3 ms·
I think that this is overall a good paper, but I have one major issue with it. They quote from a presentation given by Richard George from the NSA twice in this
by csandreasen 11y ago
I think that this is overall a good paper, but I have one major issue with it. They quote from a presentation given by Richard George from the NSA twice in this paper. I had seen that presentation before, and in it he speaks to why the algorithm was put in the NIST standard[1] and directly answers a question regarding how the P and Q in the standard were generated[2].
His claim was that the NSA had issues in the past getting encryption devices certified for use in unclassified environments because NSA controlled the certification process for classified encryption algorithms (which were themselves generally classified), but NIST controlled the certification for government use in unclassified settings (and these algorithms could not be classified). The NSA wanted to be able to use an existing algorithm in an unclassified setting. As the article does point out, Mr. George stated that the algorithm was intended primarily for their own internal use and user should be able to use any P and Q, though they needed their own P and Q certified for their own use.
Later on in the presentation he states that the P and Q were both non-deterministically generated random numbers. He states that the NSA has office devoted specifically to producing random numbers for their own use, and they just got the P and Q from there.
Whether or not you believe this claim is an entirely different and reasonable question (there's no real way to verify it), but why bother quoting him if you're going to selectively quote like this? If the P and Q are in fact purely random as Mr. George claims, Dual_EC goes from being a grand conspiracy to just a slow, crappy PRNG. I think selectively quoting to make this guy sound more sinister makes it look like the author wants it to be a grand conspiracy and just undermines the argument.
Btw., the entire presentation is worth watching if you have time - he goes into the history of DES, espionage between the US and Soviets, getting cryptographic equipment working in tanks, etc...
[1] http://vimeo.com/97891042 http://vimeo.com/97891042 (jump to 57:53)
[2] Same video, jump to 30:14
- tptacek 11y agoThere is now strong circumstantial evidence about Dual_EC: Certicom had contemporaneous patent filings for key escrow using PKRNG. It is weird that Certicom had a patent for key escrow using backdoored RNGs, and weird that they had a patent for escrow using backdoored PKRNGs, but a contemporaneous patent for elliptic curve PKRNG key escrow? https://www.google.com/patents/US8396213 https://www.google.com/patents/US8396213
- csandreasen 11y agoAlternately, it could just be that Certicom saw a means to profit off of an emerging standard by modifying it to support key escrow. It's not like key escrow in general was something that no had thought of before in 2005. If this was an NSA backdoor, why would the NSA reveal it publicly by having Certicom patent it? Not to mention that it this was a horribly unpopular algorithm long before any suspicion of it being a backdoor. If it was an NSA campaign to break public cryptography, it was a miserable failure long before Snowden ever hit the scene.
- nitrogen 11y agoWasn't DualEC the default algorithm used by a bunch of RSA products that were incorporated elsewhere?
- csandreasen 11y agoDual_EC was the default PRNG for the RSA BSAFE library. The only actual numbers I've seen regarding how popular the library was this researcher's findings[1] in which he did a scan of 21.8 million IP addresses and managed to find 720 servers using it (to be fair, that's a lower bound as there were two implementations of BSAFE and only one was detectable remotely). It was generally easier use a PRNG provided by the OS or use an open source library for free. As a testament to how unpopular Dual_EC was, there was a bug in OpenSSL for years that prevented it from working at all when Dual_EC was enabled, and it wasn't discovered until after Snowden. [1] http://dualec.org/ http://dualec.org/
- tptacek 11y agoIn 10 years of doing software security assessments I saw a total of zero (0) systems use BSAFE. It may have been popular with government contractors. Later There was also a period during which the Red Hat Secure Server that shipped with Red Hat Professional linked against BSAFE. Its release timing doesn't square with Dual_EC though.