Todos los fabricantes

Vendor lineage

RSA Security - the company that fought Clipper, then shipped Dual_EC

Nine years with a suspect random number generator as the default, a 10 million dollar contract, and a denial that answered a different question.

RSA Security is an American security company, founded in 1982 by the authors of the RSA algorithm, whose BSAFE toolkit shipped the Dual_EC_DRBG generator as its default from 2004 to 2013.

RSA Security is named for the algorithm its founders published, and for most of the 1990s it was the company that fought the government over encryption and won: the campaign against the Clipper Chip, the proposal to mandate a government-accessible key in every phone, was led from here. That history is the reason what followed is worth a whole entry rather than a paragraph.

From 2004 until 2013 the default random number generator in BSAFE, the company's widely licensed cryptographic toolkit, was Dual_EC_DRBG. Random numbers are where keys come from, and a generator whose output can be predicted makes every key derived from it recoverable. In 2007 two Microsoft researchers showed at a cryptography conference that this particular design had a property nobody could explain: one of its parameters, if chosen with a secret in mind, gave whoever chose it the ability to reverse the generator. They did not claim anyone had done so. They showed that the door had a lock, and that somebody might hold the key.

It stayed the default for six more years. In December 2013 Reuters reported that a 10 million dollar contract with the National Security Agency had made that choice, and that setting the algorithm as the default was a condition of it. The number needs its context: the BSAFE division had earned 27.5 million dollars the previous year, so the payment was more than a third of what the whole business made. The Snowden material had by then confirmed that the agency had contributed the algorithm to the standard.

The company's reply should be read as carefully as it was written. It categorically denied entering a secret contract to incorporate a known flawed generator - and said it had chosen the algorithm in 2004, before the flaw was public, when the agency was a trusted participant in strengthening encryption; that the generator was one option among several; and that it was kept for its value in compliance. A university cryptography group described this as an artfully worded quasi-denial. What was not denied was the payment.

Two things in that paragraph matter beyond this company. The first is compliance. The algorithm survived six years of expert warning because it was in the government standard, and using the standard is what compliance rewards - so the process meant to certify security is what kept the suspect component in place. The second is the shape of the denial. It answers the accusation as phrased and leaves the fact standing, and the discipline of reading a vendor statement for what it does not say is one this catalogue recommends everywhere.

For the taxonomy of supplier compromise this adds a sixth route to the five already recorded: compromise the standard, and every compliant product inherits the weakness without any single manufacturer having to be persuaded. The agency withdrew the algorithm from the standard in 2014 and the company removed it from the toolkit in 2015. The 2011 breach of the same company's SecurID tokens has its own entry in the glossary and is a different story; this one is about a choice, and it was made twice - once in 2004, and again every year it was not reversed.

Sources