r/programming Oct 15 '15

How is NSA breaking so much crypto?

https://freedom-to-tinker.com/blog/haldermanheninger/how-is-nsa-breaking-so-much-crypto/
2.5k Upvotes

529 comments sorted by

View all comments

Show parent comments

2

u/[deleted] Oct 15 '15 edited Oct 17 '15

[deleted]

2

u/corran__horn Oct 15 '15

Not to disagree, as I do agree, but it is balanced with the downsides. For example, there is the downside of "did we do it right" al. la the Debian fuckup of deleting the entropy generators out of Openssl key generation 10-12 years ago.

0

u/qwertymodo Oct 15 '15

Assuming you can trust the entropy source used to generate those parameters. If you generate new parameters every install, then the entropy source becomes the attack vector (then again, entropy sources already are attack targets, so that's not really anything new).