Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

211–220 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#211

Earlier quoted context omitted.

> "I may believe almost all of this is overblown and silly, as like a matter of cryptographic research ..." Am I misunderstanding you, or are you saying that you believe almost all of DJB's statements claiming that NIST/NSA is doctoring cryptography is overblown and silly? If that's the case, would you mind elaborating?

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#212
post #199

Earlier quoted context omitted.

Filippo Valsorda seems to be happy to ignore the fact that NIST already let an NSA backdoor in, as recently as 2014: https://wikipedia.org/wiki/Dual_EC_DRBG is he really just going to ignore something from 8 years ago?

Quoted post unavailable.

First, last I checked, Filippo does not in fact work at Google.

Second: the guidelines on this site forbid you to write comments like this; in fact, this pattern of comments is literally the most frequent source of moderator admonitions on HN.

Filippo hardly needs me to defend his reputation, but, as a service to HN and to you in particular, I'd want to raise your awareness of the risk of beclowning yourself by suggesting that he, of all people, is somehow compromised.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#213
post #29

Earlier quoted context omitted.

I think we are a long way away from being able to wirelessly read a few specific bytes of data from the brain of an unknowing person. Far enough away that I'm not sure it's productive to begin thinking of how to design encryption systems around it.

Memory and experience aren't encoded in the brain like traditional computers. There's no concept of a "byte" when thinking about the human computational model.

There is the concept of "byte" when talking about a string of characters which make up a password, though, which is why I said bytes. But yes, I am aware, and your statement just further supports my point.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#214

Earlier quoted context omitted.

There's an easier problem here, which is that our reliance on formal standards bodies for the selection of cryptography constructions is bad, and, not hardly just at NIST, has been over the last 20 years mostly a force for evil. One of the most important "standards" in cryptography, the Noise Protocol Framework, will probably never be a formal standard. But on the flip side, no formal standards body is going to crud…

Believing both "Don't roll your own crypto" and "Don't trust the standards" would seem to leave the average developer in something of a quandry, no?

No. I don't think we should rely on formal standards, like FIPS, NIST, and the IETF. Like Bernstein himself, I do think we should rely on peer-reviewed expert cryptography. I use Chapoly, not a stream cipher I concocted myself, or some bizarro cipher cascade posted to HN. This is what I'm talking about when I mentioned the Noise Protocol Framework.

If IETF standards happen to end up with good cryptography because they too adopt things like Noise or Ed25519, that's great. I don't distrust the IETF's ability to standardize something like HTTP/3. I do deeply distrust the process they use to arrive at cryptographic architectures. It's gotten markedly better, but there's every reason to believe it'll backslide a generation from now.

(There are very excellent people who contribute to things like CFRG and I wouldn't want to be read as disparaging any of them. It's the process I have an issue with, not anything happening there currently.)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#216

Earlier quoted context omitted.

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I think you need to re-read my comment, because you have not comprehended what I just wrote.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#217

Earlier quoted context omitted.

how could NIST possibly be "one of our most sacrosanct institutions" after the NSA already fucked them with Dual_EC_DRBG? whoever wants to recommend standards at any point since 2015 needs to be someone else https://en.wikipedia.org/wiki/NIST_SP_800-90A for this who have forgotten.

Look, my point is that there are lots of companies around the world who can’t afford highly skilled mathematicians and cryptographers on staff. These institutions rely on NIST to help them determine what encryption systems may make sense. If NIST is truly adversarial, the public has a right to know and determine how to engage going forward.

They don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#219

If anyone is curious, the courtlistener link for the lawsuit is here: https://www.courtlistener.com/docket/64872195/bernstein-v-na... (And somebody has already kindly uploaded the documents to RECAP, so it costs you nothing to access.) Aside: I really wish people would link to court documents whenever they talk about an ongoing lawsuit.

It's just a vanilla FOIA lawsuit, of the kind hundreds of people file every month when public bodies fuck up FOIA.

If NIST puts up any kind of fight (I don't know why they would), it'll be fun to watch Matt and Wayne, you know, win a FOIA case. There's a lot of nerd utility in knowing more about how FOIA works!

But you're not going to get the secrets of the Kennedy assassination by reading this thing.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#220
post #177

Earlier quoted context omitted.

Dismissing this lawsuit as a conspiracy theory is embarrassing for both of them. There is ample evidence to document malfeasance by the involved parties, and it’s reasonable to ask NIST to follow public law.

> Dismissing this lawsuit as a conspiracy theory is embarrassing for both of them. They are not dismissing the lawsuit.

One says he’s doing it wrong. The other says he hopes that he wins, of course!

Meanwhile they go on to attack Bernstein, mischaracterize his writing, completely dismiss his historical analysis, mock him with memes as a conspiracy theorist, and to top it off they question his internal motivations (which they somehow know) as some kind of a sore loser which is demonstrably false.

The plot twist for the last point: he is still in the running for round four and his former PhD students did win major parts of round three.

Post reply on HN