NSA Crypto Backdoors

The cluster focuses on discussions of the NSA's alleged history of weakening or backdooring cryptographic standards, particularly Dual_EC_DRBG, DES, and elliptic curves, with references to past scandals and skepticism toward government-influenced crypto.

📉 Falling 0.3x Security
3,147
Comments
19
Years Active
5
Top Authors
#4380
Topic ID

Activity Over Time

2007
1
2008
6
2009
20
2010
25
2011
31
2012
68
2013
518
2014
253
2015
266
2016
200
2017
171
2018
183
2019
160
2020
163
2021
215
2022
235
2023
293
2024
154
2025
185

Keywords

US TIL CFRG RSA DES CSO AE arstechnica.com IETF schneier.com nsa crypto cryptography aes des backdoor key constants nist sha

Sample Comments

nerdy Mar 26, 2015 View on HN

Yeah the NSA would never try to break crypto anyhow coughDual_EC_DRBGcough

thelittleone Jan 3, 2024 View on HN

Like the Dual_EC_DRBG issue involving the NSA?

monkeynotes Jul 8, 2019 View on HN

TIL that the NSA designed SHA and there is at least a chance they implementation of the elliptic curve has a back-door[1][1] https://arstechnica.com/information-technology/2014/01/how-t...

MertsA Nov 8, 2021 View on HN

The NSA will never do that as it would be tipping their hand about whatever novel technique they reveal. In the past the NSA actually did provide some constants that went into DES and people were suspicious as the constants weren't randomly chosen. Later on it came out that differential cryptanalysis would have broken the original constants but the NSA provided ones were chosen to thwart this. They clearly knew about it well ahead of it being discovered in academia. Then you have the NSA&#x

eevilspock Jun 17, 2014 View on HN

The NSA deliberately weakened crypto keys/code. How is that any different?

maze-le May 15, 2018 View on HN

Nope, see: https://en.wikipedia.org/wiki/Dual_EC_DRBG

jiggawatts Nov 22, 2024 View on HN

The NSA has definitely weakened or back-doored crypto. It’s not a conspiracy or even a secret! It was a matter of (public) law in the 90s, such as “export grade” crypto.Most recently Dual_EC_DRBG was forced on American vendors by the NSA, but the backdoor private key was replaced by Chinese hackers in some Juniper devices and used by them to spy on westerners.Look up phrase likes “nobody but us” (NOBUS), which is the aspirational goal of these approaches, but often fails, leaving everyone

Evidlo Jun 24, 2024 View on HN

If the universe uses Dual_EC_DRBG then the NSA can read your mind.

jjgreen Nov 18, 2022 View on HN

This is the same NSA which backdoored Dual_EC_DRBG right?

helloooooooo Mar 9, 2022 View on HN

Or maybe the choice of Dual EC DRBG constants are intended to protect against a new cryptanalysis technique known only to the NSA