RSA has advised its customers to make a configuration adjustment to its BSafe security software products. This follows an announcement issued by NIST not to use a security standard it designed and published: the Dual Elliptic Curve Deterministic Random Bit Generator. The Dual_EC_DRBG is believed to contain an NSA backdoor that would in essence nullify the standard’s security. “NIST and the NSA have always had a close relationship, but this was not supposed to extend into subverting cryptographic standards,” said ITIF’s Daniel Castro.
RSA Warns Customers Off Suspected NSA-Tainted Crypto Tools
Posted by: Richard Adhikari September 21, 2013 05:00 AMRSA has advised its customers to make a configuration adjustment to its BSafe security software products. This follows an announcement issued by NIST not to use a security standard it designed and published: the Dual Elliptic Curve Deterministic Random Bit Generator. The Dual_EC_DRBG is believed to contain an NSA backdoor that would in essence nullify the standard’s security. “NIST and the NSA have always had a close relationship, but this was not supposed to extend into subverting cryptographic standards,” said ITIF’s Daniel Castro.