Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

71–80 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#72
post #48

Earlier quoted context omitted.

I remember reading about this in Steven Levy's crypto and elsewhere, there was a lot of internal arguing about lots of this stuff at the time and people had different opinions. I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known (though at the the time people suspected they were suggesting this because it w…

> I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known So we have that and other examples of NSA apparently strengthening crypto, then we have the dual-EC debacle and some of the info in the Snowden leaks showing that they've tried to weaken it. I feel like any talk about NSA influence on NIST PQ or other cu…

The NSA wants "NOBUS" (NObody-But-US) backdoors. It is in their interest to make a good show of fixing easily-detected vulnerabilities while keeping their own intentional ones a secret. The fantasy they are trying to sell to politicians is that people can keep secrets from other people but not from the government; that they can make uncrackable safes that still open when presented with a court warrant.

This isn't speculation either; Dual_EC_DRBG and its role as a NOBUS backdoor was part of the Snowden document dump.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#73
Perhaps the old advice (“never roll your own crypto”) should be reevaluated? If you’re creative enough, you could combine and apply existing algorithms in such ways that it would be very difficult to decrypt? Think 500 programmatic combinations (steps) of encryption applying different algorithms. Content encrypted in this way would require knowledge of the encryption sequence in order to execute the required steps in reverse. No amount of brute force could help here…

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#74
post #40
post #16

Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.

Many government or government affiliated organizations are required to comply with NIST approved algorithms by regulation or for interoperability. If NIST cannot be trusted as a reputable source it leaves those organizations in limbo. They are not equipped to roll their own crypto and even if they did, it would be a disaster.

"Roll your own crypto" typically refers to making your own algorithm or implementation of an algorithm not choosing the algorithm.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#76
post #16

Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.

Another upvote from someone with many friends and colleagues in NIST. I hope transparency prevails and NISTers side with that urge as well (I suspect many do).

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#78

Earlier quoted context omitted.

I remember reading about this in Steven Levy's crypto and elsewhere, there was a lot of internal arguing about lots of this stuff at the time and people had different opinions. I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known (though at the the time people suspected they were suggesting this because it w…

You are not accurately reflecting the history that is presented in the very blog post we are discussing. NSA made DES weaker for everyone by reducing the key size. IBM happily went along. The history of IBM is dark. NSA credited tweaks to DES can be understood as ensuring that a weakened DES stayed deployed longer which was to their advantage. They clearly explain this in the history quoted by the author: “Narrowing…

>IBM happily went along. The history of IBM is dark.

Then, as of now, I'm confused why people expect these kinds of problems to be solved by corporations "doing the right thing" rather than demanding some kind of real legislative reform.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#79
post #60

So, question then, isn't one of the differences between this time's selection, compared to previous selections, that some of the algorithms are open source with their code available. For example, Kyber, one of the finalists, is here: https://github.com/pq-crystals/kyber And where it's not open source, I believe in the first round submissions, everyone included reference implementations. Does the code being available…

Worth noting DJB (the article author) was on two competing (losing) teams to Kyber[0] in Round 3. And has an open submission in round 4 (still in progress). That's going to slightly complicate any FOIA until after the fact, or it should. Not that there's no merit in the request. [0]: https://csrc.nist.gov/Projects/post-quantum-cryptography/pos...

It is wrong to imply he is unreasonable here. NIST has been dismissive and unprofessional towards him and others in this process. They look terrible because they’re not doing their jobs.

Several of his student’s proposals won the most recent round. He still has work in the next round. NIST should have answered in a timely manner.

On what basis do you think any of these matters can or may complicate the FOIA process?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#80

Earlier quoted context omitted.

Ok that's actually a great point. To make the comparison: Tire-irons require physical proximity. And torture generally doesn't work, at least in the case of getting a private key. Reading/writing to the brain, on the other hand, requires no physical proximity if wireless. And the person(s) won't even know it's happening. These seem like totally different paradigms to me.

> torture generally doesn't work, at least in the case of getting a private key. Why not?

[deleted]
Post reply on HN