{"id":23157,"date":"2014-05-26T16:42:16","date_gmt":"2014-05-26T20:42:16","guid":{"rendered":"http:\/\/www.opensource.im\/?p=23157"},"modified":"2014-05-26T16:42:16","modified_gmt":"2014-05-26T20:42:16","slug":"congress-divorces-nist-and-nsa","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/congress-divorces-nist-and-nsa.php","title":{"rendered":"Congress divorces NIST and NSA"},"content":{"rendered":"<p><p>        Survival guide for data in the wild  <\/p>\n<p>    The US Congress has passed a bill that removes the NSA's direct    input into encryption standards.  <\/p>\n<p>    According to a     report at ProPublica, an amendment to the National    Institute of Standards and Technology act removes the    requirement that NIST consult with the NSA in setting new    encryption standards.  <\/p>\n<p>    Following the Snowden revelations, NIST had denied that it        deliberately weakened encryption standards at the behest of    the NSA.  <\/p>\n<p>    However, that didn't put to rest suspicions that weaknesses    such as existed in Dual_EC_DRBG were deliberate NSA    contrivances, with RSA singled out for criticism    over the random number generator.  <\/p>\n<p>    Earlier this year, NIST formalised its     advice that nobody should be using Dual_EC_DRBG.  <\/p>\n<p>    Concern over the NSA's involvement also led to an unsuccessful        campaign to exclude the agency from IETF crypto research,    and a successful     one to block RSA key swaps from the TLS standards.  <\/p>\n<p>    According to Slate, Congress has now     passed the amendment that was recommended by the House    Science and Technology Committee (Slate also complains    that the rest of the bill is mostly toothless).  <\/p>\n<p>    As Bruce Schneir pointed out last     week, users' one source of post-Snowden optimism is that    vast dollars haven't yet delivered a special sauce that lets    the NSA or its five-eyes partners crack well-implemented    encryption.  <\/p>\n<p>    Hence their continuing reliance either on social engineering,    or on various forms of keylogging, to get user data.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Continue reading here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2014\/05\/26\/congress_divorces_nist_from_nsa\" title=\"Congress divorces NIST and NSA\">Congress divorces NIST and NSA<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Survival guide for data in the wild The US Congress has passed a bill that removes the NSA's direct input into encryption standards. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-23157","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/23157"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=23157"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/23157\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=23157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=23157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=23157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}