Live data from Hacker News

A Patent From 2004 Describes Dual EC As Key Escrow

twitter.com

11–20 of 41 posts

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#11
post #2

Been waiting a little while for this one to come out. Key escrow schemes were the establishment answer to the problem of crypto enabling crime. The idea was that strong crypto would be outlawed, and the government would instead provide regulated crypto that would include overt backdoors for lawful access. Thankfully, that idea perished in the crypto wars of the '90s. One line of reasoning about Dual EC, the PKRNG tha…

Why didn't you come out with it?

What a weird question.

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#12
post #2

Been waiting a little while for this one to come out. Key escrow schemes were the establishment answer to the problem of crypto enabling crime. The idea was that strong crypto would be outlawed, and the government would instead provide regulated crypto that would include overt backdoors for lawful access. Thankfully, that idea perished in the crypto wars of the '90s. One line of reasoning about Dual EC, the PKRNG tha…

http://security.stackexchange.com/questions/43164/which-prod...

Dual_EC_DRBG is actually used in real life products:

> we know the RSA BSAFE library uses Dual_EC_DRBG (...) by default, I would guess that this would be the main vector. > As for the use of BSAFE, I can easily find (hint: use your favourite search engine to search for the terms "This product includes" "RSA BSAFE") implementations, oddly skewed towards imaging and gaming devices: surprisingly many printer/copier/fax devices use BSAFE, though for unknown purposes. Including Ricoh, Minolta, Océ/Canon, Brother, Fuji/Xerox, Epson ... Your Playstation (PDF), PSP, or your Nintendo DS wifi (PDF) Software from Adobe, Hitachi, Oracle and HP Some Nokia phones(PDF)

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#13
post #8

Earlier quoted context omitted.

Why didn't you come out with it?

I imagine professional courtesy, it's considered incredibly rude to disclose another researchers discovery before they've announced it.

Sorry. I interpreted tptacek's first line as that he'd known about the patent and what it contained independently for "a little while". (It was a patent after all. Isn't that public information?)

Or was the news not the existence of the patent referenced on the tweet?

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#15
This patent was originally owned by Certicom, now part of Blackberry. One of the inventors was Scott Vanstone who's excellent book, Handbook of Applied Cryptography lives on my desk.

The patent seems to indicate that Dual EC is known to be usable for escrow, something that the NSA surely knew. But given the pedigree of the authors, it must have been known by a bunch of other people well before the March 2013 publication date.

There's something odd going on here.

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#17
post #2

Been waiting a little while for this one to come out. Key escrow schemes were the establishment answer to the problem of crypto enabling crime. The idea was that strong crypto would be outlawed, and the government would instead provide regulated crypto that would include overt backdoors for lawful access. Thankfully, that idea perished in the crypto wars of the '90s. One line of reasoning about Dual EC, the PKRNG tha…

Avoiding the backdoor does not require changing the points (and possibly getting in patent trouble). Even with malicious points, truncating enough bits out of each x coordinate is enough to thwart the attack. I don't know why this is not pointed out more often.

I'm honestly far more surprised by finding out that another factorization-based (Micali-Schnorr) DRBG standard comes with 'default' public keys.

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#18
post #2

Been waiting a little while for this one to come out. Key escrow schemes were the establishment answer to the problem of crypto enabling crime. The idea was that strong crypto would be outlawed, and the government would instead provide regulated crypto that would include overt backdoors for lawful access. Thankfully, that idea perished in the crypto wars of the '90s. One line of reasoning about Dual EC, the PKRNG tha…

> Thankfully, that idea perished in the crypto wars of the '90s

Did Lotus Notes ever get rid of key escrow? IIRC they used BSAFE.

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#19
post #8

Earlier quoted context omitted.

I imagine professional courtesy, it's considered incredibly rude to disclose another researchers discovery before they've announced it.

Sorry. I interpreted tptacek's first line as that he'd known about the patent and what it contained independently for "a little while". (It was a patent after all. Isn't that public information?) Or was the news not the existence of the patent referenced on the tweet?

I can't speak for tptacek, but what I think he means (when he says "Been waiting a little while for this one to come out.") is that he's been waiting a while for confirmation that Dual EC was explicitly designed as an RNG with an escrow system.

I don't think he meant that he knew about it - instead, he was saying that there was evidence to be found that would demonstrate this.

But I'm not tptacek, so who knows what he really means.

Re: A Patent From 2004 Describes Dual EC As Key Escrow

#20
post #11

Earlier quoted context omitted.

Why didn't you come out with it?

What a weird question.

The first sentence of your post could be interpreted to mean that you knew about this for "a little while" but decided not to inform the rest of us, in which case I don't think it's that weird to ask "why didn't you tell us?"
Post reply on HN