SAN FRANCISCO - Internet security experts are calling for a campaign to rewrite Web security in the wake of disclosures that the US National Security Agency has developed the capability to break encryption protecting millions of sites.
But they acknowledged the task won't be easy, in part because internet security has relied heavily on brilliant government scientists who now appear suspect to many.
Leading technologists said they felt betrayed that the NSA, which has contributed to some important security standards, was trying to ensure they stayed weak enough that the agency could break them. Some said they were stunned that the government would value its monitoring ability so much that it was willing to reduce everyone's security.
"We had the assumption that they could use their capacity to make weak standards, but that would make everyone in the US insecure," said Johns Hopkins cryptography professor Matthew Green. "We thought they would never be crazy enough to shoot out the ground they were standing on, and now we're not so sure."
The head of the volunteer group in charge of the Internet's fundamental technology rules told Reuters on Saturday that the panel will intensify its work to add encryption to basic Web traffic and to strengthen the so-called secure sockets layer, which guards banking, email and other pages beginning with Https.
"This is one instance of the dangers that we face in the networked age," said Jari Arkko, an Ericsson scientist who chairs the Internet Engineering Task Force. "We have to respond to the new threats."
Other experts likewise responded sharply to media reports based on documents from former NSA contractor Edward Snowden showing the NSA has manipulated standards.