CITP Seminar: Leaving Randomness to Chance: Standards Shortcomings and Buried Backdoors in Random Number Generators

Shaanan Cohney photo
Date & Time Sep 29 2020 12:30 PM - 1:30 PM
Speaker(s)
Shaanan Cohney, Postdoctoral Research Associate
Audience Open to the Public

Please join the webinar here.

Security is too important to leave to chance.  Security by design is often touted as the solution, but when your system is broken before you design it—something has gone very, very wrong.

Secure random number generators are a critical part of most deployed cryptosystems. When they fail, so does the cryptography.

Over the past two decades, researchers have discovered vulnerabilities in many of the most commonly deployed algorithms that generate these random numbers. In more than one instance, researchers discovered flaws in proposed algorithms before it was too late. Yet, these algorithms still went on to become U.S. government standards and were broadly deployed.

This talk draws on Shaanan’s work discovering fatal flaws in real systems to find that behind each one is the hint of a new type of adversary, an adversary who threads flaws into our standards.