Schneier: The Strange Story of Dual_EC_DRBG
[Posted November 15, 2007 by corbet]
Bruce Schneier has posted
an interesting look at a U.S. random number generator standard. "
What Shumow and Ferguson showed is that these numbers have a relationship with a second, secret set of numbers that can act as a kind of skeleton key. If you know the secret numbers, you can predict the output of the random-number generator after collecting just 32 bytes of its output. To put that in real terms, you only need to monitor one TLS internet encryption connection in order to crack the security of that protocol. If you know the secret numbers, you can completely break any instantiation of Dual_EC_DRBG."
(
Log in to post comments)