Hopefully the last post I'll ever write on Dual EC DRBG
blog.cryptographyengineering.com
blog.cryptographyengineering.com
[1] http://vimeo.com/97891042 (jump to 57:53)
[2] Same video, jump to 30:14
[0]: http://ethanheilman.tumblr.com/post/108115952435/a-response-...
PS - There may very well be a backdoor. In fact I believe that there is. But people keep claiming the Snowden leaks confirmed it, when I see no such confirmation.
A leak confirmed that the NSA paid RSA to use that particular algorithm in BSAFE. http://en.wikipedia.org/wiki/RSA_BSAFE#Dual_EC_DRBG_backdoor
Esp. coupled with its insanely slow performance and NSA's failure to point out that the selection of the 'random' numbers could be used to backdoor the cryptosystem. (especially when they continued to fail to point that out and support the cryptosystem while embargoing the patent for national security reasons).
But indeed, I'm not aware of any stronger proof. ... but people go to jail on evidence less circumstantial than this all the time. How high a bar must be set before we can just say "backdoored" without a page of footnotes?
"Classified N.S.A. memos appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency." -http://www.propublica.org/article/the-nsas-secret-campaign-t...
They appear to? There's armies you could lose in the gaps of interpretation words like that allow.
'Appear to' covers everything from "NSA and DRBG mentioned in same document" to definitely not a statement like "the Dual EC-DRBG private key has not proven sufficiently useful in recovering useful intelligence and we're discontinuing the program" or some such.
> Internal N.S.A. memos describe how the agency subsequently worked behind the scenes to push the same standard on the International Organization for Standardization. “The road to developing this standard was smooth once the journey began,” one memo noted. “However, beginning the journey was a challenge in finesse.”
> At the time, Canada’s Communications Security Establishment ran the standards process for the international organization, but classified documents describe how ultimately the N.S.A. seized control. “After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft,” the memo notes. “Eventually, N.S.A. became the sole editor.” [0]
Yes, it's somewhat circumstantial, but pretty damning. If they weren't backdooring it, I'd like to hear an alternate explanation for why the NSA has memos about, in their own words, "behind-the-scenes finessing" to "become the sole editor" and "rewrite" an international standard. All that hard work quietly manipulating things to be just how they want them and, oopsie, the standard just might have a back door! Meanwhile, as described in other comments here, they paid RSA Security to deploy the standard; and were made aware of the possibility of a backdoor[1], but for whatever reason continued recommending its use.
I'd entertain arguments that they were actually trying to strengthen it, as may have happened with DES, but in this case, they were pushing something that civilian contemporaries knew was dangerous. Malice or incompetence seem more likely than secret benevolence here. Or is there some other reasonable explanation I'm missing?
[0] http://bits.blogs.nytimes.com/2013/09/10/government-announce... [1] https://projectbullrun.org/dual-ec/patent.html
The ubuntu's gpg lists the following:
Pubkey: RSA, RSA-E, RSA-S, ELG-E, DSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH, CAMELLIA128, CAMELLIA192, CAMELLIA256
Hash: MD5, SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224It was on discussed on HN, at the time noone pointed out anything glaring about the advice given.
Do you have a pointer to the HN discussion?
Fortuna is built on top of an underlying block cipher in counter mode (typically AES), with some additional machinery for periodic reseeding to recover from the situation where the PRNG's internal state is compromised at a particular point in time.
But in most cases, the correct answer is to use your OS's /dev/urandom (CryptGenRandom on windows). If that is not secure your app is probably screwed whatever you do.