- Joined
- Jan 27, 2010
- Posts
- 71,573
- Reaction score
- 1,221
- Points
- 2,125
- Location
- State Of Confusion
- Website
- wober.net
RSA, the internet security firm, has warned customers not to use one of its own encryption algorithms after fears it can be unlocked by the US National Security Agency (NSA).
In an advisory note to its developer customers, RSA said that a default algorithm in one of its toolkits could contain a "back door" that would allow the NSA to decrypt encrypted data.
It "strongly recommends" switching to other random number generators.
RSA is reviewing all its products.
The advice comes in the wake of New York Times allegations that the NSA may have intentionally introduced a flaw into the algorithm - known as Dual Elliptic Curve Deterministic Random Bit Generation - and then tried to get it adopted as a security standard by the US National Institute of Standards and Technology.
Full article