It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
RSA warns developers not to use RSA products
11–20 of 81 posts
Re: RSA warns developers not to use RSA products
#12It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
Re: RSA warns developers not to use RSA products
#13Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
Re: RSA warns developers not to use RSA products
#14The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
His answers are post-hoc justifications. The real reason they picked it was because they wanted to make money on sweet, sweet government contracts, and the easiest way to do that is to just do everything NIST says to the letter.
Re: RSA warns developers not to use RSA products
#15Re: RSA warns developers not to use RSA products
#16Earlier quoted context omitted.
This was actually going to be the first thing I posted when I read this link. tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard. Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive…
He's been trying to downplay the importance of the leaks since it first started, so what did you expect.
Re: RSA warns developers not to use RSA products
#17It irks me that many people are calling this a backdoor. It's not. It's a vulnerability. You have to exploit it to get in.
Thats a backdoor by most descriptions. This isn't just a bug.
Re: RSA warns developers not to use RSA products
#18Hasn't tptacek posted "nothing to see here" regarding this issue on HN a half dozen times because "nobody uses it"? :)
But I also expressed the view that no one would have used this. I guess it makes a lot more sense now: It seemed weird to put it in the standard, as no one was going to just use it. I'd been guessing that they hoped that it would be made an option and then they could do some negotiation attack to force it. I was missing a more obvious explanation: Someone was already willing to ship it, but they wanted the plausible denyability of it being a standard, because it looked too suspect otherwise.
Re: RSA warns developers not to use RSA products
#19[deleted]
By the way, the 'less-than-technically-competent journalist' here is Matthew Green, a cryptographer. So I think he's plenty technically-competent. Also, they're called elliptic curves, not 'elliptical' curves.
Re: RSA warns developers not to use RSA products
#20The RSA CTO's answers are hilarious. He can't really be that clueless as the CTO of a security firm, can he? That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
Especially the part about KDFs being deliberately slow, and according to him that somehow implies that RNGs should also be slow. Whut? This guy is really a CTO?
If a system's seed is weak, one attack is to try all likely seeds, run them through the PRNG to generate keys, and see if any of the keys work. A slow PRNG indeed slows down this process.
For instance, it would have slowed down the attack on the Taiwan Cryptocards, which exploited patterns in the seed that appear directly in the key, reported here: http://smartfacts.cr.yp.to/smartfacts-20130916.pdf