Jump to content
The Inquirer-Home

Encryption standard tiggered by spooks

Haunted Backdoor
Friday, 16 November 2007, 08:15

A NEW encryption standard has been rendered largely useless because security bods at the US National Security Agency might have placed a backdoor to read an documents that use it.

According to Wired , the spooks' backdoor involves a new random-number machine which is slow and badly designed.

Security expert Bruce Schneier, said the US government released a new official standard for random-number generators this year, and it will likely be followed by software and hardware developers around the world.

The standard, which was published in NIST Special Publication 800-90 contains four different approved techniques, called DRBGs, or 'Deterministic Random Bit Generators.'

One of those generators used in the standard is called Dual_EC_DRBG. NSA has been wanting security experts to use it for years.

However since 2006, the use of Dual_EC_DRBG has been questioned by those security experts who know how to use a slide rule. The random numbers it produces have a small bias which makes them a little easier to predict.

Also the algorithm has a bunch of constants which could be used to predict the output of the random-number generator after collecting just 32 bytes of its output.

No one knows what the secret numbers are, but the person who produced them probably does. According to Schneier that bloke would be working for the NSA and would know how to break any use of Dual_EC_DRBG.

Share this:

Comments
Kave speak

I thought Kave-speak was discouraged in article titles...

Some people don't know how bad Tig's code is.

posted by : snuke, 16 November 2007 Complain about this comment
Probably on purpose

Oops! We accidentally told everyone to use encryption we can break. Our bad. PGP had the best idea. Encryption so strong it couldn't be broken by normal means.

posted by : mogbert, 16 November 2007 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?