4 ms·
Alternately, it could just be that Certicom saw a means to profit off of an emerging standard by modifying it to support key escrow. It's not like key escrow in
by csandreasen 11y ago
Alternately, it could just be that Certicom saw a means to profit off of an emerging standard by modifying it to support key escrow. It's not like key escrow in general was something that no had thought of before in 2005. If this was an NSA backdoor, why would the NSA reveal it publicly by having Certicom patent it? Not to mention that it this was a horribly unpopular algorithm long before any suspicion of it being a backdoor. If it was an NSA campaign to break public cryptography, it was a miserable failure long before Snowden ever hit the scene.
- nitrogen 11y agoWasn't DualEC the default algorithm used by a bunch of RSA products that were incorporated elsewhere?
- csandreasen 11y agoDual_EC was the default PRNG for the RSA BSAFE library. The only actual numbers I've seen regarding how popular the library was this researcher's findings[1] in which he did a scan of 21.8 million IP addresses and managed to find 720 servers using it (to be fair, that's a lower bound as there were two implementations of BSAFE and only one was detectable remotely). It was generally easier use a PRNG provided by the OS or use an open source library for free. As a testament to how unpopular Dual_EC was, there was a bug in OpenSSL for years that prevented it from working at all when Dual_EC was enabled, and it wasn't discovered until after Snowden. [1] http://dualec.org/ http://dualec.org/
- tptacek 11y agoIn 10 years of doing software security assessments I saw a total of zero (0) systems use BSAFE. It may have been popular with government contractors. Later There was also a period during which the Red Hat Secure Server that shipped with Red Hat Professional linked against BSAFE. Its release timing doesn't square with Dual_EC though.