Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • Networking

    Reports of NSA’s Deeper Involvement With RSA Raise Questions

    Written by

    Sean Michael Kerner
    Published April 1, 2014
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Reports that the NSA’s involvement with RSA Security’s cryptographic tools was greater than first claimed raise many questions. The issue is complicated and requires a detailed look.

      In December 2013, a Reuters report alleged that RSA Security had accepted $10 million from the U.S. National Security Agency (NSA) in an effort that ultimately served to weaken security in components of the RSA BSAFE encryption tools. On March 31, Reuters published a new report alleging that NSA involvement affected a wider number of RSA BSAFE cryptographic components.

      The report on the second NSA-related RSA vulnerability is based on newly published research from professors working at Johns Hopkins, the University of Wisconsin and the University of Illinois. The tool in question is called the Extended Random extension, and could potentially be used to crack the RSA Dual Elliptic Curve (EC) pseudo-random-number generator that is widely used in the security world today.

      The Extended Random extension was published as an Internet Engineering Task Force (IETF) draft in April 2008 and clearly lists the NSA as a co-author of the draft.

      “The BSAFE implementations of TLS makes the Dual EC backdoor particularly easy to exploit in two ways,” the research report states. “The Java version of BSAFE includes fingerprints in connections, making them easy to identify. The C version of BSAFE allows a drastic speed-up in the attack by broadcasting longer strings of random bits than one would at first imagine to be possible given the TLS standards.”

      RSA has repeatedly denied that it has ever intentionally weakened encryption to enable an NSA backdoor. At the recent RSA Security conference, Art Coviello, executive vice president of EMC and executive chairman of RSA, said that his company has done a lot of work with the NSA to help improve security. Coviello did not, however, directly address the $10 million contract question.

      Whether RSA knew that it was helping the NSA enable a backdoor remains a subject of debate.

      Marc Maiffret, CTO of BeyondTrust told eWEEK that revelations such as this continue to show that even security companies cannot blindly put their faith in the government for guidance on securing systems.

      “While the NSA has done many things to help improve Internet security, there are also many instances where they have weakened it,” Maiffret said. “Companies like RSA that are selling a solution to a problem should know fully their solution, even the parts of it that might have come as ideas from academia or the government; otherwise technology companies will find themselves an easy pass-through for subversion.”

      There is another perspective that can be taken on the issue, J.J. Thompson, managing director and CEO of Rook Security, told eWEEK. “Real security is dirty, and we should stop acting surprised,” Thompson said. “Even if portions of the NSA’s conduct are agreed upon by the public as questionable, it will become critical to know why that line was crossed, not simply to condemn the NSA for crossing that line.”

      Thompson added that perhaps the risk of not crossing the line was simply too high and the intelligence gained has saved countless lives.

      “Regardless, no matter how many Senate intelligence hearings are held, we’ll never know; for if the intelligence was valuable enough to break the law for, then its valuable enough to cover up,” Thompson said.

      While there is some reason to be concerned over the latest information about potential weakness in RSA encryption, the foundational encryption algorithms are themselves still secure, Geoff Webb, senior director for security strategy at NetIQ, told eWEEK. “These attempts to weaken the encryption process have been aimed at random-number generators used as part of the overall securing of data,” Webb said. “What this means is that we can still reclaim privacy on the Internet once these weakening elements have been removed.”

      Webb compares encryption to a symphony orchestra. Most of the players are great, but if you get one bad violinist, then the whole things falls over, he said.
      “I do think, however, that while we can get Internet privacy back on track, it may take a long time to reclaim the lost trust and confidence in the security of data transmitted—even when it’s supposed to be encrypted,” Webb said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×