News / USA

Study: NSA Infiltrated RSA Security More Deeply Than Thought

A sign marks the entrance to RAS's facility in Bedford, Massachusetts, March 28, 2014.
A sign marks the entrance to RAS's facility in Bedford, Massachusetts, March 28, 2014.
Reuters
Security industry pioneer RSA adopted not just one but two encryption tools developed by the U.S. National Security Agency, greatly increasing the spy agency's ability to eavesdrop on some Internet communications, according to a team of academic researchers.
 
Reuters reported in December that the NSA had paid RSA $10 million to make a now-discredited cryptography system the default in software used by a wide range of Internet and computer security programs. The system, called Dual Elliptic Curve, was a random number generator, but it had a deliberate flaw - or “back door” - that allowed the NSA to crack the encryption.
 
A group of professors from Johns Hopkins, the University of Wisconsin, the University of Illinois and elsewhere now say they have discovered that a second NSA tool exacerbated the RSA software's vulnerability.
 
The professors found that the tool, known as the “Extended Random” extension for secure websites, could help crack a version of RSA's Dual Elliptic Curve software tens of thousands of times faster, according to an advance copy of their research shared with Reuters.
 
While Extended Random was not widely adopted, the new research sheds light on how the NSA extended the reach of its surveillance under cover of advising companies on protection.
 
RSA, now owned by EMC Corp, did not dispute the research when contacted by Reuters for comment. The company said it had not intentionally weakened security on any product and noted that Extended Random did not prove popular and had been removed from RSA's protection software in the last six months.
 
“We could have been more skeptical of NSA's intentions,” RSA Chief Technologist Sam Curry told Reuters. “We trusted them because they are charged with security for the U.S. government and U.S. critical infrastructure.”
 
Curry declined to say if the government had paid RSA to incorporate Extended Random in its BSafe security kit, which also housed Dual Elliptic Curve.
 
An NSA spokeswoman declined to comment on the study or the intelligence agency's motives in developing Extended Random.
 
The agency has worked for decades with private companies to improve cybersecurity, largely through its Information Assurance Directorate. After the 9/11 attacks, the NSA increased surveillance, including inside the United States, where it had previously faced strict restrictions.
 
Documents leaked by former NSA contractor Edward Snowden showed that the agency also aimed to subvert cryptography standards. A presidential advisory group in December said that practice should stop, though experts looking at the case of Dual Elliptic Curve have taken some comfort in concluding that only the NSA could likely break it.
 
“It's certainly well-designed,” said security expert Bruce Schneier, a frequent critic of the NSA. “The random number generator is one of the better ones.”

Random numbers
 
Cryptography experts have long been suspicious of Dual Elliptic Curve, but the National Institute of Standards and Technology and RSA only renounced the technology after Snowden leaked documents about the back door last year.
 
That was also when the academic team set out to see if they could break Dual Elliptic Curve by replacing two government-issued points on the curve with their own. The professors plan to publish a summary of their study this week and present their findings at a conference this summer.
 
Random numbers are used to generate cryptographic keys - if you can guess the numbers, you can break the security of the keys. While no random number generator is perfect, some generators were viewed as more predictable than others.
 
In a Pentagon-funded paper in 2008, the Extended Random protocol was touted as a way to boost the randomness of the numbers generated by the Dual Elliptic Curve.
 
But members of the academic team said they saw little improvement, while the extra data transmitted by Extended Random before a secure connection begins made predicting the following secure numbers dramatically easier.
 
“Adding it doesn't seem to provide any security benefits that we can figure out,” said one of the authors of the study, Thomas Ristenpart of the University of Wisconsin.
 
Johns Hopkins Professor Matthew Green said it was hard to take the official explanation for Extended Random at face value, especially since it appeared soon after Dual Elliptic Curve's acceptance as a U.S. standard.
 
“If using Dual Elliptic Curve is like playing with matches, then adding Extended Random is like dousing yourself with gasoline,” Green said.
 
The NSA played a significant role in the origins of Extended Random. The authors of the 2008 paper on the protocol were Margaret Salter, technical director of the NSA's defensive Information Assurance Directorate, and an outside expert named Eric Rescorla.
 
Rescorla, who has advocated greater encryption of all Web traffic, works for Mozilla, maker of the Firefox web browser. He and Mozilla declined to comment. Salter did not respond to requests for comment.
 
Though few companies appear to have embraced Extended Random, RSA did. The company built in support for the protocol in BSafe toolkit versions for the Java programming language about five years ago, when a preeminent Internet standards group - the Internet Engineering Task Force - was considering whether to adopt Extended Random as an industry standard. The IETF decided in the end not to adopt the protocol.
 
RSA's Curry said that if Dual Elliptic Curve had been sound, Extended Random would have made it better. “When we realized it was not likely to become a standard, we did not enable it in any other BSafe libraries,” he added.
 
The academic researchers said it took about an hour to crack a free version of BSafe for Java using about $40,000 worth of computer equipment. It would have been 65,000 times faster in versions using Extended Random, dropping the time needed to seconds, according to Stephen Checkoway of Johns Hopkins.
 
The researchers said it took them less than 3 seconds to crack a free version of BSafe for the C programming language, even without Extended Random, because it already transmitted so many random bits before the secure connection began. And it was so inexpensive it could easily be scaled up for mass surveillance, the researchers said.

You May Like

Turkey's Erdogan: Women Not Equal to Men

Speaking at conference in Istanbul, President Erdogan says Islam has defined a position for women: motherhood More

Ahead of SAARC Summit, Subdued Expectations

Some regional analysts say distrust between Pakistani, Indian officials has slowed SAARC's progress over the year More

Philippines Leery of Development on Reef Reclamation in S. China Sea

Chinese land reclamation projects in area have been ongoing for years, but new satellite imagery reportedly shows China’s massive construction project More

This forum has been closed.
Comments
     
There are no comments in this forum. Be first and add one

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Aung San Suu Kyi: Myanmar Opposition to Keep Pushing for Constitutional Changei
X
November 24, 2014 10:09 PM
Myanmar opposition leader Aung San Suu Kyi says she and her supporters will continue pushing to amend a constitutional clause that bars her from running for president next year. VOA's Than Lwin Htun reports from the capital Naypyitaw in this report narrated by Colin Lovett.
Video

Video Aung San Suu Kyi: Myanmar Opposition to Keep Pushing for Constitutional Change

Myanmar opposition leader Aung San Suu Kyi says she and her supporters will continue pushing to amend a constitutional clause that bars her from running for president next year. VOA's Than Lwin Htun reports from the capital Naypyitaw in this report narrated by Colin Lovett.
Video

Video Mali Attempts to Shut Down Ebola Transmission Chain

Senegal and Nigeria were able to stop small Ebola outbreaks by closely monitoring those who had contact with the sick person and quickly isolating anyone with symptoms. Mali is now scrambling to do the same. VOA’s Anne Look reports from Mali on what the country is doing to shut down the chain of transmission.
Video

Video Ukraine Marks Anniversary of Deadly 1930s Famine

During a commemoration for millions who died of starvation in Ukraine in the early 1930s, President Petro Poroshenko lashed out at Soviet-era totalitarianism for causing the deaths and accused today’s Russian-backed rebels in the east of using similar tactics. VOA’s Daniel Shearf reports from Kyiv.
Video

Video Hong Kong Protests at a Crossroads

New public opinion polls in Hong Kong indicate declining support for pro-democracy demonstrations after weeks of street protests. VOA’s Bill Ide in Guangzhou and Pros Laput in Hong Kong spoke with protesters and observers about whether demonstrators have been too aggressive in pushing for change.
Video

Video US Immigration Relief Imminent for Mixed-Status Families

Tens of thousands of undocumented immigrants in the Washington, D.C., area may benefit from a controversial presidential order announced this week. It's not a path to citizenship, as some activists hoped. But it will allow more immigrants who arrived as children or who have citizen children, to avoid deportation and work legally. VOA's Victoria Macchi talks with one young man who benefited from an earlier presidential order, and whose parents may now benefit after years of living in fear.
Video

Video New Skateboard Defies Gravity

A futuristic dream only a couple of decades ago, the hoverboard – a skateboard that floats above the ground - has finally been made possible. While still not ready for mass production, it promises to become a cool mode of transport... at least over some surfaces. VOA’s George Putic reports.
Video

Video Falling Gas Prices Impact US Oil Extraction

With the price of oil now less than $80 a barrel, motorists throughout the United States are benefiting from gas prices below $3 a gallon. But as VOA’s Kane Farabaugh reports, the decreasing price of petroleum has a downside for the hydraulic fracturing industry in the United States.
Video

Video Tensions Build on Korean Peninsula Amid Military Drills

It has been another tense week on the Korean peninsula as Pyongyang threatened to again test nuclear weapons while the U.S. and South Korean forces held joint military exercises in a show of force. VOA’s Brian Padden reports from the Kunsan Air Base in South Korea.
Video

Video Mama Sarah Obama Honored at UN Women’s Entrepreneurship Day

President Barack Obama's step-grandmother is in the United States to raise money to build a $12 million school and hospital center in Kogelo, Kenya, the birthplace of the president's father, Barack Obama, Sr. She was honored for her decades of work to aid poor Kenyans at a Women's Entrepreneurship Day at the United Nations.
Video

Video Ebola Economic Toll Stirs W. Africa Food Security Concerns

The World Bank said Wednesday that it expects the economic impact of the Ebola outbreak on the sub-Saharan economy to cost somewhere betweenf $3 billion to $4 billion - well below a previously-outlined worst-case scenario of $32 billion. Some economists, however, paint a gloomier picture - warning that the disruption to regional markets and trading is considerable. Henry Ridgwell reports from London.
Video

Video Chaos, Abuse Defy Solution in Libya

The political and security crisis in Libya is deepening, with competing governments and, according to Amnesty International, widespread human rights violations committed with impunity. VOA’s Al Pessin reports from London.
Video

Video US Hosts Record 866,000 Foreign Students

Close to 900,000 international students are studying at American universities and colleges, more than ever before. About half of them come from Asia, mostly China. The United States hosts more foreign students than any other country in the world, and its foreign student population is steadily growing. Zlatica Hoke reports.

All About America

AppleAndroid