Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Intelligence

RSA is accused again to have helped NSA to weaken security products

A group of researchers from Johns Hopkins University discovered that a second NSA tool aggravate the RSA security software’s vulnerability. We all remember the Snowden‘s revelations regarding the support provided my RSA Security, a division of EMC company, to the NSA Intelligence. Snowden accused the RSA to have deliberately inserted an alleged encryption backdoor in […]

RSA is accused again to have helped NSA to weaken security products

A mobile phone simulating a call to German Chancellor Angela Merkel next to a tablet computer showing the logo of the United Staes’ National Security Agency (NSA) is seen in this multiple exposure picture illustration taken in Frankfurt October 28, 2013. A German newspaper said on Sunday that U.S. President Barack Obama knew his intelligence […]

A group of researchers from Johns Hopkins University discovered that a second NSA tool aggravate the RSA security software’s vulnerability.

We all remember the Snowden‘s revelations regarding the support provided my RSA Security, a division of EMC company, to the NSA Intelligence. Snowden accused the RSA to have deliberately inserted an alleged encryption backdoor in the BSafe software.

According the news published by the Reuters agency, documents leaked by former NSA contractor Edward Snowden show that the NSA created and promulgated a flawed formula for generating random numbers.

The flawed random number generator (Dual_EC_DRBG) was used to create a “back door” in popular encryption products, Reuters reported that RSA became the most important distributor of that formula by rolling it into a software tool called Bsafe, a security tool installed in many personal computers.

RSA-denies-claims-on-BSafe-and-NSA

According the report disclosed by Snowden, the NSA paid a $10 million fee to RSA for the adoption of the flawed algorithm as the default choice in his products, but RSA has always refused the claims.

A group of researchers at Johns Hopkins University, the University of Illinois, has claimed that the choice of the Dual_EC_DRBG systems was not isolated, RSA also adopted another tool called Extended Random extension for secure websites, under the suggestion of the National Security Agency.

The choice for the adoption of the Extended Random extension allows the NSA to crack a version of the Dual Elliptic Curve software tens of thousands of times faster, Reuters reported.

The professors found that the tool, known as the “Extended Random” extension for secure websites, could help crack a version of RSA’s Dual Elliptic Curve software tens of thousands of times faster, according to an advance copy of their research shared with Reuters. While Extended Random was not widely adopted, the new research sheds light on how the NSA extended the reach of its surveillance under cover of advising companies on protection.

The researchers demonstrated that it is possible to crack a free version of BSafe for Java in just one hour, using about $40,000 worth of computer equipment.

“It would have been 65,000 times faster in versions using Extended Random, dropping the time needed to seconds, according to Stephen Checkoway of Johns Hopkins.The researchers said it took them less than 3 seconds to crack a free version of BSafe for the C programming language, even without Extended Random, because it already transmitted so many random bits before the secure connection began. And it was so inexpensive it could easily be scaled up for mass surveillance, the researchers said” stated Reuters.

This case is yet another pickaxe to the reputation of US Intelligence,

Pierluigi Paganini

(Security Affairs –  RSA, NSA)