Earlier quoted context omitted.
I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.
Transparency is good, and, as Bernstein's attorneys will ably establish, not optional.
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
121–130 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#122Earlier quoted context omitted.
Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.
Every piece of mail that passes through a high-speed sorting machine is scanned, front and back, OCR'd, and stored - as far as we know, indefinitely. That's how they deliver the "what's coming in your mailbox" images you can sign up to receive via email. Those images very often show the contents of the envelope clearly enough to recognize and even read the contents, which I'm quite positive isn't an accident. The USP…
https://en.m.wikipedia.org/wiki/Mail_Isolation_Control_and_T...
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#123Earlier quoted context omitted.
This is part of a class division where we cannot practically exercise our rights which are clearly enumerated in public law. Only people with money or connections can even attempt to get many kinds of records. It’s wrong and government employees involved should be fired, and perhaps seriously punished. If people at NIST had faced real public scrutiny and sanction for their last round of sabotage, perhaps we wouldn’t…
> This is part of a class division where we cannot practically exercise our rights which are clearly enumerated in public law. Only people with money or connections can even attempt to get many kinds of records. As someone with those resources, I'm still kind of annoyed because I think this state agency is playing chess accurately too. My request was anonymous through my lawyer and nobody would know that I have these…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#124Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#125Earlier quoted context omitted.
"Roll your own crypto" typically refers to making your own algorithm or implementation of an algorithm not choosing the algorithm.
Would you really want every random corporation having some random person pick from the list of open source cipher packages? Which last I checked , still included things like 3DES, MD5, etc. You might as well hand a drunk monkey a loaded sub machine gun.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#126Earlier quoted context omitted.
Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.
TFA says: «The European Parliament already issued a 194-page "Report on the existence of a global system for the interception of private and commercial communications (ECHELON interception system)" in 2001» (July 2001, that is)
To clarify, I was asking them for their specific favorite programs as they didn’t indicate they only meant the ones in the blog post.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#127Earlier quoted context omitted.
It's an argument for fixing NIST so that it is trustworthy again.
This. One wonders if NIST can be fixed or if it should simply be abolished with all archives opened in the interest of restoring faith in the government . The damage done by NSA and NIST is much larger than either of those organizations.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#128Earlier quoted context omitted.
I'll also add Which have not prevented anything and instead are used in parallel construction to go after Americans
I don’t like the collateral damages of many policies. But it’s not fair to say that the policies “have not prevented anything” because we simply don’t know. The policies could have stopped in-progress evil acts (but they were never revealed to the public for intel reasons) or prevented attempts of an evil acts (well, nothing happened, nothing to report).
In comic books, we read fanciful stories about the good guys saving the world in secret. But the real world doesn't really work like that.
When the police seize some illegal drugs, what is the first thing they do? They snap a picture and publish it for society to see:
https://www.google.com/search?q=police+seize+drugs&tbm=isch
because citizens want to see that their tax money is being used successfully. The same would likely be done by the surveillance authorities if they saw significant success in their mission.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#129https://twitter.com/matthew_d_green/status/15556838562625208...
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#130Earlier quoted context omitted.
Would you really want every random corporation having some random person pick from the list of open source cipher packages? Which last I checked , still included things like 3DES, MD5, etc. You might as well hand a drunk monkey a loaded sub machine gun.
Surely I'm misunderstanding, are you really advocating that people should roll their own encryption algorithms from scratch? As in, they should invent novel and secure algorithms in isolation? And this should happen.... at every major enterprise or software company in the world?
I'm saying some standards body is appropriate for validating/vetting algorithms, and having a standards body advocate for known reasonable ones is... reasonable and desirable.
That NIST has a history of being compromised by the NSA (and other standards bodies would likely similarly be a target), is a problem. But having everyone 'figure it out' on their own is even worse. 'hand a drunk monkey a loaded submachine gun' worse.