It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
RSA warns of NSA encryption sabotage RSA warns of NSA encryption sabotage
FAQ Members List Calendar Search Today's Posts Mark Forums Read


RSA warns of NSA encryption sabotage
Reply
 
Thread Tools
Old 24th September 2013, 07:24   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 153,514
Stefan Mileschin Freshly Registered
Default RSA warns of NSA encryption sabotage

RSA has warned thousands of customers about using software that relies on a weak mathematical formula developed by the National Security Agency.

RSA, the security arm of storage company EMC, told customers that a toolkit for developers had a default random number generator using the weak formula.

It is suggesting that customers should switch to one of several other formulas in the product.

The move follows a report in the New York Times which showed that among Snowden's cache of documents, the agency used its public participation setting voluntary cryptography standards to push for a formula it knew it could break.

The National Institute of Standards and Technology accepted the NSA proposal in 2006 as one of four systems acceptable for government use. The NSA said it would reconsider that inclusion in the wake of questions about its security.

Developers who used RSA's "BSAFE" kit wrote code for web browsers, other software, and hardware components to increase security.

At the centre of the system are random numbers and the ability to guess what they are renders those formulas vulnerable.

The NSA-promoted formula was so odd that even at the time some felt it was flawed by design.

Reuters claims that the NIST accepted it in part because many government agencies were already using it. However, now it has changed its mind and is calling for changes in the standard straight away.

http://news.techeye.net/security/rsa...ption-sabotage
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Analyst warns Wii U going down the pan Stefan Mileschin WebNews 0 9th July 2013 07:42
Why Most Web Services Don’t Use End-to-End Encryption Stefan Mileschin WebNews 0 3rd July 2013 07:51
Top cryptographer warns against logging in Stefan Mileschin WebNews 0 19th March 2013 08:13
OCZ warns of 'significant' Q2 net loss jmke WebNews 1 12th October 2012 15:16
AMD warns on revenue Stefan Mileschin WebNews 0 11th July 2012 07:26
Sprint warns it's a 'little behind' on Samsung Galaxy S III Stefan Mileschin WebNews 0 20th June 2012 08:50
Microsoft warns of TLS/SSL flaw in Windows jmke WebNews 0 10th February 2010 14:28
FBI warns of new Storm worm variant Shogun WebNews 0 31st July 2008 08:21
Microsoft warns users against using vLite jmke WebNews 3 17th February 2008 14:47
Reg readers sabotage their Windows boxes jmke WebNews 0 14th September 2004 16:16

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 16:39.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO