NIST Finally Removes NSA-Compromised Crypto Algorithm From Random Number Generator Recommendations

from the took-'em-long-enough dept

Back in December, it was revealed that the NSA had given RSA $10 million to push weakened crypto. Specifically, RSA took $10 million to make Dual Elliptic Curve Deterministic Random Bit Generator, better known as Dual_EC_DRBG, as the default random number generator in its BSAFE offering. The random number generator is a key part of crypto, because true randomness is nearly impossible, so you need to be as random as possible. If it’s not truly random, you’ve basically made incredibly weak crypto that is easy to break. And that’s clearly what happened here. There were other stories, released earlier, about how the NSA spent hundreds of millions of dollars to effectively take over security standards surreptitiously, including at least one standard from the National Institute of Standards and Technology (NIST). People quickly realized they were talking about Dual_EC_DRBG, meaning that the algorithm was suspect from at least September of last year (though there were indications many suspected it much earlier).

In response to all this, NIST quickly issued an announcement recommending against using Dual_EC_DRBG, but it didn’t finally remove it from its random number generator recommendations until this week — following through on an open comment process on changing its recommendations.

Following a public comment period and review, the National Institute of Standards and Technology (NIST) has removed a cryptographic algorithm from its draft guidance on random number generators. Before implementing the change, NIST is requesting final public comments on the revised document, Recommendation for Random Number Generation Using Deterministic Random Bit Generators (NIST Special Publication 800-90A, Rev. 1).

The revised document retains three of the four previously available options for generating pseudorandom bits needed to create secure cryptographic keys for encrypting data. It omits an algorithm known as Dual_EC_DRBG, or Dual Elliptic Curve Deterministic Random Bit Generator. NIST recommends that current users of Dual_EC_DRBG transition to one of the three remaining approved algorithms as quickly as possible.

In September 2013, news reports prompted public concern about the trustworthiness of Dual_EC_DRBG. As a result, NIST immediately recommended against the use of the algorithm and reissued SP 800-90A for public comment.

Some commenters expressed concerns that the algorithm contains a weakness that would allow attackers to figure out the secret cryptographic keys and defeat the protections provided by those keys. Based on its own evaluation, and in response to the lack of public confidence in the algorithm, NIST removed Dual_EC_DRBG from the Rev. 1 document.

In the announcement, NIST also points out that it’s reviewing its cryptographic standards development process, to try to prevent this sort of thing from happening again.

Filed Under: , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “NIST Finally Removes NSA-Compromised Crypto Algorithm From Random Number Generator Recommendations”

Subscribe: RSS Leave a comment

I don't think Dual_EC_DRBG is unsafe per se

The way I understood this, it becomes unsafe once somebody gets to name the (fixed) constants in use. If those constants are calculated rather than picked randomly, the one providing the constants for use in the standard has an easy hook into the inner state of the random generator.

So it’s not unsafe per se. It’s just that the one proposing the constants may have a secret master key into all communication. And the NSA is not likely bribing RSA and NIST out of goodness of heart.


Re: I don't think Dual_EC_DRBG is unsafe per se

This is true, however the specific constants that should be used are part of the Dual_EC_DRBG ‘standard’. While you can use your own constants, it wouldn’t be Dual_EC_DRBG anymore, but a derivative that just happens to share a lot with it.

This is why, when cryptographic constants must be chosen, you typically pick a ‘nothing up my sleeve’ number.


Re: I don't think Dual_EC_DRBG is unsafe per se

I don’t think you understand the problem here

The problem isn’t the algorithm itself (as far as any crypologist can tell) it’s that the recommendation includes specifications for the random number generator, which DOES produce the hidden numbers needed to break the algorithm.

Which is why there is such a fit over this. You can’t be NIST compliant and not use only one part of this. The random number generator and this algorithm go hand in hand for companies who are NIST compliant (See: RSA). So there is literally no telling now many RSA devices are now compromised because of this discovery.

The numbers themselves in the generator have not been found yet. But they will be someday, which means all that information that was encrypted using it will be vulnerable.



“…an agency of the U.S. Department of Commerce”
– and thus subject to the FBI and NSA interference.

You are correct. The NIST’s purpose is the same as Microsofts, Googles, IBM’s , and any US Corperation or US Government Department.

Be an agent of NSA. Assist in Industrial Espionage , and blame it all on the hunt for terrorism.

One presumes the Chanceller of Germany is a Terrorist , since they bugged her phone and the phones of all her aids , and refuse to stop.

That Anonymous Cowardsays:

“In the announcement, NIST also points out that it’s reviewing its cryptographic standards development process, to try to prevent this sort of thing from happening again.”

Step 1 – Maybe stop taking piles of cash and not asking who it came from.
Step 2 – Maybe hire someone who can maybe like check to make sure your not offering the illusion of crypto.



They will fail in their “Try to prevent…”

Why ?

Because they are a US Government department subject to the will of the NSA and the president.

I hope you like getting it up the (ahem) , because like Obama, they have no intention of stopping. The best that can be hoped for is that they’re slow and gentle about it.



Any cryptosystem that has the word deterministic in should be considered suspect.

It is easy to determine the results of the Random Number Generation Using Deterministic Random Bit Generator.

Really, who did not see this coming?

I bet some dude at the NSA is laughing.. “Ha, bunch of morons! I even choose a name that describes our intention and it took them this long to figure it out. What an awesome job I have, I am so evil, muwahaaaaaa!


Re: Deterministic

It’s the opposite, all cryptosystems should be deterministic.

The playstation hack happened because they didn’t use a deterministic variation of ECDSA. The common (non-deterministic) variation of ECDSA depends on a unique random number; if that number is ever not unique (even if just a few bits are constant), it leaks the private key.

A deterministic random bit generator is related to a stream cipher (and in fact, most common fast DRBGs are directly based on stream ciphers or the similar CTR modes). As long as the initial “seed” is truly random, the output is completely unpredictable to anyone who does not know the seed. You only need true randomness for the seed, and for periodic reseeding (or adding more randomness to the seed).

Leave a Reply to Anonymous Cancel reply

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Older Stuff
13:40 It's Great That Winnie The Pooh Is In The Public Domain; But He Should Have Been Free In 1982 (Or Earlier) (35)
12:06 Norton 360 Now Comes With Crypto Mining Capabilities And Sketchy Removal Process (28)
10:45 Chinese Government Dragnet Now Folding In American Social Media Platforms To Silence Dissent (14)
10:40 Daily Deal: The 2022 Ultimate Cybersecurity Analyst Preparation Bundle (0)
09:29 A Fight Between Facebook And The British Medical Journal Highlights The Difficulty Of Moderating 'Medical Misinformation' (9)
06:29 Court Ruling Paves The Way For Better, More Reliable Wi-Fi (4)
20:12 Eighth Circuit (Again) Says There's Nothing Wrong With Detaining Innocent Minors At Gunpoint (15)
15:48 China's Regulatory War On Its Gaming Industry Racks Up 14k Casualties (10)
13:31 Chinese Government Fines Local Car Dealerships For Surveilling While Not Being The Government (5)
12:08 Eric Clapton Pretends To Regret The Decision To Sue Random German Woman Who Listed A Bootleg Of One Of His CDs On Ebay (29)
10:44 ICE Is So Toxic That The DHS's Investigative Wing Is Asking To Be Completely Separated From It (29)
10:39 Daily Deal: The 2022 Complete Raspberry Pi And Arduino Developer Bundle (0)
09:31 Google Blocked An Article About Police From The Intercept... Because The Title Included A Phrase That Was Also A Movie Title (24)
06:22 Wireless Carriers Balk At FAA Demand For 5G Deployment Delays Amid Shaky Safety Concerns (16)
19:53 Tenth Circuit Denies Qualified Immunity To Social Worker Who Fabricated A Mother's Confession Of Child Abuse (35)
15:39 Sci-Hub's Creator Thinks Academic Publishers, Not Her Site, Are The Real Threat To Science, And Says: 'Any Law Against Knowledge Is Fundamentally Unjust' (34)
13:32 Federal Court Tells Proud Boys Defendants That Raiding The Capitol Building Isn't Covered By The First Amendment (25)
12:14 US Courts Realizing They Have A Judge Alan Albright Sized Problem In Waco (17)
10:44 Boston Police Department Used Forfeiture Funds To Hide Purchase Of Surveillance Tech From City Reps (16)
10:39 Daily Deal: The Ultimate Microsoft Excel Training Bundle (0)
09:20 NY Senator Proposes Ridiculously Unconstitutional Social Media Law That Is The Mirror Opposite Of Equally Unconstitutional Laws In Florida & Texas (25)
06:12 Telecom Monopolies Are Exploiting Crappy U.S. Broadband Maps To Block Community Broadband Grant Requests (7)
12:00 Funniest/Most Insightful Comments Of 2021 At Techdirt (17)
10:00 Gaming Like It's 1926: Join The Fourth Annual Public Domain Game Jam (6)
09:00 New Year's Message: The Arc Of The Moral Universe Is A Twisty Path (33)
19:39 DHS, ICE Begin Body Camera Pilot Program With Surprisingly Good Policies In Place (7)
15:29 Remembering Techdirt Contributors Sherwin And Elliot (1)
13:32 DC Metro PD's Powerful Review Panel Keeps Giving Bad Cops Their Jobs Back (6)
12:11 Missouri Governor Still Expects Journalists To Be Prosecuted For Showing How His Admin Leaked Teacher Social Security Numbers (39)
10:48 Oversight Board Overturning Instagram Takedown Of Ayahuasca Post Demonstrates The Impossibility Of Content Moderation (10)
More arrow
This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it