Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

111–120 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#111
post #5

Earlier quoted context omitted.

seems like they just need a judge to force the NSA to comply with a Freedom of Information Act request, its just part of the process I'm stonewalled on an equivalent Public Record Act request w/ a state, and am kind of annoyed that I have to use the state's court system Doesn't feel super partial and a couple law journals have written about how its not partial at all in this state and should be improved by the legisl…

This is part of a class division where we cannot practically exercise our rights which are clearly enumerated in public law. Only people with money or connections can even attempt to get many kinds of records. It’s wrong and government employees involved should be fired, and perhaps seriously punished. If people at NIST had faced real public scrutiny and sanction for their last round of sabotage, perhaps we wouldn’t…

> This is part of a class division where we cannot practically exercise our rights which are clearly enumerated in public law. Only people with money or connections can even attempt to get many kinds of records.

As someone with those resources, I'm still kind of annoyed because I think this state agency is playing chess accurately too. My request was anonymous through my lawyer and nobody would know that I have these documents, while if I went through the court - even if it was anonymous with the ACLU being the filer - there would still be a public record in the court system that someone was looking for those specific documents, so that's annoying

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#112

Earlier quoted context omitted.

Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.

Every piece of mail that passes through a high-speed sorting machine is scanned, front and back, OCR'd, and stored - as far as we know, indefinitely. That's how they deliver the "what's coming in your mailbox" images you can sign up to receive via email. Those images very often show the contents of the envelope clearly enough to recognize and even read the contents, which I'm quite positive isn't an accident. The USP…

Agreed. It’s even worse: they also have the capability with the “mail covers” program to divert and tamper with mail. This happens to Americans on U.S. soil and I’m not just talking about suspects of terrorism.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#113

Earlier quoted context omitted.

The dragnets existed before 9/11. That just gave justification for even more funding.

Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.

TFA says: «The European Parliament already issued a 194-page "Report on the existence of a global system for the interception of private and commercial communications (ECHELON interception system)" in 2001» (July 2001, that is)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#114

An interesting thing that is happening on Bitcoin mailing list is that although it would be quite easy to add Lamport signatures as an extra safety feature for high value transactions, as they would be quite expensive and easy to misuse (they can be used only once, which is a problem if money is sent to the same address twice), the current concensus between developers is to ,,just wait for NSA/NIST to be ready with t…

Why not start that discussion yourself?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#115

Earlier quoted context omitted.

You are not accurately reflecting the history that is presented in the very blog post we are discussing. NSA made DES weaker for everyone by reducing the key size. IBM happily went along. The history of IBM is dark. NSA credited tweaks to DES can be understood as ensuring that a weakened DES stayed deployed longer which was to their advantage. They clearly explain this in the history quoted by the author: “Narrowing…

> "NSA credited tweaks to DES can be understood as ensuring that a weakened DES stayed deployed longer which was to their advantage. They clearly explain this in the history quoted by the author" I'm not sure I buy that this follows, wouldn't the weakened key size also make people not want to deploy it given that known weakness? To me it reads more that some people wanted a weak key so NSA could still break it, but o…

It follows: entire industries were required to deploy DES and the goal was to create one thing that was “strong enough” to narrow the field.

Read the blog post carefully about the role of NBS, IBM, and NSA in the development of DES.

It’s hard to accept because the implications are upsetting and profound. The evidence is clear and convincing. Lots of people try to muddy the waters, don’t help them please.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#118
post #47

Earlier quoted context omitted.

I don’t like the collateral damages of many policies. But it’s not fair to say that the policies “have not prevented anything” because we simply don’t know. The policies could have stopped in-progress evil acts (but they were never revealed to the public for intel reasons) or prevented attempts of an evil acts (well, nothing happened, nothing to report).

It also could have stopped the Gods from smiting us all, but there's no evidence that it has. This article[1] is a good start at realizing the costs outweigh the benefits. There's little or no evidence of good caused, but plenty of evidence of harms caused. [1]: https://www.eff.org/deeplinks/2014/06/top-5-claims-defenders...

There is evidence of that, in fact. There were many serious terrorist attacks in Europe, like in Spain's subway (300 dead) and Frankfurt, in the aftermath of 9/11 and other...uh howmy gonna say this...other stuff, the Spanish terrorist attacks were done by Basque nationalists or such, not Muslims.

So there's your control group, Europe.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#119
post #22

The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist. The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs. O…

the author was also part of the Linux kernel SPECK cipher talks that broke down in 2013 due to the nsa's stonewalling and hand waving for technical data and explanations. nsa speck was never adopted. https://en.m.wikipedia.org/wiki/Speck_(cipher)

Interesting read!

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#120

Maybe this is too much tinfoil hattery, but are we sure DJB isn't a government asset? He'd be the perfect deep-cover agent.

Please don’t do the JTRIG thing. Dan is a national treasure and we would be lucky to have more people like him fighting for all of us.

Between the two, material evidence shows that NIST is the deep-cover agent sabotaging our cryptography.

Post reply on HN