Slashdot Mirror


Are the NIST Standard Elliptic Curves Back-doored?

IamTheRealMike writes "In the wake of Bruce Schneier's statements that he no longer trusts the constants selected for elliptic curve cryptography, people have started trying to reproduce the process that led to those constants being selected ... and found it cannot be done. As background, the most basic standard elliptic curves used for digital signatures and other cryptography are called the SEC random curves (SEC is 'Standards for Efficient Cryptography'), a good example being secp256r1. The random numbers in these curve parameters were supposed to be selected via a "verifiably random" process (output of SHA1 on some seed), which is a reasonable way to obtain a nothing up my sleeve number if the input to the hash function is trustworthy, like a small counter or the digits of PI. Unfortunately it turns out the actual inputs used were opaque 256 bit numbers, chosen ad-hoc with no justifications provided. Worse, the curve parameters for SEC were generated by head of elliptic curve research at the NSA — opening the possibility that they were found via a brute force search for a publicly unknown class of weak curves. Although no attack against the selected values are currently known, it's common practice to never use unexplainable magic numbers in cryptography standards, especially when those numbers are being chosen by intelligence agencies. Now that the world received strong confirmation that the much more obscure and less widely used standard Dual_EC_DRBG was in fact an NSA undercover operation, NIST re-opened the confirmed-bad standards for public comment. Unless NIST/the NSA can explain why the random curve seed values are trustworthy, it might be time to re-evaluate all NIST based elliptic curve crypto in general."

6 of 366 comments (clear)

  1. Re:Meta review by Anonymous Coward · · Score: -1, Offtopic

    Excellent point. Slashdot is backdoored as well, as Israel's hasbara corps constantly downvote anything critical of Israel's control over the US government.

  2. Re:Meta review by Anonymous Coward · · Score: -1, Offtopic

    I think he was expressing the frustration that some our elected officials are always eager to help Israel, even in situations where we don't need to get involved, or where Israel is in the wrong. This has nothing to do with nationality or race, just religion -- some Christians feel that they must lend aid to Israel for religious reasons, and that need to lend aid trumps common sense now and then.

    The movie takes some liberties with actual events, but Charlie Wilson's War sheds some light on how rich Christians influence politics to aid Israel, strictly for religious reasons -- even when it is bad for America.

    So I think you can be frustrated with that happening, without being an anti-Semite.

  3. Re:Meta review by TheCarp · · Score: -1, Offtopic

    He mentioned isreal, a national country, not jews . He said nothing of Iran, who are also semitic peoples. Hell, most jews are not even semitic; after their religion has traveled the world and induced imigration the world over into Isreal... whereas the Iranians have been there since the land was called Persia.... they are way more semitic than Isrealis.

    --
    "I opened my eyes, and everything went dark again"
  4. Re:Meta review by Ziest · · Score: -1, Offtopic

    Look up "premillennial dispensationalism". It explains why the fundies love Israel so much. It has very little to do with the Jews but it's all about jebuss.

    --
    Another day closer to redwood heaven
  5. Re:Meta review by MickLinux · · Score: -1, Offtopic

    Hmmm... your post ignites a desire in me to ramble. If you're going to bother looking up premillennial dispensationalism, also look up the Great Revolt of Jerusalem.

    It seems that favored race or not, God does not look kindly on people trying to force His hand to enthrone them NOW. Therefore, starting a war with one's neighbors, expecting God to uphold one, is a bad idea. He might take a pass.

    That said, there's a lot of nationalist, Hitlerian craziness in the region all around Isreal as well, and no, it didn't begin with Israel's behavior, it began with Hitler, and a deep-seated desire to exterminate Jews. Every wonder why that is? Maybe it really is because they are God's chosen people, and that makes them a target of envy. Not too many nations have lasted as long as that one has.

    In other words, I do think there is something to all that stuff, but I don't think we have it all quite right.

    But the one part that is definitely right is that yes, it *is* all about Jesus.

    --
    Correct Horse Battery Staple: 72 bits of entropy. Enter "Correct H" into google. When it generates the phrase, that's
  6. Re:Meta review by LynnwoodRooster · · Score: -1, Offtopic

    Cool - good to know that President Obama and Senator Harry Reid (Occupant of the White House and Senate Majority Leader, respectively) are fundies, since we're going to war with Syria. And I guess President Bush is not a fundie, given that he told Israel to "hold fast and suck it up" whilst Scud missiles were falling on them.

    --
    Browsing at +1 - no ACs, I ignore their posts. So refreshing!