Live data from Hacker News

ISO Rejects NSA Encryption Algorithms

schneier.com

11–17 of 17 posts

Re: ISO Rejects NSA Encryption Algorithms

#11
post #4

Earlier quoted context omitted.

It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…

Why should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything,…

> Why should the NSA receive any more scrutiny than anyone else?

They’re a large, well-funded agency with documented efforts antagonistic to the goals of cryptography. There aren’t that many organisations fitting that bill and submitting designs. It makes sense to give them special attention. Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.

Re: ISO Rejects NSA Encryption Algorithms

#12

Earlier quoted context omitted.

Why should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything,…

> Why should the NSA receive any more scrutiny than anyone else? They’re a large, well-funded agency with documented efforts antagonistic to the goals of cryptography. There aren’t that many organisations fitting that bill and submitting designs. It makes sense to give them special attention. Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.

> Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.

That's exactly my point. You can immediately reject or even ban them from submitting anything but they will end run the process.

Rather than having a special procedure just for them, you're better off hold everyone to the same standard and assuming everyone is the NSA.

Re: ISO Rejects NSA Encryption Algorithms

#13
post #9

Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.

tptacek's comment lower down is interesting: > I've already stipulated the politics of the story, which are deeply boring to me. I'm not sure it's possible to be bored by "politics"-- i.e., to be bored by evidence from the Snowden leaks that the NSA is interested in pushing and has pushed kleptographic cryptography to undermine standards-- and be seriously engaged in a technical analysis. It's like saying you're only…

His point is that he wanted to discuss the technical details of the cipher design and not the political background story. He specifically said he agrees that it seems sensible ISO has not adopted this standard in light of NSA's subversive Dual EC DRBG deception, but that it also is very unlikely these ciphers contain or could contain a backdoor.

He's not at all arguing that ISO is in the wrong to decline accepting the algorithms or that the politics don't matter; just that they probably didn't backdoor these 2 particular algorithms. NSA has voided all of their goodwill, no doubt, but that's not what he was addressing.

I imagine the cryptographers working at NSA who are genuinely trying to design secure, non-backdoored algorithms are very unhappy at how badly their organization shot themselves in the foot.

Re: ISO Rejects NSA Encryption Algorithms

#14
post #4

Earlier quoted context omitted.

It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…

Why should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything,…

>Why should the NSA receive any more scrutiny than anyone else?

Because they were caught red-handed. They were effectively proven to have attempted to push a backdoored random number generator as a standard. They were the only ones who possessed the key to the backdoor.

They never suggested that the backdoor (or "key escrow" as they call it) was present in the algorithm. Even the Clipper chip [1], as bad as it was, wasn't this bad, since they were trying to be semi-transparent by saying "we possess the master key to this so we can help law enforcement investigate terrorism and other serious crimes".

Here, the scheme was executed entirely in secret.

If any private person or organization in the US tried to do something like this, they would be arrested and prosecuted under the CFAA (among other things). One could even make an argument that their DRBG backdoor is even more willfully malicious and toxic to our security than the warrantless mass surveillance.

If a conman tries to sell you some phony goods that he knows to be phony, you're never going to buy anything from him again, even if the later stuff seems legit.

[1] https://en.wikipedia.org/wiki/Clipper_chip

Re: ISO Rejects NSA Encryption Algorithms

#15
post #4

Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.

It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. Tha…

Kevin Igoe has been gone from the CFRG since mid-2015.

Re: ISO Rejects NSA Encryption Algorithms

#16

Earlier quoted context omitted.

Why should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything,…

>Why should the NSA receive any more scrutiny than anyone else? Because they were caught red-handed. They were effectively proven to have attempted to push a backdoored random number generator as a standard. They were the only ones who possessed the key to the backdoor. They never suggested that the backdoor (or "key escrow" as they call it) was present in the algorithm. Even the Clipper chip [1], as bad as it was, w…

What's stopping them, or anyone else, from trying this sort of thing again through an unidentified agent to circumvent the enhanced scrutiny that they would receive otherwise?

By making harder just for the NSA you achieve nothing but a false sense of security.

Instead the process needs to be more rigorous and scrutinized for everyone.

Post reply on HN