NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
101–110 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#102Earlier quoted context omitted.
The encryption is fine, that's just a way to avoid it. Much like how tire-iron attacks don't break passwords so much as bypass them.
Ok that's actually a great point. To make the comparison: Tire-irons require physical proximity. And torture generally doesn't work, at least in the case of getting a private key. Reading/writing to the brain, on the other hand, requires no physical proximity if wireless. And the person(s) won't even know it's happening. These seem like totally different paradigms to me.
This seems incorrect.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#103The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist. The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs. O…
Given his track record, and the actual meat of this suit, I think he has a good chance. - He is an expert in the domain - He made a lawful request - He believes he's experiencing an obstruction of his rights I don't see anything egregious here. Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Suing sounds offensive, but th…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#104side question : I've only recently started to digg a bit deeper into crypto algorithms ( looking into various types of curves etc), and it gave me the uneasing feeling that the whole industry is relying on the expertise of only a handful of guys to actually ensure that crypto schemes used today are really working. Am i wrong ? are there actually thousands and thousands of people with the expertise to actually proove…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#105Earlier quoted context omitted.
Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.
Every piece of mail that passes through a high-speed sorting machine is scanned, front and back, OCR'd, and stored - as far as we know, indefinitely. That's how they deliver the "what's coming in your mailbox" images you can sign up to receive via email. Those images very often show the contents of the envelope clearly enough to recognize and even read the contents, which I'm quite positive isn't an accident. The USP…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#106Earlier quoted context omitted.
When it comes to the number of times DJB is right versus the number of times that DBJ is wrong, I'll fully back DJB. Simply put the NSA/NIST cannot and should not be trusted in this case.
You misread. I'm saying his reasons for filing are in question. NIST probably was being dishonest. That's not the reason there is a lawsuit though.
The lawsuit is because they refused to answer his reasonable and important FOIA in a timely manner. This is not unlike how they also delayed the round three announcement.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#107Earlier quoted context omitted.
Given his track record, and the actual meat of this suit, I think he has a good chance. - He is an expert in the domain - He made a lawful request - He believes he's experiencing an obstruction of his rights I don't see anything egregious here. Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Suing sounds offensive, but th…
Trump Card: National Security
But still, that requires a response, and there hasn't been one.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#108I genuinely fear that he will be suicided one of these days.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#109Earlier quoted context omitted.
It's funny how often the bitterness of a post is used as an excuse to dismiss the long and well documented case being made.
If NTRU Prime had been declared the winner, would this suit have been filed? It's the same contest, same people, same suspicious behavior from NIST. I don't think this suit would have come up. djb is filing this suit because of alleged bad behavior, but I have doubts that it's the real reason.
The behavior in question by NIST isn’t just alleged - look at the FOIA ( https://www.muckrock.com/foi/united-states-of-america-10/nsa... ). They’re not responding in a reasonable or timely manner.
Does that seem like reasonable behavior by NIST to you?
To my eyes, it is completely unacceptable behavior by NIST, especially given the timely nature of the standardization process. They don’t even understand the fee structure correctly, it’s a comedy of incompetence with NIST.
His FOIA predates the round three announcement. His lawsuit was filed in a timely manner, and it appears that he filed it fairly quickly. Many requesters wait much longer before filing suit.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#110Earlier quoted context omitted.
I remember reading about this in Steven Levy's crypto and elsewhere, there was a lot of internal arguing about lots of this stuff at the time and people had different opinions. I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known (though at the the time people suspected they were suggesting this because it w…
You are not accurately reflecting the history that is presented in the very blog post we are discussing. NSA made DES weaker for everyone by reducing the key size. IBM happily went along. The history of IBM is dark. NSA credited tweaks to DES can be understood as ensuring that a weakened DES stayed deployed longer which was to their advantage. They clearly explain this in the history quoted by the author: “Narrowing…
I'm not sure I buy that this follows, wouldn't the weakened key size also make people not want to deploy it given that known weakness? To me it reads more that some people wanted a weak key so NSA could still break it, but other people wanted it to be stronger against differential cryptanalysis attacks and that they're not really related. It also came across that way in Levy's book where they were arguing about whether they should or should not engage with IBM at all.