funsec mailing list archives

Re: More stuff to worry about random number generators:


From: "Paul Ferguson" <fergdawg () netzero net>
Date: Tue, 18 Dec 2007 01:32:24 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -- "Dude VanWinkle" <dudevanwinkle () gmail com> wrote:

via bruce:
http://www.schneier.com/blog/archives/2007/12/dual_ec_drbg_ad.html  

Dual_EC_DRBG Added to Windows Vista

Microsoft has added the random-number generator Dual_EC-DRBG to
Windows Vista, as part of SP1. Yes, this is the same RNG that could
have an NSA backdoor.

It's not enabled by default, and my advice is to never enable it. Ever.


Windows Vista? What's that? ;-)

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)

wj8DBQFHZyMlq1pz9mNUZTMRAh77AJkBXgwSUJ2ksAW4wImXwFQS75foOACeI9tl
tADDiVXEEEoNiE0YitnyYK0=
=0Dec
-----END PGP SIGNATURE-----

--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: