Security provider RSA endowed its BSAFE cryptography toolkit with a second NSA-influenced random number generator (RNG) that's so weak it makes it easier for eavesdroppers to decrypt protected communications, Reuters reported Monday. . Citing soon-to-be-published research from several universities, Reuters said the Extended Random extension for secure websites allows attackers to work tens of thousands of times faster when breaking cryptography that uses the Dual EC_DRBG algorithm to generate the random numbers that populate a specific cryptographic key. . Investigations show that the BSAFE toolkit from RSA relies on a weak RNG influenced by the NSA, jeopardizing the integrity of secure communications.. BSAFE Cryptography, Random Number Generation, Security Flaw, Decryption Risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.