum hosting platform that had messaging between boards (databases), with user email as a special case.
While interesting, this is way off topic and should not be rated above discussion about the nefarious cryptographic behaviour of the business.
> nefarious cryptographic behaviour of the business.

It was not just "business" then: the export of strong encryption had the same status as the export of weapons in the U.S. laws at that time. See the other threads here.

I strongly agree! When I was first thrust into Notes administration (version 3 no less!) I hated it. But combined with version 4 and using it more, the power hiding behind the ugly GUI became more and more apparent. I've yet to find a system that can handle unstructured data or workflows with field level replication, role based security and encryption as quickly or as elegantly as with Lotus Notes - UI warts and all. Indeed I have some workflows that I could probably automate myself in a week or so but am in the process of getting dev support to accomplish some other way.

It's too bad IBM didn't really fix the non-windows feel of Notes until version 8. By then Exchange had clearly won - should have never happened. The Notes server back end is still far more robust than Exchange. Oh well...

Hated Notes. I left companies because of it.
As mentioned in The Friendly Orange Glow, it was started by people who worked on the PLATO system at the University of Illinois which added its Notes discussion system in 1973. PLATO ran until 2015.
You should check out Couchbase Mobile and Couchbase Enterprise Edition then!
Just don't use couchbase for larger amounts of data. In fact as a database it is mediocre at best. NoSQL, when it even works, is slow. Bulk operations are slow. Memcache backend gets constantly killed by oom killer. Rebalancing cluster is manual. Indices dont work. Timeouts are specified in microseconds. Documentation is lacking. maybe that's changed since 5.3, but bad taste lingers on.
Thank you for the link. I found barrkel’s comment[1] particularly moving:

> A non-authoritarian government is an historical anomaly. It's a ball balanced on top of a hill, pushed there by the deaths of millions, and kept there by the vigilance of those who care. Please start caring.

[1]: https://news.ycombinator.com/item?id=5847789

> It's a ball balanced on top of a hill, pushed there by the deaths of millions, and kept there by the vigilance of those who care.

I feel like the ball has started to roll downhill, and is rapidly gaining speed, but that the only folks who can stop it are too dug into their own partisanship to take a look around them and do something.

That, or they desire authoritarianism. I've frankly been surprised at the number of people I've talked to in the past few years who seem to like the idea of a strongman leader. I always assumed everyone but the most extreme wings of the right and left believed in liberty and democracy, but I now see that was I mistaken.

June 2013 discussion's top post is by the person involved in making Lotus Notes (Ray Ozzie). His comment - which tangents into issue of privacy and data control - is also prescient, and could have just as well been written today, which is a sad testament to how things didn't get any better in the past 6 years.
As well in this thread.
https://en.wikipedia.org/wiki/RSA-768#RSA-768 was factored almost exactly 10 years ago. I wonder if anyone has tried factoring this one? Hopefully the NSA doesn't still use this key...
I have to chime in that I too have a love/hate relationship with Lotus Notes. I started using it back in ‘98. It was massively empowering to build functional and secure workflow apps, and do so faster than you could wireframe on other platforms. I rolled it out to thousands of users successfully. It was truly visionary in scope. However, the performance was mediocre and there were many really poor oversights and omissions. Often I would go to program some base operation and find out you just “can’t get there from here“. It seemed their QC process hadn’t really given much though to global calendar synchronization or to very basic needs like printing landscape. I still use it daily for a large (funeral) industry specific app. and it has run flawlessly for a decade (albeit making API calls to MS Office and the web). I go to program new things in React or even Rails and am disappointed that you have to reinvent things that were built into Notes 20 yrs ago.
They embedded an entire X.509 cert in it? I wonder if the Lotus devs just made an X.509 cert out of key material they were given or if the NSA actually minted it with that subject.
I have to think the engineers were maliciously complying with the directive. It's far too dark a joke to be honorific.
Ray Ozzie confirmed in a thread below that it was done by Charlie/Al/him as a joke.
The cert has to be signed by something, usually its own key. If it was self-signed then the NSA signed it with those details.
I thought at first the NSA made the Orwell reference, but it looks just the lotus notes devs did?

I guess that's...reassuring.

Charlie, Al, and I were just trying to maintain a sense of humor in fairly tough times, knowing that the first who would see the key would be the folks we were working with at the ministry.
That's why Ray Ozzie's comment on a previous submission is so significant: https://news.ycombinator.com/item?id=5847189
Are you sure? Looks like the Orwell references are encoded into the NSA public key, so I assumed it was the NSA that made the joke.
This is a bit spooky. I wonder if the engineers responsible were just trying to be cute, or "reaching out" in a way.
Probably just having a joke. Human psychology is complex, no matter what positive or negative things we do to each other.
Posted by the man himself before your reply:

> Charlie, Al, and I were just trying to maintain a sense of humor in fairly tough times, knowing that the first who would see the key would be the folks we were working with at the ministry.

Inslaw's legal case-management system "PROMIS" also had a back door, put there by Michael Riconosciuto, under the direction of Earl Brian of Inslaw's competitor Hadron. Attorney General Edwin Meese's Department of Justice drove Inslaw out of business, pirated their software, and distributed it with the back door to Israel and 80 other countries so the US could spy on them. Danny Casolaro was investigating it, but suddenly died of an unlikely apparent suicide.

If Trump really wanted to investigate corruption in the deep state, he should start by interrogating his good buddy Edwin Meese, instead of honoring him with the Medal of Freedom. He could also ask his own Attorney General Bill Barr why he whitewashed the Justice Department last time he had it investigate itself. (Actually, maybe that's why he hired Barr!)

https://www.npr.org/2019/10/08/768136964/trump-to-honor-form...

>Trump To Honor Former Reagan Attorney General, Who Left Government Under Ethics Cloud

http://nothingmajor.com/journal/775-meese-is-a-pig-returns/

>Experts Agree! MEESE is a PIG

https://threadreaderapp.com/thread/1179701030520524801.html

>INSLAW/PROMIS links

>Barr refused to appoint an independent counsel to the Inslaw case, relying instead on a retired federal judge, in this case Nicholas Bua, who reported to Barr alone. In other words, the DOJ was responsible for investigating itself.

https://en.wikipedia.org/wiki/PROMIS_(software)

https://en.wikipedia.org/wiki/Inslaw

https://en.wikipedia.org/wiki/Michael_Riconosciuto

https://en.wikipedia.org/wiki/Earl_Brian

https://en.wikipedia.org/wiki/Danny_Casolaro

>The Justice Department had dishonestly conspired to "drive Inslaw out of business 'through trickery, fraud and deceit'" by withholding payments to Inslaw and then pirating the software.

>The Justice Department had done so in order to modify PROMIS, originally created to manage legal cases, to become a monitoring software for intelligence operations.

>"PROMIS was then given or sold at a profit to Israel and as many as 80 other countries by Dr. Earl W. Brian, a man with close personal and business ties to then-President Ronald Reagan and then-Presidential counsel Edwin Meese."

>"There appears to be strong evidence, as indicated by the findings in two Federal Court proceedings as well as by the committee investigation, that the Department of Justice 'acted willfully and fraudulently,' and 'took, converted and stole,' Inslaw's Enhanced PROMIS by 'trickery fraud and deceit.'"

>A book written in 1997 by Fabrizio Calvi and Thierry Pfister claimed that the National Security Administration (NSA) had been "seeding computers abroad with PROMIS-embedded SMART (Systems Management Automated Reasoning Tools) chips, code-named Petrie, capable of covertly downloading data and transmitting it, using electrical wiring as an antenna, to U.S. intelligence satellites" as part of an espionage operation.

>"another undeclared mission of the Justice Department's covert agents was to insure that investigative journalist Danny Casolaro remained silent about the role of the Justice Department in the INSLAW scandal by murdering him in west Virginia in August 1991."

>Inslaw's new allegations described the Justice Department dispute with Inslaw as part of a broad conspiracy to drive Inslaw into bankruptcy so that Earl Brian, the founder of a venture capital firm called Biotech (later Infotechnology), could acquire Inslaw's assets, including its software Promis. Inslaw owner William Hamilton told PSI investigators that Brian had first attempted to acquire Inslaw through a computer services corporation he controlled, called Hadron. Hamilton said that he rejected an offer from Hadron to acquire Inslaw, and that Brian then attempted to drive Inslaw into bankruptcy through his influence with Attorney General Edwin Meese.

https://www.wired.com/1993/01/inslaw/

>The INSLAW Octopus

>Software piracy, conspiracy, cover-up, stonewalling, covert action: Just another decade at the Department of Justice

>The House Judiciary Committee lists these crimes as among the possible violations perpetrated by "high-level Justice officials and private individuals":

>> Conspiracy to commit an offense

>> Fraud

>> Wire fraud

>> Obstruction of proceedings before departments, agencies and committees

>> Tampering with a witness

>> Retaliation against a witness

>> Perjury

>> Interference with commerce by threats or violence

>> Racketeer Influenced and Corrupt Organizations (RICO) violations

>> Transportation of stolen goods, securities, moneys

>> Receiving stolen goods

https://www.muckrock.com/news/archives/2017/may/16/FBI-promi...

>The Undying Octopus: FBI and the PROMIS affair Part 1 35 years later, file reveals dropped leads and confirmed allegations in “the scandal that wouldn’t die”.

>Inslaw’s attorneys, which included Elliot Richardson, who had previously resigned from the DOJ rather than comply with President Nixon’s orders to fire the Watergate Special Prosecutor Archibald Cox, repeatedly demanded a special prosecutor be appointed to investigate the matter, along with its numerous connections that implicated officials such as Ed Meese, who were in turn allegedly connected to affairs such as Iran-Contra and Reagan’s October Surprise.

The perils of "Cloud Computing" in the 80's:

https://en.wikipedia.org/wiki/Inslaw#Contract_disputes_and_I...

> There were also disputes over service fees. During the first year of the contract, the DOJ did not have the hardware to run Promis in any of the offices covered by the contract. As a stopgap measure, Inslaw provided Promis on a time-share basis through a Vax computer in Virginia, allowing the offices to access Promis on the Inslaw Vax through remote terminals, until the needed equipment was installed on-site. EOUSA claimed that Inslaw had overcharged for this service and withheld payments.

O=MiniTruth CN=Big Brother :D love it
Was it systematically leaking the same 24 bits (encrypted to the NSA public key), or a random contiguous selection of 24 bits?

in the second case having just a few documents would result in only the NSA being able to decrypt without even brute forcing...

Does anyone else find it ironic that cypherspace.org doesn't support https?
So the fact that most crypto export controls are gone now means NSA can crack everything now right?
The export controls weren't relaxed particularly willingly.

https://en.wikipedia.org/wiki/Bernstein_v._United_States

Well DOH!
> the NSA public key had an organizational name of "MiniTruth", and a common name of "Big Brother"

> the Ministry of Truth was the agency who's job was propaganda and suppression of truths that did not suit the malignant fictional future government in the book, and "Big Brother" was the evil shadowy leader of this government.

"Are we the baddies?", said nobody at the NSA.

Seriously, this is kind of blatant. I could see them using the phrase "Big Brother", because it has become a common saying and lost some of its edge. But not Ministry of Truth, that only has one meaning and it's terrifying. It literally means "ministry of lying to the people and denial of truth". There is no reading of the book, no matter how superficial, that the term "Ministry of Truth" is anything but overtly sarcastic.

What does this come from? Is it edgy young people (young back then), picking these names? Even if tongue-in-cheek, it has enormous consequences on the culture inside a rather insulated work environment of a job that really should be one of solemn responsibility.

> What does this come from?

Do some reading of the threads here + links to previous discussions. Ray Ozzie (one involved) has been commenting.