Hacker News new | ask | show | jobs
by codeflo 4563 days ago
I have admire the careful wording: "We also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA's products, or introducing potential 'backdoors' into our products for anyone's use."

This leaves the door open for a lot of things, including them having weakened their products and added backdoors. They just deny having entered a contract with the intention of doing so.

Though one has to wonder how exactly that deal went down. You wouldn't have to pay RSA anything to implement a good crypto algorithm because they'd do that out of pure business interest. Did the NSA call and ask "Here's a new RNG algorithm, it's slower than others and mathematically dubious. Would you implement it for $10 million?"

2 comments

Most probably they said something like "many of your government agency customers would be very happy if / will require that you implemented this PRNG".
My guess would be the RSA wanted more government contracts and the NSA said they would have to implement the government preferred algo as the default. The NSA will also pay you for these efforts. RSA would see that is win-win. They are getting paid to implement the gov standard AND it will help them win contracts in the future. Only a fool would say no to that.