Hacker News new | ask | show | jobs
by zakk 982 days ago
> The NIST elliptic curves that power much of modern cryptography were generated in the late ‘90s by hashing seeds provided by the NSA.

I find this deeply troubling. So the seeds were provided by the NSA and they said "don't worry, they were generated hashing a trivial sentence. Unfortunately we forgot it now, but trust us, it's just Jerry joking about getting a raise, nothing more..."

I can't believe this didn't undergo further scrutiny earlier, and I can't believe the seeds haven't been chosen in a more sensible way, such as combining random seeds provided by different parties with competing interests, also including hardware RNGs, etc...

2 comments

> I can't believe the seeds haven't been chosen in a more sensible way, such as combining random seeds provided by different parties with competing interests, also including hardware RNGs, etc...

This is because you're looking at it from the perspective of someone living in 2023 with knowledge of what happened between the 90s and now. While that would have been a good way to go, at the time few people would have seen the need for it.

Well, with today's internet traffic mostly being encrypted, what would they need their large data centers such as Bluffdale for?

https://en.wikipedia.org/wiki/Utah_Data_Center