Secret contract tied NSA and security industry pioneer
1–10 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#2Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
Re: Secret contract tied NSA and security industry pioneer
#3TLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit."
Dual_EC_DRBG was a NIST standard.
Re: Secret contract tied NSA and security industry pioneer
#4Lucky Green was the first to mention this: http://lists.randombit.net/pipermail/cryptography/2013-Septe...
Re: Secret contract tied NSA and security industry pioneer
#5Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
Assuming that the preference of which algorithm is used in an encryption standard can be influenced by $10 million, then I I'd say you read the article correctly. Very alarming...
Re: Secret contract tied NSA and security industry pioneer
#6The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane.
RSA, much like NIST, can not, and should not be trusted any longer. All of their customers should be warned, and advised to quit them ASAP. Companies need to learn this is just unacceptable.
Re: Secret contract tied NSA and security industry pioneer
#7$10Mi? That's a very cheap price for trashing your companies reputation.
More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.
Re: Secret contract tied NSA and security industry pioneer
#8> [...] but RSA said in a statement: "RSA always acts in the best interest of its customers [...]
True, you just have to keep in mind that their customer is the NSA.
Re: Secret contract tied NSA and security industry pioneer
#9TLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit." Dual_EC_DRBG was a NIST standard.
[deleted]
Re: Secret contract tied NSA and security industry pioneer
#10I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.