Live data from Hacker News

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

nist.gov

41–50 of 60 posts

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#41
post #39

Earlier quoted context omitted.

> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again. Sorry if you think I'm trying to convince people of anything. I'm simply asking fo…

You said "NIST worked together with NSA to allow/insert backdoors into cryptography". It's been pointed out a couple times now that neither NIST nor NSA designed these schemes; they were submitted by the highest-profile academic cryptography research teams in the world. You aren't being asked to trust NIST in any meaningful way. The closest analog to NIST I can think of is ECRYPT and the eSTREAM contest. It produced…

> You aren't being asked to trust NIST in any meaningful way

I understand that neither NIST nor NSA have designed these schemes, but isn't NIST the organization who picked these winning schemes after all? That's the impression I got, and my history of trusting what NIST picks, isn't the greatest, so I'd like to avoid that. I also understand that countless of people have reviewed the schemes as well, people from all around the world with different types of experience. It's still hard to shake off something that essentially boils down to a feeling: "trust".

Thank you for providing some alternatives in your final paragraph, for the uneducated plebs like myself.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#42
post #32

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back.

In advance of what ? Not intended as a gotcha I'm genuinely interested.

I see past NIST competitions as a mixed bag in terms of whether what we got is important (e.g. AES) or not so much (e.g. SHA-3) but I don't see any cases where they made things worse. And the NIST competitions attract some attention whereas something more discrete like the CFRG PAKE selection process can be so quiet if you're not intimately involved you might not know the CFRG actually selected anything. If you build a new product with Serpent or Twofish inside it, that will attract questions about why not AES - does this happen if your product has SPAKE2?

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#43

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

Other nation states and capitalist big corp are the only other groups with the resources to produce such things.

Good luck there.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#44
post #32

Earlier quoted context omitted.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. In advance of what ? Not intended as a gotcha I'm genuinely interested. I see past NIST competitions as a mixed bag in terms of whether what we got is important (e.g. AES) or not so much (e.g. SHA-3) but I don't see any cases where they made things worse.…

It's not so much that NIST has chosen bad ciphers in their competitions, so much as that they've created institutional pressure against other totally reasonable constructions, which in turn make it harder for things like WireGuard to get adopted inside the USG. The ciphers are much less important than the protocols that use them.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#45
post #39

Earlier quoted context omitted.

You said "NIST worked together with NSA to allow/insert backdoors into cryptography". It's been pointed out a couple times now that neither NIST nor NSA designed these schemes; they were submitted by the highest-profile academic cryptography research teams in the world. You aren't being asked to trust NIST in any meaningful way. The closest analog to NIST I can think of is ECRYPT and the eSTREAM contest. It produced…

> You aren't being asked to trust NIST in any meaningful way I understand that neither NIST nor NSA have designed these schemes, but isn't NIST the organization who picked these winning schemes after all? That's the impression I got, and my history of trusting what NIST picks, isn't the greatest, so I'd like to avoid that. I also understand that countless of people have reviewed the schemes as well, people from all a…

About the worst thing you could say about the NIST competitions is that if NSA knows some horrible flaw in CRYSTAL-KYBER, they're not going to tell us about it. But that's true of any other contest anybody else runs, too.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#46
post #45

Earlier quoted context omitted.

> You aren't being asked to trust NIST in any meaningful way I understand that neither NIST nor NSA have designed these schemes, but isn't NIST the organization who picked these winning schemes after all? That's the impression I got, and my history of trusting what NIST picks, isn't the greatest, so I'd like to avoid that. I also understand that countless of people have reviewed the schemes as well, people from all a…

About the worst thing you could say about the NIST competitions is that if NSA knows some horrible flaw in CRYSTAL-KYBER, they're not going to tell us about it. But that's true of any other contest anybody else runs, too.

[deleted]

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#47

Earlier quoted context omitted.

No. Public key cryptography is impossible if P=NP. What we are left with is shared one-time-pads that can be arranged using quantum key distribution. I am not an expert so I will simply link the Wikipedia article on Computational Complexity Theory as my "source". https://en.m.wikipedia.org/wiki/Computational_complexity_the...

If there is an n^(100^100) algorithm that solves an NP-complete problem, then P=NP, but public-key cryptography is still safe because for any practical n it's still too hard to break. There are also public-key systems that are based on NP-complete problems that are easily broken, because n is chosen too small.

Thank you for schooling me on this. I wasn't considering n^(100^100) problems.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#48
post #32

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

BULLRUN was done to NIST, not by them.

It’s think it’s also an example of why NIST is so important. The subversion of the standard is a problem, but the real exploit using that subversion was the laziness and lack of skill that downstream practitioners demonstrated. People clicked next and installed that RSA BSAFE package without any configuration or reading of the manual.

Without NIST, you’d have Crypto AG — much worse. With NIST, you may have trust concerns, but ultimately the US government is protecting much of its own data as well as politically/economically critical data with NIST algorithms (aka FIPS 140-2).

Ultimately, I think the model in place with these competitions is probably the “best worst” option.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#49

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

You're not expected to trust NIST. They write standards documents. It's up to cryptography researchers to formally verify and reason about the standards and for cryptosystem implementers to choose carefully based on available research.

Any trust you're going to put into an algorithm is going to have to come from downstream of NIST.

Post reply on HN