4 ms·
From the web page: "Recent press coverage has asserted that RSA entered into a 'secret contract' with the NSA to incorporate a known flawed random number gener
by rpedroso 13y ago
From the web page:
"Recent press coverage has asserted that RSA entered into a 'secret contract' with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation."
The emphasis is mine. This quote allows for the possibility that they entered into a contract with the NSA to incorporate a random number generator that was not yet known to be flawed.
- sigzero 13y agoUm, if it wasn't known to be flawed, why wouldn't they do it?
- wfunction 13y agoWhy the hell would the NSA offer MONEY for you to adopt their encryption proposal if it was actually legitimately good? It doesn't matter if you have any other information on the security of the algorithm; the fact that they're offering you money should speak for itself.
- dekz 13y agoBecause while the NSA would love to backdoor your application, they also want to be the only ones who backdoor your application. The NSA would still want to promote security to prevent other malicious attackers from being able to exploit a domestic corporation bad security. It's in the best interests of national security for the NSA to promote both good and/or backdoored algorithms for all allied nations and their corporations.
- eli 13y agoWell, the NSA has a track record of making public encryption algorithms stronger. They proposed changes to DES which puzzled researchers at the time, but years later were shown to significantly harden the algorithm against some attacks.
- thematt 13y agoI don't have the citation on hand right now, but if I recall correctly their recommendations strengthened DES against mathematical attacks, but weakened it against brute-force attacks.
- gizmo686 13y agoI don't know what it means to weaken DES against brute-force attacks, but, if I recall correctly, their changes did weaken it against linear crypto analysis. Their change was to replace the random constants of DES's s-boxes with their own constants. They have since then published the criteria that they used to generated these constants. Based on the fact that everything I have read on the subject, and talking with several cryptographers, says that the change was to strengthen DES against differential crypto-analysis, I think it is reasonable to believe that this is supported by looking at how they generated the constants.
- mnordhoff 13y agoNSA suggested decreasing DES's key size. IBM ultimately agreed to use effectively 56-bit* keys. This by definition makes brute force attacks easier. It was apparently criticized at the time, but it's worth noting that there's nothing secretive about it -- it's a basic and obvious element of the algorithm. The public cryptographic community started brute-forcing DES keys for fun in the '90s; with the NSA's budget, they could have been doing it from the beginning. * DES keys are 64 bits, but 8 bits are for parity, so the meaningful key length is 56 bits.
- wfunction 13y agoYes, I just read this yesterday I think.
- AnthonyMouse 13y agoThe NSA is really bizarre because they have two missions: 1) to break encryption and spy, and 2) to make better encryption so the enemy can't spy on the U.S. It makes sense if you think about it: Both goals are useful to Uncle Sam and both require the same skill set. The trouble is it obviously creates quite the conflict of interest.