So, as we all know, Dual_EC_DRBG contains an NSA back door. At this point, there is no reason to call it a "potential" or even an "alleged" back door; the presence is obvious even to the NY Times. As we also know, RSA BSAFE has been using Dual_EC_DRBG by default, with a justification so stupid it can only be translated as "because NSA paid us to". And like Dual_EC_DRBG, it provides no documentation for how or why this number was chosen. Now as Vitalik pointed out, even if the NSA knew of a specific elliptic curve with vulnerabilities, it still should have been near impossible for them rig the system due to the fact that brute-forcing a hash function is not feasible. 0x04 32 bytes X coordinate 32 bytes Y coordinate. Is there a way we can get the original point value on the Elliptic curve of R? I did convert the 32 bytes into integer and I believe the curve point is generated using the order of the base point, now can we remove the order of the base point and look at only the value Dual_EC_DRBG uses an initial seed that is 2 * security_strength bits in length to initia the generation of outlen-bit pseudorandom strings by performing scalar multiplications two points in an elliptic curve group, where the curve is defined over a field approxima 2m in size. For all the NIST curves given in this Recommendation, m is at least twice th security_strength, and never less than 256 ... Stack Exchange Network. Stack Exchange network consists of 176 Q&A communities including Stack Overflow, the largest, most trusted online community for developers to learn, share their knowledge, and build their careers. Visit Stack Exchange. Loading… 0 +0; Tour Start here for a quick overview of the site Help Center Detailed answers to any questions you might have Meta Discuss the workings ...

