So, question then, isn't one of the differences between this time's selection, compared to previous selections, that some of the algorithms are open source with their code available. For example, Kyber, one of the finalists, is here: https://github.com/pq-crystals/kyber And where it's not open source, I believe in the first round submissions, everyone included reference implementations. Does the code being available…
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
31–40 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#32Matt Topic is probably best known as the FOIA attorney who got the Laquan McDonald videos released in Chicago; I've been peripherally involved in some work he and Merrick Wayne did for a friend, in a pretty technical case that got fierce resistance from CPD, and those two were on point. Whatever else you'd say about Bernstein here, he knows how to pick a FOIA lawyer.
A maybe more useful way to say the same thing is: if Matt Topic and Merrick Wayne are filing this complaint, you should probably put your money on them having NIST dead-to-rights with the FOIA process stuff.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#33Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#34Earlier quoted context omitted.
Given his track record, and the actual meat of this suit, I think he has a good chance. - He is an expert in the domain - He made a lawful request - He believes he's experiencing an obstruction of his rights I don't see anything egregious here. Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Suing sounds offensive, but th…
I'd add * and it's been 20 yrs since the 9/11 attacks which predicated a lot of the more recent dragnets
Which have not prevented anything and instead are used in parallel construction to go after Americans
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#35This definitely has the sting of bitterness in it, I doubt djb would have filed this suit if NTRU Prime would have won the PQC NIST contest. It's hard to evaluate this objectively when there are strong emotions involved.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#36Earlier quoted context omitted.
The encryption is fine, that's just a way to avoid it. Much like how tire-iron attacks don't break passwords so much as bypass them.
Ok that's actually a great point. To make the comparison: Tire-irons require physical proximity. And torture generally doesn't work, at least in the case of getting a private key. Reading/writing to the brain, on the other hand, requires no physical proximity if wireless. And the person(s) won't even know it's happening. These seem like totally different paradigms to me.
Why not?
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#37So, question then, isn't one of the differences between this time's selection, compared to previous selections, that some of the algorithms are open source with their code available. For example, Kyber, one of the finalists, is here: https://github.com/pq-crystals/kyber And where it's not open source, I believe in the first round submissions, everyone included reference implementations. Does the code being available…
A lot of the instances in the post even show the NSA giving a why. It's not a particular convincing why, but it was enough to sow doubt. The reason to make all discussions public is so that there isn't an after the fact "wait, why is that obviously odd choice being done?" but instead a before the fact "I think we should make a change". The burden of evidence is different for that. A "I think we should reduce the key length for performance" is a much harder sell when the spec already prescribes a longer key length, than an after the fact "the spec's key length seems too short" "Nah, it's good enough, and we need it that way for performance". The status quo always has inertia.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#38Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.
Indeed. Have my upvote stranger. The related “just ignore NIST” crowd is intentionally or unintentionally dismissing serious issues of governance. Anyone who deploys this argument is questionable in my mind, essentially bad faith actors, especially when the topic is about the problems brought to the table by NIST and NSA. It is a good sign that those people are actively ignoring the areas where you have no choice and…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#39Good god, this guy is a bad communicator. Bottom line up front: > NIST has produced zero records in response to this [March 2022] FOIA request [to determine whether/how NSA may have influenced NIST's Post-Quantum Cryptography Standardization Project]. Civil-rights firm Loevy & Loevy has now filed suit on my behalf in federal court, the United States District Court for the District of Columbia, to force NIST to comply…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#40Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.