
“The fix may not be all that difficult—the tainted part of the standard is a highly inefficient algorithm that security experts identified as a problem long ago. In fact, the biggest mystery, those experts say, is why the NSA thought any company or government agency would willingly use that particular algorithm to protect their data. Despite Dual_EC_DRBG’s known flaws, prominent tech companies including Microsoft, Cisco, Symantec and RSA include the algorithm in their product’s cryptographic libraries primarily because they need it to be eligible for government contracts, cryptographer Bruce Schneier says.”
https://www.scientificamerican.com/article.cfm?id=nsa-nist-encryption-scandal
Related posts:
The price Gina Gray paid for whistleblowing through 'proper internal channels'
Want to make money as a landlord? Try Detroit
Test reveals Facebook, Twitter and Google snoop on links in private messages
Map: All the Countries John McCain Has Wanted to Attack
Japanese cult fugitive given runaround as he tried to surrender [2012]
New sanctions against North Korea after threat of pre-emptive nuclear strike
Fed delays Basel III bank capital buffer rules
Germany's top publisher bows to Google in news licensing row
Trade war bailout: $12 billion in emergency aid for farmers hurt by tariffs
Canada to end airstrikes in Syria and Iraq: new prime minister Trudeau
German Constitutional Court Rejects Calls to Block ESM Fund
Mitt Romney Says He Could Wage War on Iran Without Congress' Approval
U.S. to seize New York skyscraper it claims is secretly owned by Iran
Why marijuana taxes are such a burning question
Girl Scouts auction off plantation amid financial troubles