CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars and star trek FYI to those who didn't know.
Kyber is a fictional thing, so I understand that it's a Star Wars reference. But Dilithium is a real thing, so not sure why that would be a Star Trek reference? Couldn't it just be a reference to the real thing somehow?
NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
11–20 of 60 posts
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#12Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
The conclusion is no, there is no alternative right now.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#13Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
Not especially if you're in the US and want to work with government systems or be a sub-contractor to a company that does. Otherwise pick an algorithm and have at it:
> That NIST worked together with NSA […]
Did they? Or did the NSA lie to NIST?
* https://www.schneier.com/blog/archives/2022/06/on-the-subver...
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#14Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out?
So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#15Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
I can't imagine with the added scrutiny the internet has gotten since then, especially from foreign governments, that NIST will be able to get away with anything like that again. But then again I may be completely ignorant as to the scope of NSA meddling.
You say this like NIST was an accomplice (and not also a victim).
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#16Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to.
However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public competition. They basically asked everyone to submit proposals and then asked everyone to find flaws in theses proposals.
These competitions have a very good reputation in the cryptographic community. An algorithm like Dual EC where the issues were quite obvious would've never survived such a process.
The thing you should look at is the process, not the organization.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#17Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent an algorithm which stands up to scrutiny, but which has some extremely hard to notice flaw which only they know about. They could then make those cryptographers submit the algorithm to NIST, and, in a seemingly fair way, pick the subtly broken algorithm as the winner. I can't know whether this happened of course, and it probably didn't, but we fundamentally have to trust that NIST wouldn't do something like that... and we do know that they would do, and indeed have done, something like that.
Maybe the process is such that this attack, and any other kind of attack, is impossible. If that's the case, please do cite something which goes into detail on that.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#18Earlier quoted context omitted.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#19CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars and star trek FYI to those who didn't know.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#20Earlier quoted context omitted.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…