Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

struggle4progress

(118,280 posts)
Sat Sep 21, 2013, 03:43 AM Sep 2013

Snowden disclosures prompt warning on widely used computer security formula

By Joseph Menn
SAN FRANCISCO
Thu Sep 19, 2013 11:56pm EDT

... Developers who used RSA's "BSAFE" kit wrote code for Web browsers, other software, and hardware components to increase their security. Random numbers are a core part of much modern cryptography, and the ability to guess what they are renders those formulas vulnerable.

The NSA-promoted formula was odd enough that some experts speculated for years that it was flawed by design. A person familiar with the process told Reuters that NIST accepted it in part because many government agencies were already using it.

But after the Times report, NIST said it was inviting public comments as it re-evaluated the formula.

"If vulnerabilities are found in these or any other NIST standards, we will work with the cryptographic community to address them as quickly as possible," NIST said on September 10 ...


http://www.reuters.com/article/2013/09/20/us-usa-security-snowden-rsa-idUSBRE98J02Z20130920

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Snowden disclosures prompt warning on widely used computer security formula (Original Post) struggle4progress Sep 2013 OP
Government standards agency “strongly” suggests dropping its own encryption standard struggle4progress Sep 2013 #1
k&r for exposure. n/t Laelth Sep 2013 #2

struggle4progress

(118,280 posts)
1. Government standards agency “strongly” suggests dropping its own encryption standard
Sat Sep 21, 2013, 03:47 AM
Sep 2013

Posted Sep 20, 2013, 9:45 pm
Jeff Larson & Justin Elliott ProPublica

Following revelations about the NSA’s covert influence on computer security standards, the National Institute of Standards and Technology, or NIST, announced earlier this week it is revisiting some of its encryption standards.

But in a little-noticed footnote, NIST went a step further, saying it is “strongly” recommending against even using one of the standards. The institute sets standards for everything from the time to weights to computer security that are used by the government and widely adopted by industry ...


http://www.tucsonsentinel.com/nationworld/report/092013_nsa_encryption/government-standards-agency-8220strongly8221-suggests-dropping-its-own-encryption-standard/

Latest Discussions»Issue Forums»Editorials & Other Articles»Snowden disclosures promp...