Newsletters
Customer Relationship Management News NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home CRM Systems Customer Service Business Intelligence Sales & Marketing More Topics...
World Wide Web
Tame your scariest paperwork. Find Out How
Average Rating:
Rate this article:  
Researchers Find NSA Planted Two Spy Tools through RSA
Researchers Find NSA Planted Two Spy Tools through RSA

By Barry Levine
March 31, 2014 2:54PM

Bookmark and Share
A team of professors has reportedly concluded that U.S. National Security Agency is even more untrustworthy than previously thought. The NSA apparently implemented not one but two encryption tools distributed through security firm RSA to make it easier to eavesdrop on Web transmissions. RSA trusted the NSA since it's charged with U.S. security.
 



Last fall, an encryption tool widely distributed through leading security firm RSA was withdrawn because of concerns it was vulnerable to decoding by the U.S. National Security Agency (NSA), which created it. Now, a team of researchers has reported that the super-secret agency also created at least one other tool that allowed it to more easily decode transmissions.

Both tools were part of RSA's BSafe software security package, and both are assumed to have provided back-door access to communications and software encrypted with BSafe tools.

The Reuters news agency reported Monday that a team of academic researchers from several universities, including Johns Hopkins, the University of Wisconsin and the University of Illinois, has discovered the NSA was involved with the second tool. It's called an "Extended Random" extension, and it can be used to crack the RSA's Dual Elliptic Curve random number generator software -- the other NSA developed tool that had been withdrawn -- tens of thousands of times faster than other methods.

NIST and NSA

The Extended Random software is supposed to increase the randomness of Dual Elliptic Curve-generated numbers, thus making its encoding more secure. However, the researchers discovered that the extra data transmitted by Extended Random before a secure connection begins made decoding the the following transmission much easier.

The Extended Random software was removed from RSA's BSafe security kit within the last six months. Reportedly, Extended Random had not been widely adopted.

"We trusted [the NSA] because they are charged with security" for the U.S., a RSA executive told Reuters.

The National Institute of Standards and Technology (NIST) had accepted an NSA proposal in 2006 to create the Dual Elliptic Curve random number generator. There had subsequently been suspicions and reports -- including from Microsoft researchers -- that the resulting code from the NSA contained a back door.

Snowden Documents

But NIST reportedly accepted it because other governmental agencies were using it. In December, Reuters reported that the NSA had paid RSA $10 million to make the Dual Elliptic Curve the default for its BSafe security kit. RSA has declined to comment on the possibility that the NSA also paid the company a fee for including Extended Random in the kit.

After documents revealed by ex-NSA contractor Edward Snowden indicated the NSA was involved in community cryptography standards in order to create vulnerabilities it could exploit, NIST issued a warning in September than the Dual Elliptic Curve code "no longer be used."

After the NIST warning, RSA warned its customers, since the code was being widely used for security. A random number generator is common in cryptography, but a generator that is not random is more easily hacked. Some experts have contended, however, that only the NSA had the capability of breaking this particular generator.
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 World Wide Web
1.   Wall Street Journal Hacked Again
2.   Internet of Things Comes to DIYers
3.   Social Media Haters Speak Up
4.   New Technology Defeats Privacy Efforts
5.   Verizon Launches Rewards Program


advertisement
Radical.FM's Freemium Biz Model
Online radio startup asks for donations.
Average Rating:
Facebook Social Experiment Irks Us
Secretive test was legal, but ethical?
Average Rating:
Social Media Haters Speak Up
Survey says, now showing a little love.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Wall Street Journal Hacked Again
Hacked again. That’s the story at the Wall Street Journal this week as the newspaper reports that the computer systems housing some of its news graphics were breached. Customers not affected -- yet.
 
Dropbox for Business Beefs Up Security
Dropbox is upping its game for business users. The cloud-based storage and sharing company has rolled out new security, search and other features to boost its appeal for businesses.
 
34 European Banks Hit by Android-Skirting Malware
Criminals have been finding gaping holes in Android-based two-factor authentication systems that banks around the world are using. The result: 34 banks in four European countries have been hit.
 

Enterprise Hardware Spotlight
Microsoft Makes Design Central to Its Future
Over the last four years, Microsoft has doubled the number of designers it employs, putting a priority on fashioning devices that work around people's lives -- and that are attractive and cool.
 
Contrary to Report, Lenovo's Staying in Small Windows Tablets
Device maker Lenovo has clarified a report that indicated it is getting out of the small Windows tablet business -- as in the ThinkPad 8 and the 8-inch Miix 2. But the firm said it is not exiting that market.
 
Seagate Unveils Networked Drives for Small Businesses
Seagate is out with five new networked attached storage products aimed at small businesses. The drives are for companies with up to 50 workers, and range in capacity from two to 20 terabytes.
 

Navigation
CRM Daily
Home/Top News | CRM Systems | Customer Service | Business Intelligence | Sales & Marketing | Contact Centers | Customer Data | CRM Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.