The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label Certicom. Tampilkan semua postingan
Tampilkan postingan dengan label Certicom. Tampilkan semua postingan

Jumat, 24 Januari 2014

BlackBerry Ltd, the NSA, and The Encryption Algorithm that NIST Warned You Not To Use

As part of my ongoing efforts to sort fact from fiction regarding the RSA - NSA debacle, I learned that BlackBerry, Ltd (NASDAQ: BBRY), with its acquisition of Certicom in 2009, became the patent-holder for Dual_EC_DRBG. And since BlackBerry devices are used by so many government and military customers, I contacted the company to inquire whether they had notified their customers about the NIST warning. Before I share what happened with that inquiry, here's a short recap of the facts:

  • In 2003, Certicom announced that it licensed its Elliptic Curve Cryptography technology to the NSA for US$25 million.
  • In 2004, the NSA convinced RSA to make it the default CPRNG (Crypto Pseudo Random Number Generator) for its BSAFE software for an alleged US$10 million. 
  • In December, 2005 NIST issued its draft standard for Dual_EC_DRBG.
  • In February, 2006, RSA announced that BSAFE had conformed with Suite B cryptography requirements issued by the NSA.
  • In March, 2006, RSA announced that the NSA had chosen BSAFE "for use in a classified communications project".
  • Starting in March, 2006 and continuing into 2007, security researchers Kristian Gjøsteen, Berry Schoenmakers and Andrey Sidorenko, Dan Shumow and Niels Ferguson, and Bruce Schneier all published articles warning about weaknesses in Dual EC DRBG. The final NIST standard SP 800-90A published in June 2006 included mention of those weaknesses as unresolved.

BlackBerry Ltd

According to NIST's DRBG Validation List, the following BlackBerry products include Dual EC DRBG:
  • BlackBerry Cryptographic Algorithm Library, Version 6.1 which apparently provides advanced cryptographic functionality to systems running BlackBerry 10 OS and components of BlackBerry Enterprise Service 10. 
  • BlackBerry Algorithm Library for Secure Work Space Version 1.0. ""The BlackBerry Algorithm Library for Secure Work Space provides a suite of cryptographic services utilized by the BlackBerry Cryptographic Library for the BlackBerry Secure Work Space (BBSWS). BBSWS provides the secure operation and management of iOS and Android devices when used in conjunction with BlackBerry® mobile device management solutions." 
  • BlackBerry Tablet Cryptographic Library Version 5.6. "The BlackBerry Tablet Cryptographic Library is the software module that provides advanced cryptographic functionality to BlackBerry Tablets." 
I passed this information to BlackBerry and within a couple of days received this response from Mike K. Brown, VP of Security Product Management & Research, BlackBerry.:
"The Dual EC DRBG algorithm is only available to third party developers via the Cryptographic APIs on the platform. In the case of the Cryptographic API, it is available if a 3rd party developer wished to use the functionality and explicitly designed and developed a system that requested the use of the API."
I then asked if BlackBerry has forwarded the NIST warning about not using Dual EC DRBG to its customers or developers and received this response:
"To your other question, the reason we didn’t issue an advisory is because it wasn’t a vulnerability. We only do them for fixes that are needed. You can read more about that process here: http://bizblog.blackberry.com/2013/07/security-privacy-malware-notices-advisories/. "
Therefore, since this warning from NIST:
"Recommending against the use of SP 800-90A Dual Elliptic Curve Deterministic Random Bit Generation: NIST strongly recommends that, pending the resolution of the security concerns and the re-issuance of SP 800-90A, the Dual_EC_DRBG, as specified in the January 2012 version of SP 800-90A, no longer be used."
does not meet BlackBerry's definition of a vulnerability, the company hasn't issued an advisory. If you are a BlackBerry customer or developer, be advised that it's apparently up to you to keep informed about possible backdoors among the encryption algorithms included with BlackBerry products.
Add to Cart View detail

Rabu, 15 Januari 2014

Guess Who Owns The Patent to RSA's Backdoor Algorithm? Blackberry

Meet Certicom, a subsidiary of Blackberry Ltd, who provides the core technology for the National Security Agency (NSA) Suite B standard for secure government communications. Certicom holds 350 patents, many of which cover key aspects of Elliptic Curve Cryptography (ECC) including this one:


Elliptic curve random number generation 


Abstract
An elliptic curve random number generator avoids escrow keys by choosing a point Q on the elliptic curve as verifiably random. An arbitrary string is chosen and a hash of that string computed. The hash is then converted to a field element of the desired field, the field element regarded as the x-coordinate of a point Q on the elliptic curve and the x-coordinate is tested for validity on the desired elliptic curve. If valid, the x-coordinate is decompressed to the point Q, wherein the choice of which is the two points is also derived from the hash value. Intentional use of escrow keys can provide for back up functionality. The relationship between P and Q is used as an escrow key and stored by for a security domain. The administrator logs the output of the generator to reconstruct the random number with the escrow key.

Certicom was acquired by Research In Motion (now known as Blackberry Ltd) in March 2009 but it has been in business since 1985. The patent authors are two Certicom employees Daniel Brown and Scott A. Vanstone who are also members of the ANSI X9.82 standardization committee. Matthew Green, a cryptography professor at Johns Hopkins, wrote a blog post describing Dual EC DRBG's history with Brown and Vanstone, ANSI and the NSA on December 28, 2013.
The existence of this patent does not mean that Brown and Vanstone were responsible for Dual EC. In fact, the generator appears to be an NSA invention, and may date back to the early 2000s. What this patent demonstrates is that some members of the ANSI committee, of which RSA was also a member, had reason to at least suspect that Dual EC could be used to create a wiretapping backdoor. (Update: John Kelsey confirms this.)
To date, Blackberry has not made a public announcement about its use of Dual EC DRBG but here are the Blackberry products that use it according to NIST:
  • "The BlackBerry Algorithm Library for Secure Work Space provides a suite of cryptographic services utilized by the BlackBerry Cryptographic Library for the BlackBerry Secure Work Space (BBSWS). BBSWS provides the secure operation and management of iOS and Android devices when used in conjunction with BlackBerry® mobile device management solutions."
  • "The BlackBerry Cryptographic Algorithm Library is a suite of cryptographic algorithms that provides advanced cryptographic functionality to systems running BlackBerry 10 OS and components of BlackBerry Enterprise Service 10."
  • "The BlackBerry Tablet Cryptographic Library is the software module that provides advanced cryptographic functionality to BlackBerry Tablets."
Other companies that have Dual EC DRBG in their products are Microsoft, RSA, Cisco, Juniper Networks, McAfee, Symantec, Samsung, Lancope, SafeLogic, GE Healthcare, Thales eSecurity, Panzura, Catbird Networks, ARX, Kony, CoCo Communications, Riverbed Technology, OpenSSL Foundation, Certicom, and Mocana. 

I've only found a few who have made public announcements advising their customers about Dual EC use: Cisco and SafeLogic. The OpenSSL Foundation has had many discussions about Dual EC in their own forum. Please leave a comment if you know of other advisories by the remaining companies which I've missed.

Related

BlackBerry Ltd, the NSA, and The Encryption Algorithm that NIST Warned You Not To Use
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID