3 ms·
Saw this pointed out in an LWN comment: > Apparently, RSA Security BSAFE Share for Java 1.1 has DUAL_EC_DRBG as a default: > "The default Pseudo Random Number
by lambda 13y ago
Saw this pointed out in an LWN comment:
> Apparently, RSA Security BSAFE Share for Java 1.1 has DUAL_EC_DRBG as a default:
> "The default Pseudo Random Number Generator (PRNG) is the Dual EC-DRBG using a P256 curve with prediction resistance off."
> I didn't find an obvious link for the equivalent C/C++ library documentation, but the RSA BSAFE CNG Cryptographic Primitives Library 1.0 FIPS 140-1 Security Policy document from RSA Security at the NIST site says (p.14):
> "The Module provides a default RNG, which is the Dual EC DRBG, using a P256 curve and SHA-256."
https://lwn.net/Articles/566329/ https://lwn.net/Articles/566329/
So yes, there are real products out there using Dual EC DRBG. In other news, never trust any crypto from RSA Security. After the SecureID fiasco, and this, it's pretty clear that they are not worth trusting for anything security related.