Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

251–260 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#251
post #248

Earlier quoted context omitted.

No part of what I said had anything to do with what NSA would or wouldn't attempt to do. If you don't understand what I wrote, ask questions. What you did instead was leap to stupid conclusions.

You used obscure language to make yourself look smart and deal with the resulting confusion by calling people stupid instead of clarifying what was said. Please get your ego in order.

The person is saying one thing then denying saying that thing and being a jerk about it. Either a bot or someone with a broken thesaurus. Glad you pointed it out because it’s ridiculous/risible.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#253

Earlier quoted context omitted.

What's with the infighting here? Nothing about the post comes across as conspiracy theory level or reputation ruining. It makes me question the motives of those implying he's crazy, to be honest.

Post-quantum cryptography is essentially a full-employment program for elite academic public key cryptographers, which is largely what the "winning" PQC teams consist of. So, yeah, suggesting that one of those teams was compromised by an intelligence agency is "conspiracy theory level". Nobody is denying the legitimacy of the suit itself. NIST is obligated to follow public records law, and public records law is impor…

Has the general notion of "conspiracy theory" ever carried any positive value? It only seems to exist to discredit "doubters against the majority consensus" without substance. But I guess words like "crank" wouldn't even exist if there weren't many people like it, so it carries some "definitional" value.

Because they show total disregard for someones opinion (in a more formal way: "unlike you/them, i completely agree with the (apparent) majority consensus (which it also implies), these words probably don't belong into a serious discussion.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#254

Earlier quoted context omitted.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Is that even a claim here? I'm on mobile right now so it's a bit hard for me to trawl through the DJB/NIST dialogue, but I thought his main complaint is that NIST didn't appear to have a proper and clear process for choosing the algorithms they did, when arguably better algorithms were available.…

It is indeed a claim here; in fact, it's probably the principle claim.

I guess I'm not reading it that way. In fact, a FOIA request is going after official records, which I wouldn't expect would contain outright bribery.

Yes, DJB brings up their known bribing of RSA wrt to the whole Dual-EC thing. But my read of that bit of info was the more general 'here's evidence that the NSA actively commits funding towards infecting standards' rather than 'the NSA's playbook just contains outright bribery and that's what we expect to find in the FOIA requests given to NIST'.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#255
> The same people tend to have trouble grasping that most of the vulnerabilities exploited and encouraged by NSA are also exploitable by the Chinese government. These people start with the assumption that Americans are the best at everything; ergo, we're also the best at espionage. If the Chinese government stole millions of personnel records from the U.S. government, records easily usable as a springboard for further attacks, this can't possibly be because the U.S. government made a policy decision to keep our computer systems "weak enough to still permit an attack of some nature using very sophisticated (and expensive) techniques".

I'm not sure if I understand this part. I was under the impression that the OPM hack was a result of poor authn and authz controls, unrelated to cryptography. Was there a cryptography component sourced somewhere?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#257
post #247

Earlier quoted context omitted.

They don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.

Where does the non-cryptographer public find out about the current consensus of the literature? Genuine question.

I guess if I saw what FAANG companies were using to secure their own data that could be an indicator. Though they could be compromised.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#259

Earlier quoted context omitted.

It is indeed a claim here; in fact, it's probably the principle claim.

I guess I'm not reading it that way. In fact, a FOIA request is going after official records, which I wouldn't expect would contain outright bribery. Yes, DJB brings up their known bribing of RSA wrt to the whole Dual-EC thing. But my read of that bit of info was the more general 'here's evidence that the NSA actively commits funding towards infecting standards' rather than 'the NSA's playbook just contains outright…

The FOIA issue is 100% legitimate. NIST is required to comply with FOIA.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#260
post #157
post #44

Earlier quoted context omitted.

I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.

Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…

> some neutral 3rd party

Unfortunately, this would appear to be the bit we've not yet solved, nor are we likely to.

Post reply on HN