Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I assumed it was that and that case is puzzling but benign as the algorithm is much too slow to be chosen compared to the alternatives[1]. As far as anyone can tell this wasn't their best work:

If this story leaves you confused, join the club. I don't understand why the NSA was so insistent about including Dual_EC_DRBG in the standard. It makes no sense as a trap door: It's public, and rather obvious. It makes no sense from an engineering perspective: It's too slow for anyone to willingly use it. And it makes no sense from a backwards-compatibility perspective: Swapping one random-number generator for another is easy.

[1] http://www.schneier.com/essay-198.html



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: