RSA Tells Its Developer Customers: Stop Using NSA-Linked Algorithm
Amidst all of the confusion and concern over an encryption algorithm that may contain an NSA backdoor, RSA Security released an advisory to developer customers today noting that the algorithm is the default algorithm …
Context & Ripple Effects
RSA Security's advisory lands after reporting that the NSA used court orders and behind-the-scenes pressure against major privacy-protecting encryption tools. That backdrop makes the security of vendor-supplied cryptographic defaults a procurement and engineering issue, not merely an implementation detail.
The story also follows disclosures of NSA access efforts spanning communications, mobile devices and payment data. RSA's instruction puts responsibility on its developer customers to move away from a default whose trust has been called into question.
First-order effects
- RSA developer customers must identify deployments using the affected default and replace it, adding migration and validation work to products that rely on RSA security software.
- RSA Security must support customers through that change while defending confidence in the cryptographic choices embedded in its products.
Second-order effects
- Organizations buying security software gain a concrete reason to audit cryptographic defaults and demand clearer documentation from vendors, raising the cost of opaque implementation choices.
- Competing security vendors can differentiate on transparent algorithm selection and safer defaults as RSA customers reassess the assumptions built into their existing deployments.
Third-order effects
- If disclosures of government pressure on encryption tools continue to erode confidence in vendor defaults, cryptographic implementation and algorithm provenance will become more central to enterprise security reviews.
- The episode points toward a security market in which trust depends not only on an algorithm's formal status but also on whether customers can independently evaluate how vendors deploy it.
The trend: Encryption vendors are being pushed to make cryptographic defaults more auditable as surveillance disclosures turn implementation choices into a trust and procurement issue.