6 ms·
> We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have o
by wfunction 13y ago
> We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it.
Liars. They publicized the $10 million deal?!
- icegreentea 13y agoNo, you're misinterpreting. They're claiming that: a) They have always had a relationship with the NSA as a vendor, and as a number of the security committee b) They have never attempted to hide a) c) As part of a) they have never signed a "secret contract" (for the mentioned 10 million) That's their claim. Maybe they're lying about c), but you're barking up the wrong tree. (edited for formatting)
- rpedroso 13y agoFrom the web page: "Recent press coverage has asserted that RSA entered into a 'secret contract' with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation." The emphasis is mine. This quote allows for the possibility that they entered into a contract with the NSA to incorporate a random number generator that was not yet known to be flawed.
- sigzero 13y agoUm, if it wasn't known to be flawed, why wouldn't they do it?
- wfunction 13y agoWhy the hell would the NSA offer MONEY for you to adopt their encryption proposal if it was actually legitimately good? It doesn't matter if you have any other information on the security of the algorithm; the fact that they're offering you money should speak for itself.
- dekz 13y agoBecause while the NSA would love to backdoor your application, they also want to be the only ones who backdoor your application. The NSA would still want to promote security to prevent other malicious attackers from being able to exploit a domestic corporation bad security. It's in the best interests of national security for the NSA to promote both good and/or backdoored algorithms for all allied nations and their corporations.
- eli 13y agoWell, the NSA has a track record of making public encryption algorithms stronger. They proposed changes to DES which puzzled researchers at the time, but years later were shown to significantly harden the algorithm against some attacks.
- thematt 13y agoI don't have the citation on hand right now, but if I recall correctly their recommendations strengthened DES against mathematical attacks, but weakened it against brute-force attacks.
- gizmo686 13y agoI don't know what it means to weaken DES against brute-force attacks, but, if I recall correctly, their changes did weaken it against linear crypto analysis. Their change was to replace the random constants of DES's s-boxes with their own constants. They have since then published the criteria that they used to generated these constants. Based on the fact that everything I have read on the subject, and talking with several cryptographers, says that the change was to strengthen DES against differential crypto-analysis, I think it is reasonable to believe that this is supported by looking at how they generated the constants.
- mnordhoff 13y agoNSA suggested decreasing DES's key size. IBM ultimately agreed to use effectively 56-bit* keys. This by definition makes brute force attacks easier. It was apparently criticized at the time, but it's worth noting that there's nothing secretive about it -- it's a basic and obvious element of the algorithm. The public cryptographic community started brute-forcing DES keys for fun in the '90s; with the NSA's budget, they could have been doing it from the beginning. * DES keys are 64 bits, but 8 bits are for parity, so the meaningful key length is 56 bits.
- wfunction 13y agoUh, money is a key part of the relationship. If they kept it secret then they kept the most crucial part of the relationship secret.
- icegreentea 13y agoWell, they're clearly claiming that the "secret contract" as reported did not exist. If you're going to call them out on being liars about that (go for it!), might want to make it less ambiguous. For all its worth, I think RSA probably did help out the NSA with Dual EC DRBG, but: a) Until I see some source documents from Snowden's stash, it's going to be all very annoying because until you see the terms of the contract (and no, you can't just go by some journalist's summary), you have no idea what RSA/NSA are dancing around b) Whatever deal there was was probably set up in some fun way to make it all nicely deniable and even plausible sounding.
- mnordhoff 13y ago> Well, they're clearly claiming that the "secret contract" as reported did not exist. Crap. They're only denying a carefully-worded strawman. They leave open: 1.) Adding support for a known-flawed PRNG for free and then entering into a secret contract with the NSA to make the already-supported PRNG the default. 2.) Entering into a secret contract with someone else (FBI?) to "incorporate" a known-flawed PRNG. 3.) Entering into a secret contract with the NSA to use a PRNG that they didn't yet know to be flawed because they didn't look at it. etc... Edit: Pointed out first by https://news.ycombinator.com/item?id=6952801 https://news.ycombinator.com/item?id=6952801. Edit: You're right, they did deny it 'as reported', with "Recent press coverage has asserted ...". This could involve a creative reading of "[r]ecent press coverage", or a lie. Edit: Also, "Crap." wasn't directed at you. I'm sorry. It was directed at RSA; these stories always get me in a lather.
- Zancarius 13y agoThe other thing that gets me is what while they sort of hint that there was no such secret contract, they simultaneously (and rather clearly) state that they cannot divulge customer contracts. So, whether or not it's a "secret" contract is moot; they aren't going to release information about any and all contracts. I guess that effectively makes them all secret, but it seems to me that debating whether or not these contracts are or are not secret is a pointless endeavor. We cannot find out the details of them through RSA (they are contractually obligated not to provide this information), so we must instead rely on the leaked documents Snowden has been providing, assuming it's true. And it probably is. I think the real kicker here isn't that RSA was intentionally including maliciously modified algorithms as much as the NSA simply bribed^Woffered them $10 million to, err, "prioritize" its inclusion. This is probably more a lesson on distrusting government offers for lucrative contracts in exchange for nifty tools more than anything, IMO.
- bmelton 13y agoThat can be pared back to a slightly more accurate state. a) They have always had a relationship with the NSA as a vendor, b) That relationship is open. C is only implied. The NSA may have paid them $10mm, but because of B, that would not count as a 'secret deal', just a deal that was not publicized.