Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

131–140 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#131

Earlier quoted context omitted.

The dragnets existed before 9/11. That just gave justification for even more funding.

Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.

There was the Clipper Chip [2] and the super-weak 40-bit 'export strength' cryptography [3] and the investigation of PGP author Phil Zimmerman for 'munitions export without a license' [4].

So there was a substantial effort to weaken cryptography, decades before 9/11.

On the dragnet surveillance front, there have long been rumours of things like ECHELON [1] being used for mass surveillance and industrial espionage. And the simple fact US spies were interested in weakening export SSL rather implied, to a lot of people, they had easy access to the ciphertext.

Of course, this was before so much stuff had moved online, so it was a different world.

[1] https://en.wikipedia.org/wiki/ECHELON [2] https://en.wikipedia.org/wiki/Clipper_chip [3] https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... [4] https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_i...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#133

The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist. The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs. O…

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#134

Maybe this is too much tinfoil hattery, but are we sure DJB isn't a government asset? He'd be the perfect deep-cover agent.

Though 99% of the time I would agree with you, the public has to have faith in people who claim to be fighting (with previously noted successes in Bernstein v. US) in our best interests.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#136
post #133

The history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist. The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs. O…

[deleted]

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#137
post #48

Earlier quoted context omitted.

> I remember that some of the suggested changes from NSA shared with IBM were actually stronger against a cryptanalysis attack on DES that was not yet publicly known So we have that and other examples of NSA apparently strengthening crypto, then we have the dual-EC debacle and some of the info in the Snowden leaks showing that they've tried to weaken it. I feel like any talk about NSA influence on NIST PQ or other cu…

The NSA wants "NOBUS" (NObody-But-US) backdoors. It is in their interest to make a good show of fixing easily-detected vulnerabilities while keeping their own intentional ones a secret. The fantasy they are trying to sell to politicians is that people can keep secrets from other people but not from the government; that they can make uncrackable safes that still open when presented with a court warrant. This isn't spe…

NSA doesn’t want NOBUS, they’re not a person.

NSA leadership has policies to propose and promote the NOBUS dream. Even with Dual_EC_DRBG, the claims of NOBUS were incredibly arrogant. Just ask Juniper and OPM how that NOBUS business worked out. The NSA leadership wants privileged access and data at nearly any cost. The leadership additionally want you to believe that they want NOBUS for special, even exceptional cases. In reality they want bulk data, and they want it even if the NOBUS promises can fail open.

Don’t believe the hype, security is hard enough, NOBUS relies on so many assumptions that it’s a comedy. We know about Snowden because he went public, does anyone think we, the public, would learn if important keys were compromised to their backdoors? It seems extremely doubtful that even the IG would learn, even if NSA themselves could discover it in all cases.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#138
post #78

Earlier quoted context omitted.

You are not accurately reflecting the history that is presented in the very blog post we are discussing. NSA made DES weaker for everyone by reducing the key size. IBM happily went along. The history of IBM is dark. NSA credited tweaks to DES can be understood as ensuring that a weakened DES stayed deployed longer which was to their advantage. They clearly explain this in the history quoted by the author: “Narrowing…

>IBM happily went along. The history of IBM is dark. Then, as of now, I'm confused why people expect these kinds of problems to be solved by corporations "doing the right thing" rather than demanding some kind of real legislative reform.

Libertarian and capitalist propaganda. The answer is always a variation of “if you don’t like it, don’t buy it/let the market decide.” Even if the “market” heads towards apocalypse.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#139
post #94

side question : I've only recently started to digg a bit deeper into crypto algorithms ( looking into various types of curves etc), and it gave me the uneasing feeling that the whole industry is relying on the expertise of only a handful of guys to actually ensure that crypto schemes used today are really working. Am i wrong ? are there actually thousands and thousands of people with the expertise to actually proove…

There may be thousands of people in the entire world who understand cryptanalysis well enough to accurately judge the security of modern ciphers. Most aren't living or working in the U.S.

It's very difficult to do better. The mathematics is complex and computer science hasn't achieved proofs of the hypotheses underlying cryptography. The best we can achieve is heuristic judgements about what the best possible attacks are, and P?=NP is an open question.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#140

Tangential question: while some FOIA requests do get stonewalled, I continue to be fascinated that they're honored in other cases. What exactly prevents the government from stonewalling practically every request that it doesn't like, until and unless it's ordered by a court to comply? Is there any sort of penalty for their noncompliance? Tangential to the tangent: is there any reason to believe FOIA won't be on the c…

Presumably most government employees are acting in good faith - why wouldn’t they fulfil a reasonable FOIA request?

This is likely the result of some actors not acting in good faith, and so have no choice but to stonewall lest their intransigence be revealed.

Post reply on HN