RSA Warns Customers About NSA Encryption Cracking

RSA, one of the best known cryptography specialists in the world, has started warning customers about using an encryption algorithm in two of its products due to fears over the activities of US intelligence.

In particular, it is worried about the Dual Elliptic Curve Deterministic Random Bit Generation that is used by default in the BSafe toolkit for developers. There are concerns the National Security Agency (NSA) may have written a backdoor into the number generator, thanks to reports in the New York Times and the Guardian.

Encryption worries

The US National Institute of Standards and Technology had already raised its own concerns about the NSA’s activity, after reports indicated the intelligence agency had covertly pushed encryption standards with weaknesses in them. That includes the Dual Elliptic Curve Deterministic Random Bit Generation.

RSA has offered developers ways to change the default encryption used in BSafe and has stopped using the algorithm in question. An internal review is ongoing to see whether the algorithm is in use anywhere else in RSA’s business.

According to leaks from Snowden, the NSA was running a 10-year programme called Bullrun – “an aggressive, multi-pronged effort” to crack various forms of Internet encryption. The UK’s GCHQ has plans to break encryption used by 15 major Internet companies and 300 VPNs by 2015, documents indicated.

Many have lambasted the NSA and GCHQ’s work on embedding backdoors into encryption standards, noting that it weakens the security of the Internet in general. If cyber criminals or any kind of malicious actor learn of the backdoors, they can use them for their own gain.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

US Provides Assurances For Julian Assange Extradition

As President Biden 'considers' request to drop Julian Assange extradition, US provides assurances to prevent…

1 hour ago

Tesla To Ask Shareholders To Reinstate Elon Musk’s $56 Billion Package

Tesla shareholders to be asked to reinstate Elon Musk's $56 billion pay package, days after…

17 hours ago

Telegram To Reach One Billion Users Within Year

Catching WhatsApp? Billionaire founder of Telegram claims encrypted platform will reach one billion users within…

17 hours ago

Judge Dismisses Some Harm Claims Against Meta, Zuckerberg

Good news for Mark Zuckerberg as judge dismisses some claims in dozens of lawsuits alleging…

19 hours ago

Google Begins Removal Of California News Ahead Of Proposed Law

Consequences of Assembly Bill 886. Google begins removing California news websites from some search results

20 hours ago

Tim Cook Says Apple Considering Factory In Indonesia

CEO Tim Cook during visit to Jakarta says Apple will look into building a manufacturing…

21 hours ago