4 ms·
NSA themselves have used Dual_EC_DRBG (which can be distinguished from a PRF even if you don't have the 'backdoor key': it's not just backdoored and slow, it's
by AlyssaRowan 11y ago
NSA themselves have used Dual_EC_DRBG (which can be distinguished from a PRF even if you don't have the 'backdoor key': it's not just backdoored and slow, it's bad - and they know that). GCHQ behaves even worse and is at this point almost entirely out of control.
In either case, I feel information assurance and signals intelligence arms really should never have been the same agency: they are roles entirely at odds with each other and do not seem to even have their own governments' equities properly balanced, nor their recommendations always having been given in good faith. So be cautious drawing any conclusions from their advice.
Unfortunately, that is not the sort of 'reform' that either government is interested in, particularly my own. It's quite depressing, really.
- rdtsc 11y ago> NSA themselves have used Dual_EC_DRBG That actually makes sense because of the way it was backdoor-ed. What they did there is the golden standard of subverting and backdoor-ing a crypto algorithm: go through a standards body, backdoor-ed it by using a public-private key. They hold the private key. Encourage others to use the system as much as they can (which includes showing the world that they themselves use it). NSA have been having dreams of key escrow forever. It seems since the 90s, that dream was further and further from reality. But they didn't completely give it up. Dual_EC_DRBG was effectively becoming that key escrow they wanted for all the system that used it and they got to keep the private key and thus have a high enough assurance others won't use their backdoor. Whoever was in charge of that operation, was probably patting themselves on the back every morning after waking up.
- tptacek 11y agoThat's true, but lots of things are bad in ways that probably aren't exploitable, and NSA is well positioned to make judgement calls like that.