Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

91–100 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#91
post #86

Earlier quoted context omitted.

"Other people have no choice but to trust NIST" is not a good argument for trusting NIST. Somehow I don't imagine the NSA is concerned about -- and is probably actively in favor of -- those organizations having backdoors.

It's an argument for fixing NIST so that it is trustworthy again.

This.

One wonders if NIST can be fixed or if it should simply be abolished with all archives opened in the interest of restoring faith in the government. The damage done by NSA and NIST is much larger than either of those organizations.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#93
post #48

Earlier quoted context omitted.

> I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known So we have that and other examples of NSA apparently strengthening crypto, then we have the dual-EC debacle and some of the info in the Snowden leaks showing that they've tried to weaken it. I feel like any talk about NSA influence on NIST PQ or other cu…

The NSA wants "NOBUS" (NObody-But-US) backdoors. It is in their interest to make a good show of fixing easily-detected vulnerabilities while keeping their own intentional ones a secret. The fantasy they are trying to sell to politicians is that people can keep secrets from other people but not from the government; that they can make uncrackable safes that still open when presented with a court warrant. This isn't spe…

Here's the counter-argument that I've seen in cryptography circles:

Dual EC, a PRNG built on an asymmetric crypto template, was kind of a ham fisted and obvious NOBUS back door. The math behind it made such a backdoor entirely plausible.

That's less obvious in other cases.

Take the NIST ECC curves. If they're backdoored it means the NSA knows something about ECC we don't know and haven't discovered in the 20+ years since those curves were developed. It also means the NSA was able to search all ECC curves to find vulnerable curves using 1990s technology. Multiple cryptographers have argued that if this is true we should really consider leaving ECC altogether. It means a significant proportion of ECC curves may be problematic. It means for all we know Curve25519 is a vulnerable curve given the fact that this hypothetical vulnerability is based on math we don't understand.

The same argument could apply to Speck:

https://en.wikipedia.org/wiki/Speck_(cipher)

Speck is incredibly simple with very few places a "mystery constant" or other back door could be hidden. If Speck is backdoored it means the NSA knows something about ARX constructions that we don't know, and we have no idea whether this mystery math also applies to ChaCha or Blake or any of the other popular ARX construction gaining so much usage right now. That means if we (hypothetically) knew for a fact that Speck was backdoored but not how it's backdoored it might make sense to move away from ARX ciphers entirely. It might mean many or all of them are not as secure as we think.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#94
side question :

I've only recently started to digg a bit deeper into crypto algorithms ( looking into various types of curves etc), and it gave me the uneasing feeling that the whole industry is relying on the expertise of only a handful of guys to actually ensure that crypto schemes used today are really working.

Am i wrong ? are there actually thousands and thousands of people with the expertise to actually proove that the algorithms used today are really safe ?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#95
post #40

Earlier quoted context omitted.

Many government or government affiliated organizations are required to comply with NIST approved algorithms by regulation or for interoperability. If NIST cannot be trusted as a reputable source it leaves those organizations in limbo. They are not equipped to roll their own crypto and even if they did, it would be a disaster.

"Roll your own crypto" typically refers to making your own algorithm or implementation of an algorithm not choosing the algorithm.

Would you really want every random corporation having some random person pick from the list of open source cipher packages? Which last I checked , still included things like 3DES, MD5, etc.

You might as well hand a drunk monkey a loaded sub machine gun.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#96
post #76
post #16

Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.

Another upvote from someone with many friends and colleagues in NIST. I hope transparency prevails and NISTers side with that urge as well (I suspect many do).

They could and should leak more documents if they have evidence of malfeasance.

There are both legal safe avenues via the IG process and legally risky many journalists who are willing to work for major change. Sadly legal doesn’t mean safe in modern America and some whistleblower have suffered massive retribution even when they play by “the rules” laid out in public law.

As Ellsberg said: Courage is contagious!

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#97

Earlier quoted context omitted.

Sure, EFF played a major role in that case as did Bernstein. It made several lawyers into superstars in legal circles and they all clearly acknowledge his contributions to the case. Still you imply that he shouldn’t have credit for that first win and that somehow he failed in the second case. EFF shouldn’t have stopped fighting for the users when the government changed the rules to something that was also unacceptabl…

The original poster said “he won a case against the government representing himself” and I felt that statement was incomplete, if not inaccurate and wanted to correct the record. I’m pretty sure Dan, if he was here, would do the same.

Sorry I didn’t know that part. I have only seen Professor Bernstein once (he had a post QC t shirt on so that’s the only way I knew who he was ). I have never interacted with him really. He is also the only faculty that is allowed to have a non UIC domain. Thank you for correcting me .

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#98

This definitely has the sting of bitterness in it, I doubt djb would have filed this suit if NTRU Prime would have won the PQC NIST contest. It's hard to evaluate this objectively when there are strong emotions involved.

It's funny how often the bitterness of a post is used as an excuse to dismiss the long and well documented case being made.

If NTRU Prime had been declared the winner, would this suit have been filed? It's the same contest, same people, same suspicious behavior from NIST. I don't think this suit would have come up. djb is filing this suit because of alleged bad behavior, but I have doubts that it's the real reason.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#99
post #35

This definitely has the sting of bitterness in it, I doubt djb would have filed this suit if NTRU Prime would have won the PQC NIST contest. It's hard to evaluate this objectively when there are strong emotions involved.

When it comes to the number of times DJB is right versus the number of times that DBJ is wrong, I'll fully back DJB. Simply put the NSA/NIST cannot and should not be trusted in this case.

You misread. I'm saying his reasons for filing are in question. NIST probably was being dishonest. That's not the reason there is a lawsuit though.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#100

Earlier quoted context omitted.

Sure, EFF played a major role in that case as did Bernstein. It made several lawyers into superstars in legal circles and they all clearly acknowledge his contributions to the case. Still you imply that he shouldn’t have credit for that first win and that somehow he failed in the second case. EFF shouldn’t have stopped fighting for the users when the government changed the rules to something that was also unacceptabl…

The original poster said “he won a case against the government representing himself” and I felt that statement was incomplete, if not inaccurate and wanted to correct the record. I’m pretty sure Dan, if he was here, would do the same.

You appear to be throwing shade on his contributions. Do I misunderstand you?

A stalemate, if you already want to diminish his efforts, isn’t a loss by definition - the classic example is in chess. He brought the government to heel even after EFF bailed. You’re also minimizing his contributions to the first case.

His web page clearly credits the right people at the EFF, and he holds back on criticism for their lack of continuing on the case.

I won’t presume to speak for Dan.

Post reply on HN