> But internal memos leaked by a former N.S.A. contractor, Edward Snowden, suggest that the N.S.A. generated one of the random number generators used in a 2006 N.I.S.T. standard — called the Dual EC DRBG standard — which contains a back door for the N.S.A. In publishing the standard, N.I.S.T. acknowledged “contributions” from N.S.A., but not primary authorship.
> Internal N.S.A. memos describe how the agency subsequently worked behind the scenes to push the same standard on the International Organization for Standardization. “The road to developing this standard was smooth once the journey began,” one memo noted. “However, beginning the journey was a challenge in finesse.”
> At the time, Canada’s Communications Security Establishment ran the standards process for the international organization, but classified documents describe how ultimately the N.S.A. seized control. “After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft,” the memo notes. “Eventually, N.S.A. became the sole editor.” [0]
Yes, it's somewhat circumstantial, but pretty damning. If they weren't backdooring it, I'd like to hear an alternate explanation for why the NSA has memos about, in their own words, "behind-the-scenes finessing" to "become the sole editor" and "rewrite" an international standard. All that hard work quietly manipulating things to be just how they want them and, oopsie, the standard just might have a back door! Meanwhile, as described in other comments here, they paid RSA Security to deploy the standard; and were made aware of the possibility of a backdoor[1], but for whatever reason continued recommending its use.
I'd entertain arguments that they were actually trying to strengthen it, as may have happened with DES, but in this case, they were pushing something that civilian contemporaries knew was dangerous. Malice or incompetence seem more likely than secret benevolence here. Or is there some other reasonable explanation I'm missing?
> Internal N.S.A. memos describe how the agency subsequently worked behind the scenes to push the same standard on the International Organization for Standardization. “The road to developing this standard was smooth once the journey began,” one memo noted. “However, beginning the journey was a challenge in finesse.”
> At the time, Canada’s Communications Security Establishment ran the standards process for the international organization, but classified documents describe how ultimately the N.S.A. seized control. “After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft,” the memo notes. “Eventually, N.S.A. became the sole editor.” [0]
Yes, it's somewhat circumstantial, but pretty damning. If they weren't backdooring it, I'd like to hear an alternate explanation for why the NSA has memos about, in their own words, "behind-the-scenes finessing" to "become the sole editor" and "rewrite" an international standard. All that hard work quietly manipulating things to be just how they want them and, oopsie, the standard just might have a back door! Meanwhile, as described in other comments here, they paid RSA Security to deploy the standard; and were made aware of the possibility of a backdoor[1], but for whatever reason continued recommending its use.
I'd entertain arguments that they were actually trying to strengthen it, as may have happened with DES, but in this case, they were pushing something that civilian contemporaries knew was dangerous. Malice or incompetence seem more likely than secret benevolence here. Or is there some other reasonable explanation I'm missing?
[0] http://bits.blogs.nytimes.com/2013/09/10/government-announce... [1] https://projectbullrun.org/dual-ec/patent.html