RSA warns developers not to use RSA products
blog.cryptographyengineering.com
blog.cryptographyengineering.com
tptacek repeatedly assured everyone that this was absolutely not a big deal and meant nothing because nobody in their right mind uses the standard.
Except whoops, one of, if not the, largest players in the field. I'm sure he'll have a bunch of really great replies that manage to simultaneously say why this still isn't a big deal and passive-aggresively insult our knowledge of the situation. I look forward to reading what he has to say.
>Thanks for the link. I would have just gone on confirming my own biases without it.
This is incredibly evident in your comments on Dual_EC and sometimes happens on other comments as well. You draw a line in the sand and argue around it constantly, eventually bleeding into passive-aggressive attacks on the knowledge of others.
I find it valuable to hear from others outside of my industry (which is not crypto) who have no expertise in that field. They often have a fresh and agnostic look at something. Do you think all these comments slinging mud at you - however inaccurate they may be - were born from nothing?
I have a different explanation for why I always seem to be at odds with people on NSA topics, but I'll wait to provide it.
Thanks for proving my point.
I'm very interested in that actually. I'm often curious what shapes people's perspectives on these issues, particularly if it doesn't align with any obvious incentives. I always thought that you must have family in law enforcement or something, but I'd love to know the actual reason.
* I'm professionally involved in computer security, like you, and have an an amateur interest in the law (I'm considering law school at some point).
* Message board nerds have a lot of weird, wrong beliefs about computer security and the law.
There is a political difference between me and HN: I'm not an anarcho-capitalist (that silly "world's smallest political test" thingy puts me dead center in "left liberal"). But politics have little to do with where I end up on the NSA threads; it's things like not understanding (or really, having even skimmed) NIST crypto standards, or not taking the time to understand what the 4th Amendment means. The things that get me into "trouble" here have more to do with taking the time to actually read primary sources than anything else.
We probably disagree about NSA a lot less than you think we do.
I hate it when people do that. If you have a position on something, don't leave us all guessing, just state it!
He was right. Nobody in their right mind does use Dual_EC_DRBG.
From this episode I conclude that RSA Security LLC was not in their right mind.
Edit: Actually, I take that back. I have no problem believing that RSA Security are perfectly sane. Would we be completely shocked if the reason they chose a questionable default was due to coercion from the spooks? Only NSA has the keys, so it's a pretty safe backdoor.
You know, props to China, had to go through the work of owning RSA's seed server last year just to level the playing field. They get so derided in the media for doing that, but it seems unfair when the other team has a backdoor. Who is the real "Advanced Persistent Threat"?
The problems with it were known days after the standard was published.. meaning anyone who implemented was well aware of its problems.
Edit: actually, the first attack was in march 06 -- 3 months before the standard was published: http://www.math.ntnu.no/~kristiag/drafts/dual-ec-drbg-commen...
I should have said calling into question the insanity, will edit.
Looks like that still stands according to the article we're supposed to be discussing here:
".. no sensible cryptographer would go near the thing"
But I also expressed the view that no one would have used this. I guess it makes a lot more sense now: It seemed weird to put it in the standard, as no one was going to just use it. I'd been guessing that they hoped that it would be made an option and then they could do some negotiation attack to force it. I was missing a more obvious explanation: Someone was already willing to ship it, but they wanted the plausible denyability of it being a standard, because it looked too suspect otherwise.
[1] http://www.pcworld.idg.com.au/article/129305/rsa_security_so...
[2] http://satchitssecurity.typepad.com/a_page_from_satchits_sec...
Thanks for the link. I would have just gone on confirming my own biases without it.
Because the NSA didn't just backdoor the Dual_EC standard. It backdoored the technology industry, as well as the rule of law.
That would be incredibly embarrassing in itself (which it already is), but the alternative is even worse (choosing the one with the backdoor on purpose).
If a system's seed is weak, one attack is to try all likely seeds, run them through the PRNG to generate keys, and see if any of the keys work. A slow PRNG indeed slows down this process.
For instance, it would have slowed down the attack on the Taiwan Cryptocards, which exploited patterns in the seed that appear directly in the key, reported here: http://smartfacts.cr.yp.to/smartfacts-20130916.pdf
They did not need to simulate the operation of the poorly-seeded PRNG that generated them.
And in particular, TW Cryptocards analysis never had to run the RNG. Just had to look at 2 million public keys already out there.
Or, management exists cover up bad hiring practices. Take your pick. Either way, CTO's saying dumb things seems to be normal.
Seems like we've got a reasonable guess now though.
1. say "we deliberately built the backdoor into our software, please never buy our products again if you value your security" and go live the rest of his life in a Buddhist monastery in Tibet,
2. say some embarrassing BS which gives him a veil of plausible deniability while raising doubts of his personal competency, but who cares, he's a C-type, they don't have to know all the details, right?
Would you trust a computer security company that when you reset your password on their web site, sent you a new password that was literally the same as your email address that you signed in with?
If this company sold closed source encryption software, would you trust that the software was competently written and did not have back doors, if the president of the company defended their actions of not hashing passwords, and of resetting passwords to their user's email addresses?
What if the president of that company had been prosecuted for computer crimes in the past, and had spend time in jail for it, because after he was first caught, he went right back to phone freaking again and got caught again?
Would you trust the president of the company, who is a convicted felon, who fraudulently made a lot of money by computer crime and got caught, but had most of the charges dropped and his sentence reduced, not to have made a deal with the government and promise to return their favor of giving him a more lenient sentence in exchange for certain favors in the future?
Can anyone guess who I'm referring to?
His company came out with a "secure" voice encryption product, and then a previously unknown anonymous hacker reviewed the product and its competitors, and wrote a suspiciously positive review of it, claiming it was the only one he couldn't break. His company then published a press release trumpeting the favorable review, right before a big mobile security conference.
A suspicious security researcher baited the anonymous hacker to post on his blog, and it turned out he was using an ip addressed registered to the security company whose product he'd written a favorable review about.
When confronted with proof, the founder of the security company denied astroturfing, denied knowing the hacker, and implausibly claimed the anonymous hacker must have been using his company's anonymous browsing service.
The same security company founder who spent three years in jail for phone phreaking, because he was convicting of hacking and defrauding profit. The same security company who stores their user's passwords in unhashed unsalted plain text encrypted with a key on their server. The same security company who resets their user's passwords with their email address. The same security company whose founder claims that "many customer do not wish their password to be reset each time they have a problem" justifies not hashing passwords, and resetting passwords to "convenient" email addresses. The same security company whose founder refuses to change his "unconventional" security policies after being confronted with these facts, and instead makes ridiculous excuses for his incompetence, and continues to betray the trust of his customers even after he's been confronted with it.
Can you figure out who it is now?
An intentionally introduced vulnerability can be considered a backdoor, even if it's not a matter of saying "open sesame" to open the so-called backdoor.
So yes, it's pretty much a matter of intent.
Thats a backdoor by most descriptions. This isn't just a bug.