Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

191–200 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#191
post #16

Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.

I'm working on a project that involves a customized version of some unclassified, non-intelligence software for a defense customer at my job (not my ideal choice of market, but it wasn't weapons so okay with it). Some of the people on the project come from the deeper end of that industry, with several TS/SCI contract and IC jobs on their resumes. We were looking over some errors on the sshd log and it was saying it c…

While I am skeptical of US domestic surveillance, Snowden leaked this information in the worst possible way.

Try internal whistleblower channels first. Not being heard? Mail to members of Congress? Contact congress? Contact the media?

Instead he fled to an adversary with classified material. That's not good faith behavior imo. Traitor

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#192

I just want to say, the problem here is worldwide standards bodies for encryption need to be trustworthy. It is incredibly hard to know what encryption is actually real without a deep mathematics background and even then, a choir of peers must be able to present algorithms, and audits of those algorithms with a straight face. Presenting broken-by-design encryption undermines public confidence in what should be one of…

how could NIST possibly be "one of our most sacrosanct institutions" after the NSA already fucked them with Dual_EC_DRBG? whoever wants to recommend standards at any point since 2015 needs to be someone else https://en.wikipedia.org/wiki/NIST_SP_800-90A for this who have forgotten.

Look, my point is that there are lots of companies around the world who can’t afford highly skilled mathematicians and cryptographers on staff. These institutions rely on NIST to help them determine what encryption systems may make sense. If NIST is truly adversarial, the public has a right to know and determine how to engage going forward.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#193
post #183

An expert, prominent, and someone who the whole cryptography community listens to, and he calls out the lies, crimes, and blatant hypocrisy of his own government. I genuinely fear that he will be suicided one of these days.

I think the United States is more about charging people with crimes and ruining their lives that way rather than disappearing people. Russia might kill you with Polonium and make sure everyone knows it, but America will straight up “legally“ torture you in prison via several means and then argue successfully that those methods were legal and convince the world you weren’t tortured. Anyone who’s a target for that trea…

McAfee and Epstein pop to mind. Maybe also Aaron Swartz.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#194
post #130

Earlier quoted context omitted.

You are completely misunderstanding yes. I'm saying some standards body is appropriate for validating/vetting algorithms, and having a standards body advocate for known reasonable ones is... reasonable and desirable. That NIST has a history of being compromised by the NSA (and other standards bodies would likely similarly be a target), is a problem. But having everyone 'figure it out' on their own is even worse. 'han…

> That NIST has a history of being compromised by the NSA is a problem. It's a disqualifying problem. If you go to a standards body to prevent yourself from making unintentional mistakes, and they have introduced intentional mistakes, any other reasonable option is better.

Personally I'm of the opinion that everyone is expecting the NSA to try now, so the odds of them pulling it off are essentially zero (same with other actors) at NIST.

If you specialize as a cat burglar after all, hitting the ONE PLACE everyone expects you to hit while they're watching goes against the grain.

More likely they're suborning us somewhere else. But hard to say for sure.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#195
post #168

Why is the submission URL using http instead of https? That just seems... bizarre.

Why? Http is simpler, less fragile, not dependent on good will of third parties, the content is public, and proving authenticity of text on Internet is always hard, even when served via the https scheme. I bet Bernstein thinks there is little point in forcing people to use https to read his page.

MITM could change what the client receives, right?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#197
post #32

I may believe almost all of this is overblown and silly, as like a matter of cryptographic research, but I'll say that Matt Topic and Merrick Wayne are the real deal, legit the lawyers you want working on something like this, and if they're involved, presumably some good will come out of the whole thing. Matt Topic is probably best known as the FOIA attorney who got the Laquan McDonald videos released in Chicago; I'v…

I have no doubt that they are great at their job, but when it comes to lawsuits the judge(s) are equally as important. You could get everything right but a judge has extreme power to interpret the law or even ignore it in select cases.

I wouldn't say they ignore the law, but legislation like FOIA has a lot of discretion to balance competing interests and that's where a judge would make the most different despite all the great articulations of the most brilliant lawyers.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#198
post #157

Earlier quoted context omitted.

Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…

> are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the algorithm on the encrypted output multiple times? Unless you can prove that all e.g. 2^256 possible 256 bit inputs map to 2^256 different 256 bit outputs (for every key, in the case of encryption), then chances are you lose strength with every application because multiple inputs map to…

For encryption, as opposed to hashing, you can’t have multiple inputs map to the same output, because then you wouldn’t be able to decrypt the output.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#199

Flippo valrosida and Matthey green aren't too happy. https://twitter.com/matthew_d_green/status/15556838562625208...

Filippo Valsorda seems to be happy to ignore the fact that NIST already let an NSA backdoor in, as recently as 2014: https://wikipedia.org/wiki/Dual_EC_DRBG is he really just going to ignore something from 8 years ago?

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#200

I just want to say, the problem here is worldwide standards bodies for encryption need to be trustworthy. It is incredibly hard to know what encryption is actually real without a deep mathematics background and even then, a choir of peers must be able to present algorithms, and audits of those algorithms with a straight face. Presenting broken-by-design encryption undermines public confidence in what should be one of…

There's an easier problem here, which is that our reliance on formal standards bodies for the selection of cryptography constructions is bad, and, not hardly just at NIST, has been over the last 20 years mostly a force for evil. One of the most important "standards" in cryptography, the Noise Protocol Framework, will probably never be a formal standard. But on the flip side, no formal standards body is going to crud it up with nonsense.

So, no, I'd say that bedlam will not follow from a lack of trustworthy cryptography standards. We've trusted standards too much as it is.

Post reply on HN