ISO Rejects NSA Encryption Algorithms
schneier.com
ISO Rejects NSA Encryption Algorithms
1–10 of 17 posts
Re: ISO Rejects NSA Encryption Algorithms
#2I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
Re: ISO Rejects NSA Encryption Algorithms
#3Re: ISO Rejects NSA Encryption Algorithms
#4Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore.
That should be the consequence not just for "getting caught" trying to put a backdoor inside a crypto algorithm, but for constantly pushing legislators to increase their surveillance powers and pass anti-encryption laws.
The NSA has made it clear in many more occasions than in the Dual_EC situation that they are the enemy of crypto, not its friend. I think that's more than enough reason to distrust all NSA projects by default.
Re: ISO Rejects NSA Encryption Algorithms
#5Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
Politically, I'm inclined to agree. But the technical merits should be commented on as well. That's what Thomas's comment did.
> Speaking of which, is the NSA guy still running the crypto review group at the IETF?
Which is "the NSA guy" and how is he running the show?
> If so, how is that still a thing?!
For the same reason that the guy peddling the Crystalline cipher is still allowed to participate with the IETF.
There's really no lock-out.
> The NSA has made it clear in many more occasions than in the Dual_EC situation that they are the enemy of crypto, not its friend. I think that's more than enough reason to distrust all NSA projects by default.
That sounds good on paper, but you're not advocating "distrust ... by default" in every part of your comment before this snippet. Your words are coming a cross as more on the "distrust ... forever" side. And I'm left wondering which of the two you actually want.
Re: ISO Rejects NSA Encryption Algorithms
#6Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
There is no good that can come from knee-jerk reactions.
Re: ISO Rejects NSA Encryption Algorithms
#7Earlier quoted context omitted.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
I disagree with this stance. Technical decisions should be made on technical merit, not because a person or institution has a shady background. The algorithms in questions have been under a lot of analysis precisely because the NSA designed them. Yet we rely on AES and SHA every day. There is no good that can come from knee-jerk reactions.
Re: ISO Rejects NSA Encryption Algorithms
#8Earlier quoted context omitted.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
I disagree with this stance. Technical decisions should be made on technical merit, not because a person or institution has a shady background. The algorithms in questions have been under a lot of analysis precisely because the NSA designed them. Yet we rely on AES and SHA every day. There is no good that can come from knee-jerk reactions.
Re: ISO Rejects NSA Encryption Algorithms
#9Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
> I've already stipulated the politics of the story, which are deeply boring to me.
I'm not sure it's possible to be bored by "politics"-- i.e., to be bored by evidence from the Snowden leaks that the NSA is interested in pushing and has pushed kleptographic cryptography to undermine standards-- and be seriously engaged in a technical analysis.
It's like saying you're only interested in the code of the winning entry of the Underhanded C Contest, but not at all interested in the rules of the challenge. If someone's analysis under those circumstances is that the code looks like it does a fine job of completing its task, one should be skeptical.
Re: ISO Rejects NSA Encryption Algorithms
#10Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…
The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves.
So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything, and to also prevent others from doing the same.
The same is probably true of every other intelligence agency.
If we start rejecting their contributions by default then they'll just start looking for other ways to exploit the process if they haven't already.
What's to stop them from bribing or extorting independent researchers?
Perhaps there needs to just be a paranoid level of scrutiny over anyone and everything? When securing software you assume every request is threatening, why not when evaluating it?