Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

231–240 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#231

Earlier quoted context omitted.

> "I may believe almost all of this is overblown and silly, as like a matter of cryptographic research ..." Am I misunderstanding you, or are you saying that you believe almost all of DJB's statements claiming that NIST/NSA is doctoring cryptography is overblown and silly? If that's the case, would you mind elaborating?

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible.

Is that even a claim here? I'm on mobile right now so it's a bit hard for me to trawl through the DJB/NIST dialogue, but I thought his main complaint is that NIST didn't appear to have a proper and clear process for choosing the algorithms they did, when arguably better algorithms were available.

So the suggestion wouldn't necessarily be that one of the respected contestants was bribed or otherwise compromised, but rather that NIST may have been tapped on the shoulder by NSA (again) with the suggestion that they should pick a specific algorithm, and that NSA would make the suggestion they have because their own cryptographers ("true believers" on NSA payroll) have discovered flaws in those suggested algorithms that they believe NSA can exploit but hopefully not adversaries can exploit.

There's no need for any novel conspiracies or corruption; merely an exact repeat of previous NSA/NIST behaviour consistent with NSA policy positions.

It's simultaneously about as banal as it gets, and deeply troubling because of that.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#232

Earlier quoted context omitted.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I think you need to re-read my comment, because you have not comprehended what I just wrote.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible.

maybe you don't know what risible means, but it reads like you're saying that the NSA "somehow" coercing someone is unlikely, which i'm sure you can agree is a "very naive and trusting view"

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#233
post #16

Weirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.

I'm working on a project that involves a customized version of some unclassified, non-intelligence software for a defense customer at my job (not my ideal choice of market, but it wasn't weapons so okay with it). Some of the people on the project come from the deeper end of that industry, with several TS/SCI contract and IC jobs on their resumes. We were looking over some errors on the sshd log and it was saying it c…

I think the term "doublethink" was invented specifically for government functionaries like the IC guy you describe.

Being consistently and perfectly dogmatic requires holding two contradictory beliefs in your head at once. It's a skill.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#235
Near the end of the post – after 50 years of axe grinding – djb does eventually get to the point wrt pqcrypto. I find the below excerpt particularly damning. Why not wrap nascent pqcrypto in classical crypto? Suspect!

--

The general view today is that of course post-quantum cryptography should be an extra layer on top of well-established pre-quantum cryptography. As the French government cybersecurity agency (Agence nationale de la sécurité des systèmes d'information, ANSSI) put it at the end of 2021:

Acknowledging the immaturity of PQC is important: ANSSI will not endorse any direct drop-in replacement of currently used algorithms in the short/medium term. However, this immaturity should not serve as an argument for postponing the first deployments. ANSSI encourages all industries to progress towards an initiation of a gradual overlap transition in order to progressively increase trust on the post-quantum algorithms and their implementations while ensuring no security regression as far as classical (pre-quantum) security is concerned. ...

Given that most post-quantum algorithms involve message sizes much larger than the current pre-quantum schemes, the extra performance cost of an hybrid scheme remains low in comparison with the cost of the underlying post-quantum scheme. ANSSI believes that this is a reasonable price to pay for guaranteeing an additional pre-quantum security at least equivalent to the one provided by current pre-quantum standardized algorithms.

But NSA has a different position: it says that it "does not expect to approve" hybrids. Publicly, NSA justifies this by

- pointing to a fringe case where a careless effort to add an extra security layer damaged security, and

- expressing "confidence in the NIST PQC process".

Does that mean the original NISTPQC process, or the current NISTPQC process in which NIST, evidently surprised by attacks, announced plans to call for new submissions?

Of course, if NSA/IDA have secretly developed an attack that works for a particular type of post-quantum cryptosystem, then it makes sense that they'd want people to start using that type of cryptosystem and turn off the existing pre-quantum cryptosystem.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#236

Earlier quoted context omitted.

I think this is a sloppy take. If you read the full back-and-forth on the FOI request between D.J. Bernstein and NIST, it becomes readily apparent that there is _something_ rotten in the state of NIST. Now of course that doesn't necessarily mean that NIST's work is completely compromised by the NSA (even though it has been in the past), but there are other problems that are similarly serious. For example, if NIST is…

All you're saying here is that NIST failed to comply with FOIA. That's not unusual. No public body does a reliably good job of complying with FOIA, and many public bodies seem to have a bad habit of pre-judging the "merits" of FOIA requests, when no merit threshold exists for their open records requirements. NIST failing to comply with FOIA makes them an intransigent public body, like all the rest of them, from your…

> It emphatically does not lend support to any of this litigants concerns about the PQC process.

I agree with most of what you're saying except for this. In my view, unlike some of the other organisations you mentioned, the _only value_ of NIST is in the quality and transparency of its processes. My reading of the DJB/NIST FOI dialogue is that there is reason to believe NIST has serious process problems that go far beyond simply handling an FOI well. From their own responses, it reads as if they aren't able to articulate themselves why they would choose one contestant's algorithm over another's. That kind of undermines the entire point of having an open contest.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#238

Earlier quoted context omitted.

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Is that even a claim here? I'm on mobile right now so it's a bit hard for me to trawl through the DJB/NIST dialogue, but I thought his main complaint is that NIST didn't appear to have a proper and clear process for choosing the algorithms they did, when arguably better algorithms were available.…

It is indeed a claim here; in fact, it's probably the principle claim.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#239

Earlier quoted context omitted.

I think you need to re-read my comment, because you have not comprehended what I just wrote.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. maybe you don't know what risible means, but it reads like you're saying that the NSA "somehow" coercing someone is unlikely, which i'm sure you can agree is a "very naive and trusting view"

No part of what I said had anything to do with what NSA would or wouldn't attempt to do.

If you don't understand what I wrote, ask questions. What you did instead was leap to stupid conclusions.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#240

Earlier quoted context omitted.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I think you need to re-read my comment, because you have not comprehended what I just wrote.

You said:

> the motivation behind those requests is risible.

It is quite hilarious that NIST suckered the industry into actually using Dual-EC, despite being worse than the other possible choices in nearly every respect. And this ignores the fact that the backdoor was publicly known for years. This actually happened; it’s not a joke.

The motivation behind the FOIA requests is to attempt to see whether any funny business is going on with PQ crypto.

If the NSA actually suckers any major commercial player into using a broken PQ scheme without a well-established classical scheme as a backup, that will be risible too.

Post reply on HN