Secret Backdoor in Dual_EC_DRBG (New Encryption Standard)
In an eye-opening post, Bruce Schneier describes the very scary back door that exists in a New Encryption Standard being put forward by NSA. Equally interesting is this PDF presentation that explains the back door in detail.
Even if no one knows the secret numbers, the fact that the backdoor is present makes Dual_EC_DRBG very fragile. If someone were to solve just one instance of the algorithm's elliptic-curve problem, he would effectively have the keys to the kingdom. He could then use it for whatever nefarious purpose he wanted. Or he could publish his result, and render every implementation of the random-number generator completely insecure.So what do you have to worry about? Microsoft is adding this standard of random number generator in Windows Vista SP1. Here's Bruce's post.






