I use one of these tokens for work. Spying is one thing but destroying encryption is another evil thing to do. If the NSA has introduced bugs in crypto then who's to say someone else can exploit the same crypto.
Secret contract tied NSA and security industry pioneer
11–20 of 346 posts
Re: Secret contract tied NSA and security industry pioneer
#12The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…
Re: Secret contract tied NSA and security industry pioneer
#13TLDR: "RSA's contract made Dual Elliptic Curve the default option for producing random numbers in the RSA toolkit." Dual_EC_DRBG was a NIST standard.
Re: Secret contract tied NSA and security industry pioneer
#14Perhaps I am not reading the article correctly, but it sounds to me like RSA products can no longer be trusted.
At least that's the message that comes through loud and clear in the rest of the world.
Re: Secret contract tied NSA and security industry pioneer
#15"RSA BSAFE Crypto Kernel offers versions of popular cryptographic algorithms optimized for both small code size and high performance. Unlike alternatives such as open source, our technology is backed by highly regarded cryptographic experts." [emphasis added]
Re: Secret contract tied NSA and security industry pioneer
#16$10Mi? That's a very cheap price for trashing your companies reputation. More importantly, it confirms that DRBD is backdoored or at least weak enough to be subverted.
Re: Secret contract tied NSA and security industry pioneer
#17Re: Secret contract tied NSA and security industry pioneer
#18The end of RSA (the company)? I find it absurd that a security company no less, would hear many veteran cryptographers say this is backdoored a decade ago, and still going ahead and using it - as the default! Who stakes the whole reputation of their company in the field for a meager $10 million (I assume RSA was pretty big back then, too)? It's insane. RSA, much like NIST, can not, and should not be trusted any longe…