Volume 13, Issue 2
Dueling over Dual_EC_DRGB: The Consequences of Corrupting a Cryptographic Standardization Process By Nadiya Kostyuk and Susan Landau In recent decades, the U.S. National Institute of Standards and Technology (NIST), which develops cryptographic standards for non-national security agencies of the U.S. government, has emerged as the de facto international source for cryptographic standards. But in 2013, Edward Snowden disclosed that the National Security Agency had subverted the integrity of a NIST cryptographic standard—the Dual_EC_DRBG—enabling easy decryption of supposedly secured communications. This discovery reinforced the desire of some public and private entities to develop their own cryptographic standards instead of relying on […]