RSA warns developers to stop using NSA's weak security formula

Advertisement
By Reuters | Updated: 20 September 2013 13:09 IST
RSA warns developers to stop using NSA's weak security formula
In the latest fallout from Edward Snowden's intelligence disclosures, a major U.S. computer security company warned thousands of customers on Thursday to stop using software that relies on a weak mathematical formula developed by the National Security Agency.

RSA, the security arm of storage company EMC Corp, told current customers in an email that a toolkit for developers had a default random-number generator using the weak formula, and that customers should switch to one of several other formulas in the product.

Last week, the New York Times reported that Snowden's cache of documents from his time working for an NSA contractor showed that the agency used its public participation in the process for setting voluntary cryptography standards, run by the government's National Institute of Standards and Technology, to push for a formula that it knew it could break.

NIST, which accepted the NSA proposal in 2006 as one of four systems acceptable for government use, this week said it would reconsider that inclusion in the wake of questions about its security.

But RSA's warning underscores how the slow-moving standards process and industry practices could leave many users exposed to hacking by the NSA or others who could exploit the same flaw for years to come.

Advertisement

RSA had no immediate comment. It was unclear how the company could reach all the former customers of its development tools, let alone how those programmers could in turn reach all of their customers.

Developers who used RSA's "BSAFE" kit wrote code for Web browsers, other software, and hardware components to increase their security. Random numbers are a core part of much modern cryptography, and the ability to guess what they are renders those formulas vulnerable.

Advertisement

The NSA-promoted formula was odd enough that some experts speculated for years that it was flawed by design. A person familiar with the process told Reuters that NIST accepted it in part because many government agencies were already using it.

But after the Times report, NIST said it was inviting public comments as it re-evaluated the formula.

Advertisement

"If vulnerabilities are found in these or any other NIST standards, we will work with the cryptographic community to address them as quickly as possible," NIST said on September 10.

Snowden, who is wanted on U.S. espionage charges and is living in temporary asylum in Russia, disclosed secret NSA programs involving the collection of telephone and email data.

© Thomson Reuters 2013

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Ground Zero, Detective Sherdil, Found S2, and More
  2. Vivo Y400 Pro 5G India Launch Today: All You Need to Know
  3. Oppo Reno 14 5G Series Teased to Launch in India Soon
  4. Nothing Phone 3 to Get New Glyph Matrix Interface on the Rear Panel
  5. Samsung Galaxy M36 5G India Launch Date and Key Features Revealed
  6. Poco F7 5G to Be Equipped With a Snapdragon 8s Gen 4 SoC
  7. Vodafone Idea to Bring Direct-to-Device Satellite Connectivity to India
  8. Realme 15 Series Said to Launch in July; Lite Variant Leaked Online
  9. Realme Buds Air 7 Pro Review: Eye-Catching Design, Thumping Bass
  1. Samsung Galaxy Z Fold 7 Leaked Renders Hint at Design Changes; Storage Options Tipped
  2. Vivo Y400 Pro 5G Launching Today: Price in India, Expected Features and Specifications
  3. Fast Radio Bursts Reveal Universe’s Missing Matter Hidden in Cosmic Intergalactic Fog
  4. Apollo Astronauts Found Orange Glass Beads on the Moon, Scientists Now Know Why
  5. World’s Oldest Tailored Dress Found in Egyptian Tomb Dates Back Over 5,000 Years
  6. Ancient Footprints in White Sands Confirm Humans Reached America 23,000 Years Ago
  7. Humanoid Robot Achieves Controlled Flight Using Jet Propulsion and AI Systems
  8. Curiosity Rover Reaches Uyuni Quad, Begins New Mars Mapping and Surface Analysis Campaign
  9. NASA to Gather Reentry Imagery of European Commercial Capsule Using High-Altitude Aircraft
  10. ESA's Proba-3 Unveils First-Ever Artificial Solar Eclipse Images from Precision Satellite Formation
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.