NIST "strongly" suggests dropping its own encryption standard
arstechnica.com
arstechnica.com
First critic from June 2006: http://eprint.iacr.org/2006/190
Not only was it immediately criticized as being insecure, it's also slow.. I doubt anyone used this algo.. certainly, after 7 years of public criticism, anyone who used it would have replaced it by now.
Apparently RSA Security uses it as a default.
http://developer-content.emc.com/docs/rsashare/share_for_jav... https://lwn.net/Articles/566329/
If anyone else has other examples, I would be interested in those too.
Most notably apart from RSA is the "McAfee Firewall Enterprise Control Center" (who actually use RSA's library)
Cisco, Certicom, RSA, McAffee (via RSA), Juniper, Blackberry/RIM, OpenPeak, OpenSSL, Samsung, Symantec, Riverbed, Cummings Engineering, CoCo Communications, Kony, Lancope (via RSA), Mocana, Safenet, SafeLogic, Panzura, Microsoft, Thales e-Security, Catbird, ARX all list Dual_EC_DRBG as at least supported.
Of these, RSA (and presumably the others based on their, like McAffee and Lancope), Thales e-Security, and possibly Microsoft (Windows Server 2008 R2 lists only Dual_EC_DRBG, though its possible that that's just their only FIPS compliant one and they use some non-standard algorithm by default) seem to use Dual_EC_DRBG by default or as the only option. I haven't tried finding documentation on all of these to see if they say what their default algorithm is, so it may be more.
edit to add: Found this discussion on the OpenSSL users list, about why they added it. Apparently it was because a paying customer requested it, thought the customer is not named for confidentiality reasons. OpenSSL doesn't appear to enable the NIST/FIPS random number generators unless you compile it in FIPS mode (at least, as far as I can tell from a quick, their build system is a bit weird, and FIPS mode is even stranger):
There is one company that only has a cert for EC_DRBG and thus can reasonably be inferred to be using it is Lancope, a network security/firewall company. For the rest of them, we don't know.
... later ...
"Using a weak PRNG is inadvisable as it may allow attackers to predict the values of secret information such as session keys."
The answer to that question is also here. You have the NIST, a government entity that is opposing another government entity, the NSA, because the former does not agree with the latter's practices. We should not forget that the government is not one cohesive entity and this is an example of that.
In fact, an explicit part of NIST's role is filling in science that businesses need but can't do themselves.
NIST started out as the National Bureau of Standards. It sits in the Department of Commerce. Most of its activities are directed at tasks-- like standardizing measurements-- that businesses depend on, but are too small, or too balkanized, to do effectively on their own.
Unless, you know, you like every corner gas station having its own definition of "gallon", and every appliance manufacturer rating its offerings using different definitions of energy, and every steel producer specifying tensile strength according to its own test procedure.
Disclosure-- I had a post-doc at NIST in the late 1990s.
(Nobody I know of uses Dual-EC, and you shouldn't either).
Their attack does work in the advertised time, but it a purely distinguishing attack, i.e., it tells you "this stream of random bits was generated by the DEC PRG". It does this by verifying that the number of 256-bit integers constructed using the 240 bits of the generator as least-significant bits are more often valid points on the P-256 curve than truly random 240-bit strings would. A 2007 paper extended this to predict bits.
EDIT: Actually, for the record, the first public attack on the generator was a predictor, in March 2006 [1]. Citing its conclusion:
"While the practical impact of these results are modest, it is hard to see how these flaws would be acceptable in a pseudo-random bit generator based on symmetric cryptographic primitives. They should not be accepted in a generator based on number-theoretic assumptions."
[1] http://www.math.ntnu.no/~kristiag/drafts/dual-ec-drbg-commen...
"Government Standards Agency “Strongly” Suggests Dropping its Own Encryption Standard"
http://www.propublica.org/article/standards-agency-strongly-...
Ars Technica, however, changed it and added in "NSA-influenced algorithm" because, you know, clicks.
> The NIST standard describes what is known as an "elliptic curve-based deterministic random bit generator."
And also links in the first paragraph to: http://www.propublica.org/documents/item/785571-itlbul2013-0...
Pretty funny, coming from an NSA partner company.
We know today that MS hands exploits over to the NSA.
Also, the likelihood that the NSA was allowed to integrate backdoors in MS Windows is extremely high.
How do you square that with "take the appropriate action to protect our customers"?
Additionally, backdoors/exploits can be used not only by their creators but also by others who find them, making MS's "protect the customers" claim even more ridiculous.
1. FBI Admits It Controlled Tor Servers Behind Mass Malware Attack (wired.com)
2. NIST "strongly" suggests dropping its own encryption standard (arstechnica.com)
3. No more CSS and HTML, just JS (ojjs.org)Yeah, that's what you get when you have an agency run by an army general.
That's a shocker.
They might undergo some reform, but the government apparatus has been far too reliant on many aspects of their work to actually shut them down.
Ideas surrounding freedom, liberty, and privacy are very complex, easily confused, and often forgotten until its too late. The laws around these things are mechanisms which help protect what you're country supposedly holds dare.
But in answer to your actual question, would you believe them if they said they hadn't?
No. We know some things they do. We don't know what else and how much they do.
Now most of the general public knows the nature of their work and some of the details surrounding it.
Public scrutiny and peer review are the best defenses, and the NIST did as much.
[1] IMHO, I'm far more concerned about China and Russia then the US.
They can't backdoor a math function because all 3 have been implemented by dozens of libraries and programs independently.
The attacks are usually on the implementations or subverting the rng. Or plain old thermorectal cryptoanalysis - it obtains both symmetrical and asymmetrical keys in fixed time.
Also Google, FB, Yahoo etc should provide grants so independent cryptologists can spend time to review and test encryption standards. They don't have to match NSA's budget...
It's a small world. They need money to do their work. MS, Google, FB, Yahoo!, etc haven't been providing the funding or the jobs. GCHQ, NSA, etc have been providing money and jobs. It's too late - there are no independent cryptologists.
EG: (http://www.cs.bris.ac.uk/Research/CryptographySecurity/) (http://bsc.bris.ac.uk/) and (http://www.blogger.com/comment.g?blogID=14836817&postID=1126...) {expand the original comment with this last link} (http://www.maths.bris.ac.uk/research/heilbronn_institute/)
(Of course the brightest mathematicians are used to fool people into clicking on ads. But that's another story.)
> I remember talking to PHD students having to live on $20K a year
The spooks recruit before PHD if the person is good enough.