Security researcher cancels talk at RSA conference in protest

Mikko Hypponen, chief research officer of F-Secure, said he was protesting reports of a secret RSA-NSA deal

Security researcher Mikko Hypponen has canceled his talk at a RSA security conference in San Francisco, reacting to a report that the security division of EMC allegedly received US$10 million from the U.S. National Security Agency to use a flawed random number generator in one of its products.

In an open letter on Monday to Joseph M. Tucci, chairman and CEO of EMC, and(Art Coviello, executive chairman of RSA, Hypponen, who is chief research officer at Finnish security company F-Secure, referred to a report by Reuters which stated that RSA accepted a random number generator from the NSA, and set it as the default option in its product BSafe, in return for the payment from the NSA.

The RSA took money "secretly" from the NSA to embed the Dual EC DRBG (Dual Elliptic Curve Deterministic Random Bit Generator) technology into its BSafe toolkit, according to the report on Friday.

The number generator used in a 2006 standard of federal agency National Institute of Standards and Technology came under scrutiny after former NSA contractor Edward Snowden suggested it provided back-door entry to NSA snooping, according to reports.

RSA has denied entering into a secret contract with the NSA. "We made the decision to use Dual EC DRBG as the default in BSAFE toolkits in 2004, in the context of an industry-wide effort to develop newer, stronger methods of encryption. At that time, the NSA had a trusted role in the community-wide effort to strengthen, not weaken, encryption," it said in a statement Sunday.

Hypponen said RSA had not denied receiving $10 million from the NSA to use the random number generator. "You had kept on using the generator for years despite widespread speculation that NSA had backdoored it," he wrote.

The researcher said he didn't expect EMC or the conference to suffer as a result of the alleged deals with the NSA. Nor did he expect other conference speakers to cancel. Most of the speakers at the conference are American so why would they care about surveillance that's not targeted at them but at non-Americans, Hypponen wrote. Surveillance operations by U.S. intelligence agencies are targeted at foreigners, he added.

"However I'm a foreigner. And I'm withdrawing my support from your event," the Finnish researcher wrote. He had earlier tweeted that "If the Reuters story is true, I - for one - will be cancelling my invited talk and my panel participation in the upcoming RSA Conference."

The RSA conference runs from Feb 24 to 28. Among the keynote speakers and other speakers, listed on the website for the conference, are executives from Microsoft, Juniper Networks, Cisco, McAfee, Symantec and Hewlett-Packard. Hypponen was to speak on "Governments as Malware Authors" at the conference. The researcher said he had spoken eight times at RSA conferences in the U.S., Europe and Japan. "You've even featured my picture on the walls of your conference walls among the 'industry experts,'" he wrote in the letter.

EMC could not be immediately reached for comment on Hypponen's decision.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags National Security Agencysecuritygovernmentemcrsa

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John Ribeiro

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?