{"id":174705,"date":"2015-01-15T09:03:55","date_gmt":"2015-01-15T14:03:55","guid":{"rendered":"http:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/nsa-so-sorry-we-backed-that-borked-crypto-even-after-you-spotted-the-backdoor.php"},"modified":"2015-01-15T09:03:55","modified_gmt":"2015-01-15T14:03:55","slug":"nsa-so-sorry-we-backed-that-borked-crypto-even-after-you-spotted-the-backdoor","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/nsa-2\/nsa-so-sorry-we-backed-that-borked-crypto-even-after-you-spotted-the-backdoor.php","title":{"rendered":"NSA: SO SORRY we backed that borked crypto even after you spotted the backdoor"},"content":{"rendered":"<p><p>    The NSA's director of research Michael Wertheimer says it's    \"regrettable\" that his agency continued to support Dual EC DRBG    even after it was widely known to be hopelessly flawed.  <\/p>\n<p>    Writing in Notices, a publication run by the American    Mathematical Society, Wertheimer outlined the history of the    Dual Elliptic Curve Deterministic Random Bit Generator (Dual EC    DRBG), and said that an examination of the facts made it clear    no malice was involved.  <\/p>\n<p>    Dual EC DRBG is a random number generator championed by the NSA    in the 2000s. Number generators     are an essential component of encryption systems; a weak    generator will leave encrypted data vulnerable to decoding by    an attacker.  <\/p>\n<p>    This random number generator was eventually approved as a    trustworthy algo by the US National Institute of Standards and    Technology (NIST), despite concerns that it    could be faulty, and RSA made it the default encryption systems    in its BSAFE toolkits. A     subsequent report suggested the NSA paid RSA $10m to    include the flawed algorithm  a claim RSA    denies.  <\/p>\n<p>    In 2007 two Microsoft security researchers, Dan Shumow and    Niels Ferguson, pointed out that there were serious flaws with    Dual EC DRBG, and that using it with elliptic curve points    generated by the NSA could create a \"trap door\" that would    allow encryption to be easily broken.  <\/p>\n<p>    \"With hindsight, NSA should have ceased supporting the Dual EC    DRBG algorithm immediately after security researchers    discovered the potential for a trapdoor. In truth, I can think    of no better way to describe our failure to drop support for    the Dual EC DRBG algorithm as anything other than regrettable,\"    Wertheimer    wrote [PDF].  <\/p>\n<p>    \"The costs to the Defense Department to deploy a new algorithm    were not an adequate reason to sustain our support for a    questionable algorithm. Indeed, we support NIST's April 2014    decision to remove the algorithm. Furthermore, we realize that    our advocacy for the Dual EC DRBG casts suspicion on the    broader body of work NSA has done to promote secure standards.\"  <\/p>\n<p>    The case doesn't prove the NSA is actively trying to subvert    crypto standards, Wertheimer argued, merely that a mistake had    been made and then rectified. He pointed out that the NSA was    keen to fund more mathematical research and  post September 11     this work was vitally needed.  <\/p>\n<p>    But Wertheimer's version of events isn't sitting well with some    experts in the field. Assistant research professor Matthew    Green of Johns Hopkins University Information Security    Institute in Maryland has     written a rebuttal to Wertheimer, pointing out several    holes in his story.  <\/p>\n<p>    For a start, Prof Green said problems with Dual EC DRBG systems    that used the NSA's elliptic curve points were first noticed    way back in 2004 by members of an ANSI standards committee, when NIST    was still considering backing the algorithm. Someone on the    panel even went as far as to file a patent    on breaking encryption using the system.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read the rest here:<\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2015\/01\/14\/nsa_sorry_we_borked_nist_encryption_well_sorry_we_got_caught\" title=\"NSA: SO SORRY we backed that borked crypto even after you spotted the backdoor\">NSA: SO SORRY we backed that borked crypto even after you spotted the backdoor<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The NSA's director of research Michael Wertheimer says it's \"regrettable\" that his agency continued to support Dual EC DRBG even after it was widely known to be hopelessly flawed. Writing in Notices, a publication run by the American Mathematical Society, Wertheimer outlined the history of the Dual Elliptic Curve Deterministic Random Bit Generator (Dual EC DRBG), and said that an examination of the facts made it clear no malice was involved <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/nsa-2\/nsa-so-sorry-we-backed-that-borked-crypto-even-after-you-spotted-the-backdoor.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[261463],"tags":[],"class_list":["post-174705","post","type-post","status-publish","format-standard","hentry","category-nsa-2"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/174705"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=174705"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/174705\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=174705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=174705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=174705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}