Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

151–160 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#151

An interesting thing that is happening on Bitcoin mailing list is that although it would be quite easy to add Lamport signatures as an extra safety feature for high value transactions, as they would be quite expensive and easy to misuse (they can be used only once, which is a problem if money is sent to the same address twice), the current concensus between developers is to ,,just wait for NSA/NIST to be ready with t…

Indeed as potato said, link this article in the ML for them to see that NIST can not be fully trusted

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#152
post #95

Earlier quoted context omitted.

"Roll your own crypto" typically refers to making your own algorithm or implementation of an algorithm not choosing the algorithm.

Would you really want every random corporation having some random person pick from the list of open source cipher packages? Which last I checked , still included things like 3DES, MD5, etc. You might as well hand a drunk monkey a loaded sub machine gun.

Is it your view that the only way a group of humans can come together to make intelligent decisions and a group, is part of a national government? Why can't an organization of private individuals do so?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#153
post #93

Earlier quoted context omitted.

The NSA wants "NOBUS" (NObody-But-US) backdoors. It is in their interest to make a good show of fixing easily-detected vulnerabilities while keeping their own intentional ones a secret. The fantasy they are trying to sell to politicians is that people can keep secrets from other people but not from the government; that they can make uncrackable safes that still open when presented with a court warrant. This isn't spe…

Here's the counter-argument that I've seen in cryptography circles: Dual EC, a PRNG built on an asymmetric crypto template, was kind of a ham fisted and obvious NOBUS back door. The math behind it made such a backdoor entirely plausible. That's less obvious in other cases. Take the NIST ECC curves. If they're backdoored it means the NSA knows something about ECC we don't know and haven't discovered in the 20+ years s…

Regarding Simon and Speck: one simple answer is that the complicated attacks may exist and simple attacks certainly exist for smaller block and smaller key sizes.

However, it’s really not necessary to have a backdoor in ARX designs directly when they’re using key sizes such as 64, 72, 96, 128, 144, 192 or 256 bits with block sizes of 32, 48, 64, 96 or 128 bits. Especially so if quantum computers arrive while these ciphers are still deployed. Their largest block sizes are the smallest available for other block ciphers. The three smallest block sizes listed are laughable.

They have larger key sizes specified on the upper end. Consider that if the smaller keys are “good enough for NSA” - it will be used and exploited in practice. Not all bits are equal either. Simon’s or Spec’s 128 bits are doubtfully as strong as AES’s 128 bits, certainly with half the bits for the block size. It also doesn’t inspire confidence that AES had rounds removed and that the AES 256 block size is… 128 bits. Suite A cryptography probably doesn’t include a lot of 32 bit block sizes. Indeed BATON supposedly bottoms out at 96 bits. One block size for me, another for thee?

In a conversation with an author of Speck at FSE 2015, he stated that for some systems only a few minutes of confidentiality was really required. This was said openly!

This is consistent in my view with NSA again intentionally pushing crypto that can be broken in certain conditions to their benefit. This can probably be practically exploited though brute force with their computational resources.

Many symmetric cryptographers literally laugh at the NSA designs and at their attempts at papers justifying their designs.

Regarding NIST curves, the safe curves project shows that implementing them safely is difficult. That doesn’t seem like an accident to me, but perhaps I am too cynical? Side channels are probably enough for targeted breaks. NIST standardization of ECC designs don’t need to be exploited in ways that cryptographers respect - it just needs to work for NSA’s needs.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#154

Earlier quoted context omitted.

Which programs do you mean specifically? We know the nature of the mass surveillance changed and expanded immensely after 9/11 in a major way, especially domestically.

There was the Clipper Chip [2] and the super-weak 40-bit 'export strength' cryptography [3] and the investigation of PGP author Phil Zimmerman for 'munitions export without a license' [4]. So there was a substantial effort to weaken cryptography, decades before 9/11. On the dragnet surveillance front, there have long been rumours of things like ECHELON [1] being used for mass surveillance and industrial espionage. An…

> there was a substantial effort to weaken cryptography, decades before 9/11.

Yes, agreed. Everyone should dig up their favorite programs and discuss them openly.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#155
post #32

I may believe almost all of this is overblown and silly, as like a matter of cryptographic research, but I'll say that Matt Topic and Merrick Wayne are the real deal, legit the lawyers you want working on something like this, and if they're involved, presumably some good will come out of the whole thing. Matt Topic is probably best known as the FOIA attorney who got the Laquan McDonald videos released in Chicago; I'v…

I have no doubt that they are great at their job, but when it comes to lawsuits the judge(s) are equally as important. You could get everything right but a judge has extreme power to interpret the law or even ignore it in select cases.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#157
post #44
post #32

I may believe almost all of this is overblown and silly, as like a matter of cryptographic research, but I'll say that Matt Topic and Merrick Wayne are the real deal, legit the lawyers you want working on something like this, and if they're involved, presumably some good will come out of the whole thing. Matt Topic is probably best known as the FOIA attorney who got the Laquan McDonald videos released in Chicago; I'v…

I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.

Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills:

1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used?

2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the algorithm on the encrypted output multiple times?

It seems that these question often have piles of people ready to jump in saying "oh, don't roll your own encryption, ooh scary... fear uncertainty doubt... and oh whatever you do, don't encrypt something 3X that will probably make it easier to decrypt!!" .. but it would be great if some neutral 3rd party could basically say, ok here is an algorithm that is ridiculously hard to break, and you can crank up the number of bits to a super crazy number.. and then also you can run the encryption N times and just not knowing the number of times it was encrypted would dramatically increase the complexity of decryption... but yea how many minutes before somebody jumps in saying -- yea, don't do that, make sure you encrypt with a well known algorithm exactly once.. "trust me"...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#158
post #157
post #44

Earlier quoted context omitted.

I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.

Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…

1. Formal, centralized crypto standards, be they NIST or IETF, are a force for evil.

2. All else equal, fewer dependencies on randomness are better. But all else is not equal, and you can easily lose security by adding determinism to designs willy-nilly in an effort to minimize randomness dependencies.

Nothing is, any time in the conceivable future, change to make a broken RNG not game-over. So the important thing remains ensuring that there's a sound design for your RNG.

None of our problems have anything to do with how "much" you encrypt something, or with "cranking up the number of bits". That should be good news for you; generally, you can run ChaPoly or AES-CTR and trust that a direct attack on the cipher isn't going to be an issue for you. Most of our problems are in the joinery, not the beams themselves.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#159

Tangential question: while some FOIA requests do get stonewalled, I continue to be fascinated that they're honored in other cases. What exactly prevents the government from stonewalling practically every request that it doesn't like, until and unless it's ordered by a court to comply? Is there any sort of penalty for their noncompliance? Tangential to the tangent: is there any reason to believe FOIA won't be on the c…

I know someone who works in gov (Australia, not US) who told me all about a FOI request that he was stonewalling. From memory, the request was open ended and would have revealed more than it possibly intended it to, and would have revealed some proprietary trade secrets from a third party contractor. That said, it was probably a case that would attract some public interest.

The biggest factors preventing governments from stonewalling every FOI case are generally time and money. Fighting FOI cases is time consuming and expensive and it's simply easier to hand over the information.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#160

Flippo valrosida and Matthey green aren't too happy. https://twitter.com/matthew_d_green/status/15556838562625208...

I think this is a sloppy take. If you read the full back-and-forth on the FOI request between D.J. Bernstein and NIST, it becomes readily apparent that there is _something_ rotten in the state of NIST.

Now of course that doesn't necessarily mean that NIST's work is completely compromised by the NSA (even though it has been in the past), but there are other problems that are similarly serious. For example, if NIST is unable to explain how certain key decisions were made along the way to standardisation, and those decisions appear to go against what would be considered by prominent experts in the field as "good practice", then NIST has a serious process problem. This is important work. It affects everyone in the world. And certain key parts of NIST's decision making process seem to be explained with not much more than a shrug. That's a problem.

Post reply on HN