NIST formally chops NSA-tainted random number generator

By

Dual_EC_DRBG algorithm no longer part of standard.

The United States National Institute of Standards and Technology (NIST) has revised its recommendations for methods used to generate random numbers, and formally removed an algorithm suspected to contain a National Security Agency (NSA) backdoor.

NIST formally chops NSA-tainted random number generator

Former NSA contractor Edward Snowden leaked documents in 2013 that suggested the NSA wrote the dual elliptic curve deterministic random bit generator (Dual_EC_DRBG) algorithm which became part of a NIST standard in 2006.

Cryptographers feared that the involvement of the US spy agency in developing the algorithm meant encryption technology using Dual_EC_DRBG could be compromised.

Random number generation forms a cornerstone of building strong encryption; if attackers can predict which numbers are generated, they are able to unravel scrambled data.

Security and cryptography vendor RSA reacted quickly to the reports that the NSA may have deliberately weakened Dual_EC_DRBG and removed the algorithm from its products two years ago.

NIST later started an investigation into the algorithm, seeking public input on its use. In 2014, the standards agency removed Dual_EC_DRBG from its draft recommendations and made the decision permanent last week.

"The algorithm has spawned controversy because of concerns that it might contain a weakness that attackers could exploit to predict the outcome of random number generation," NIST wrote in its announcement.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Eagers Automotive finds unauthorised access to parts of IT systems

Eagers Automotive finds unauthorised access to parts of IT systems

Hackers hit Victoria's court recording database

Hackers hit Victoria's court recording database

St Vincent's Health Australia warns cyber attack forensics could "take some time"

St Vincent's Health Australia warns cyber attack forensics could "take some time"

Yakult Australia confirms cyber incident

Yakult Australia confirms cyber incident

Log In

  |  Forgot your password?