Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Demeter

(85,373 posts)
20. Review Group Falsely Claims No NSA Backdoors in U.S. Software
Mon Dec 23, 2013, 08:35 AM
Dec 2013
http://www.moonofalabama.org/2013/12/review-group-falsly-claims-no-nsa-backdoors-in-us-software.html

In its 28th recommendation Obama's NSA Review Group, which included no technological experts, asserted (pdf via emptywheel):

Upon review, however, we are unaware of any vulnerability created by the US Government in generally available commercial software that puts users at risk of criminal hackers or foreign governments decrypting their data. Moreover, it appears that in the vast majority of generally used, commercially available encryption software, there is no vulnerability, or “backdoor,” that makes it possible for the US Government or anyone else to achieve unauthorized access.


Like other seemingly assuring assertions from the NSA and related entities this one turns out to be false:

As a key part of a campaign to embed encryption software that it could crack into widely used computer products, the U.S. National Security Agency arranged a secret $10 million contract with RSA, one of the most influential firms in the computer security industry, Reuters has learned.

Documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers to create a "back door" in encryption products, the New York Times reported in September. Reuters later reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe that is used to enhance security in personal computers and many other products.

Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract.


RSA security products, widely used so far, are not secure. The NSA paid RSA to use a weak encryption which the NSA can easily break. If the NSA can break these others can too. They thereby have a backdoor into RSA software and whoever uses those insecure products should do away with them.

If the NSA Review Group was unaware of paid for NSA backdoors in commercial products how many of its other recommendations tackle the real problems?

Yeah. Thought so.

Recommendations

0 members have recommended this reply (displayed in chronological order):

Who is the libertarian geek? Anyone in particular? Demeter Dec 2013 #1
It could be just as easily him Warpy Dec 2013 #2
The cartoonist Tansy_Gold Dec 2013 #3
Five Years After Lehman's: Did We Learn Anything? By L. Randall Wray - EconoMonitor Demeter Dec 2013 #4
Obama Exempts “If You Like It You Can Keep It” Cancelees from the Individual Mandate Demeter Dec 2013 #5
I never thought I'd be an outlaw, but the Affordable Care Act might make me one By Diane Snyder Demeter Dec 2013 #24
Latest ACA problem: New Medicaid enrollees may find their coverage is limited By Beth Fitzgerald Demeter Dec 2013 #26
Colorado Takes Health Plans To People Shopping For Groceries Demeter Dec 2013 #37
Irish banking world rocked as three financiers in court Demeter Dec 2013 #6
Insight: How U.S. spying cost Boeing multibillion-dollar jet contract Demeter Dec 2013 #7
N.S.A. Spied on Allies, Aid Groups and Businesses Demeter Dec 2013 #8
Major computer security firm RSA took $10 mln from NSA to weaken encryption Demeter Dec 2013 #9
A spy world reshaped by Edward Snowden A MUST READ: TIES IT ALL TOGETHER Demeter Dec 2013 #13
Review Group Falsely Claims No NSA Backdoors in U.S. Software Demeter Dec 2013 #20
The NSA review panel didn't answer the real question: was any of this legal? Demeter Dec 2013 #21
Conning the Record, Conning the Courts, Defrauding the People Demeter Dec 2013 #31
Mr. Obama’s Disappointing Response NYT EDITORIAL Demeter Dec 2013 #35
NSA review panel members to appear before Senate committee in January Demeter Dec 2013 #36
Why I want Bitcoin to die in a fire By Charlie Stross Demeter Dec 2013 #10
Bitcoin, Magical Thinking, and Political Ideology Alex Payne Demeter Dec 2013 #11
Banks Mostly Avoid Providing Bitcoin Services Demeter Dec 2013 #46
Into the Bitcoin Mines By NATHANIEL POPPER Demeter Dec 2013 #48
Big US online retailer to accept Bitcoin Demeter Dec 2013 #49
Trust Me (I'm a kettle) By Charlie Stross Demeter Dec 2013 #12
ANOTHER TTP! The corporation invasion by Lori M Wallach Demeter Dec 2013 #14
Investors’ Story Left Out of Wall St. ‘Wolf’ Movie By SUSAN ANTILLA Demeter Dec 2013 #15
FOR THOSE WHO HAVEN'T "WRAPPED UP" THEIR CHRISTMAS GIVING, YET Demeter Dec 2013 #16
The kitty wrap, lol! DemReadingDU Dec 2013 #41
I should try that with Moby. Tansy_Gold Dec 2013 #47
It would only work on my cats if they were dead Demeter Dec 2013 #50
The Most Memorable Words of 2013 Demeter Dec 2013 #17
Whew! Just that little bit of posting left me exhausted Demeter Dec 2013 #18
Detroit's Dan Gilbert: Henry Ford or Henry Potter? Demeter Dec 2013 #19
Secret Handshakes Greet Frat Brothers on Wall Street xchrom Dec 2013 #22
Swiss Banks Employ Army of Advisers for U.S. Amnesty Plan xchrom Dec 2013 #23
European Stocks Climb on IMF Outlook; ARM Holdings Gains xchrom Dec 2013 #25
Probes See U.K. Market Manipulation Reports Rise 43% xchrom Dec 2013 #27
Hedge Funds Cut Gold Bull Bets Amid Record Outflows: Commodities xchrom Dec 2013 #28
"People wanted to take on risk this year" Demeter Dec 2013 #33
Vietnam GDP Rises 5.42% in 2013; Estimate 5.3% Gain xchrom Dec 2013 #29
Japan Unveils Record 2014 Budget Draft as Debt Burden Mounts xchrom Dec 2013 #30
Australia Sets Higher Capital Buffer for Four Biggest Banks xchrom Dec 2013 #32
MICHAEL HUSDON EXPLAINS IT ALL Demeter Dec 2013 #34
A Locked Door, A Secret Meeting And The Birth Of The Fed Demeter Dec 2013 #38
THIS JUST IN: Obamacare raising health costs for most, poll finds Demeter Dec 2013 #39
First.... Tansy_Gold Dec 2013 #51
Followed by.... Tansy_Gold Dec 2013 #52
BAE finalizes South Korean F-16 upgrade deal, eyes more prospects xchrom Dec 2013 #40
Italy PM Letta pledges reform pact in January xchrom Dec 2013 #42
For pity's sake! This isn't a Santa Claus Rally It's a Xmas Snowjob! Demeter Dec 2013 #43
Off Limits, but Blessed by the Fed By GRETCHEN MORGENSON Demeter Dec 2013 #44
The opposite of what they do in America by David Atkins Demeter Dec 2013 #45
Obama Repeals ObamaCare WSJ Editorial board member Joe Rago MUST READ! Demeter Dec 2013 #53
Latest Discussions»Issue Forums»Economy»STOCK MARKET WATCH -- Mon...»Reply #20