| Thread Tools |
24th September 2013, 07:24 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,514
| RSA warns of NSA encryption sabotage RSA has warned thousands of customers about using software that relies on a weak mathematical formula developed by the National Security Agency. RSA, the security arm of storage company EMC, told customers that a toolkit for developers had a default random number generator using the weak formula. It is suggesting that customers should switch to one of several other formulas in the product. The move follows a report in the New York Times which showed that among Snowden's cache of documents, the agency used its public participation setting voluntary cryptography standards to push for a formula it knew it could break. The National Institute of Standards and Technology accepted the NSA proposal in 2006 as one of four systems acceptable for government use. The NSA said it would reconsider that inclusion in the wake of questions about its security. Developers who used RSA's "BSAFE" kit wrote code for web browsers, other software, and hardware components to increase security. At the centre of the system are random numbers and the ability to guess what they are renders those formulas vulnerable. The NSA-promoted formula was so odd that even at the time some felt it was flawed by design. Reuters claims that the NIST accepted it in part because many government agencies were already using it. However, now it has changed its mind and is calling for changes in the standard straight away. http://news.techeye.net/security/rsa...ption-sabotage |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Analyst warns Wii U going down the pan | Stefan Mileschin | WebNews | 0 | 9th July 2013 07:42 |
Why Most Web Services Don’t Use End-to-End Encryption | Stefan Mileschin | WebNews | 0 | 3rd July 2013 07:51 |
Top cryptographer warns against logging in | Stefan Mileschin | WebNews | 0 | 19th March 2013 08:13 |
OCZ warns of 'significant' Q2 net loss | jmke | WebNews | 1 | 12th October 2012 15:16 |
AMD warns on revenue | Stefan Mileschin | WebNews | 0 | 11th July 2012 07:26 |
Sprint warns it's a 'little behind' on Samsung Galaxy S III | Stefan Mileschin | WebNews | 0 | 20th June 2012 08:50 |
Microsoft warns of TLS/SSL flaw in Windows | jmke | WebNews | 0 | 10th February 2010 14:28 |
FBI warns of new Storm worm variant | Shogun | WebNews | 0 | 31st July 2008 08:21 |
Microsoft warns users against using vLite | jmke | WebNews | 3 | 17th February 2008 14:47 |
Reg readers sabotage their Windows boxes | jmke | WebNews | 0 | 14th September 2004 16:16 |
Thread Tools | |
| |