Live data from Hacker News

Encrypting and authenticating the whole Internet: DJB (video)

27c3.iphoneblog.de

11–20 of 23 posts

Re: Encrypting and authenticating the whole Internet: DJB (video)

#11
post #3

This is a great talk; Bernstein is a surprisingly excellent public speaker with solid timing. You can get most of the points he raises from the foils of previous talks on his website, but, the high points: * DNSSEC offers DDoS attackers 30+ : 1 amplification for attack traffic; at reasonably low deployment levels, it allows a 200> node botnet to saturate most websites on the Internet. It does this while not actually…

> Your conception of the speed of public-key crypto is warped by how slow SSL is; 256 bit elliptic curve crypto, which hasn't degraded in security for almost 25 years, is so fast that you can rekey 10 million sessions every 10 minutes on standard PC hardware. This argument implies ECC and SSL are mutually exclusive when they aren't. ECC has been a standardized part of SSL for years and there are many shipping impleme…

NIST reviews! Official IANA identifiers for TLS! A prove-the-negative patent resolution! And, it'd sure be nice if the NSA came out and endorsed the solution!

Yeah, this is definitely an apples to apples standard compared to what DNSSEC dealt with.

I am, for the record, (a) a proponent of x509 and (in particular) TLS, (b) not a particular fan of "nym security", (c) not optimistic about any ground-up replacement of TCP. It's weird that you're arguing with me about this stuff.

But he's straight-up right about DNS security.

Re: Encrypting and authenticating the whole Internet: DJB (video)

#14
post #11

Earlier quoted context omitted.

> Your conception of the speed of public-key crypto is warped by how slow SSL is; 256 bit elliptic curve crypto, which hasn't degraded in security for almost 25 years, is so fast that you can rekey 10 million sessions every 10 minutes on standard PC hardware. This argument implies ECC and SSL are mutually exclusive when they aren't. ECC has been a standardized part of SSL for years and there are many shipping impleme…

NIST reviews! Official IANA identifiers for TLS! A prove-the-negative patent resolution! And, it'd sure be nice if the NSA came out and endorsed the solution! Yeah, this is definitely an apples to apples standard compared to what DNSSEC dealt with. I am, for the record, (a) a proponent of x509 and (in particular) TLS, (b) not a particular fan of "nym security", (c) not optimistic about any ground-up replacement of TC…

I'm not arguing with you (aren't you just summarizing somebody else's viewpoint?). I think it's important to see the non-technical factors that may cause a new scheme to lose out to even technically-inferior alternatives. How much value is there in a NIST or NSA rubber stamp? Well, so far MS and Mozilla have only implemented Suite B curves. How hurtful is the ECC patent FUD? Well, look at how much work Red Hat did to strip all ECC code from all the software they ship in their products. How likely is it that there will be a standard that takes off without being distributed by either Microsoft or Red Hat (or Oracle or CentOS)? What would it take to get Curve25519 used in Firefox? Well, there's not much reward for implementing a curve that isn't going to be implemented by many other browsers or servers, so it's hard to justify spending time to consider it, even ignoring the NIST/NSA/IETF/IANA angle.

Re: Encrypting and authenticating the whole Internet: DJB (video)

#15
post #11

Earlier quoted context omitted.

NIST reviews! Official IANA identifiers for TLS! A prove-the-negative patent resolution! And, it'd sure be nice if the NSA came out and endorsed the solution! Yeah, this is definitely an apples to apples standard compared to what DNSSEC dealt with. I am, for the record, (a) a proponent of x509 and (in particular) TLS, (b) not a particular fan of "nym security", (c) not optimistic about any ground-up replacement of TC…

I'm not arguing with you (aren't you just summarizing somebody else's viewpoint?). I think it's important to see the non-technical factors that may cause a new scheme to lose out to even technically-inferior alternatives. How much value is there in a NIST or NSA rubber stamp? Well, so far MS and Mozilla have only implemented Suite B curves. How hurtful is the ECC patent FUD? Well, look at how much work Red Hat did to…

I think there's zero chance any of this stuff ever gets deployed, for whatever that's worth. I think that, and that Bernstein is probably right.

Re: Encrypting and authenticating the whole Internet: DJB (video)

#16
post #3

This is a great talk; Bernstein is a surprisingly excellent public speaker with solid timing. You can get most of the points he raises from the foils of previous talks on his website, but, the high points: * DNSSEC offers DDoS attackers 30+ : 1 amplification for attack traffic; at reasonably low deployment levels, it allows a 200> node botnet to saturate most websites on the Internet. It does this while not actually…

> This is a great talk; Bernstein is a surprisingly excellent public speaker with solid timing.

If you haven't seen him speak before, you might enjoy these old MSRI videos:

Fast Multiplication - http://angelina.msri.org/IA/TalkDetail?field_tid=11002

Protecting Communications Against Forgery - http://angelina.msri.org/IA/TalkDetail?field_tid=11479

Not as dynamic as his CCC talk, but educational.

Re: Encrypting and authenticating the whole Internet: DJB (video)

#17
post #11

Earlier quoted context omitted.

> Your conception of the speed of public-key crypto is warped by how slow SSL is; 256 bit elliptic curve crypto, which hasn't degraded in security for almost 25 years, is so fast that you can rekey 10 million sessions every 10 minutes on standard PC hardware. This argument implies ECC and SSL are mutually exclusive when they aren't. ECC has been a standardized part of SSL for years and there are many shipping impleme…

NIST reviews! Official IANA identifiers for TLS! A prove-the-negative patent resolution! And, it'd sure be nice if the NSA came out and endorsed the solution! Yeah, this is definitely an apples to apples standard compared to what DNSSEC dealt with. I am, for the record, (a) a proponent of x509 and (in particular) TLS, (b) not a particular fan of "nym security", (c) not optimistic about any ground-up replacement of TC…

Just curious: what troubles you about nym security?
Post reply on HN