Earlier quoted context omitted.
No part of what I said had anything to do with what NSA would or wouldn't attempt to do. If you don't understand what I wrote, ask questions. What you did instead was leap to stupid conclusions.
You used obscure language to make yourself look smart and deal with the resulting confusion by calling people stupid instead of clarifying what was said. Please get your ego in order.
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
251–260 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#252Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#253Earlier quoted context omitted.
What's with the infighting here? Nothing about the post comes across as conspiracy theory level or reputation ruining. It makes me question the motives of those implying he's crazy, to be honest.
Post-quantum cryptography is essentially a full-employment program for elite academic public key cryptographers, which is largely what the "winning" PQC teams consist of. So, yeah, suggesting that one of those teams was compromised by an intelligence agency is "conspiracy theory level". Nobody is denying the legitimacy of the suit itself. NIST is obligated to follow public records law, and public records law is impor…
Because they show total disregard for someones opinion (in a more formal way: "unlike you/them, i completely agree with the (apparent) majority consensus (which it also implies), these words probably don't belong into a serious discussion.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#254Earlier quoted context omitted.
> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Is that even a claim here? I'm on mobile right now so it's a bit hard for me to trawl through the DJB/NIST dialogue, but I thought his main complaint is that NIST didn't appear to have a proper and clear process for choosing the algorithms they did, when arguably better algorithms were available.…
It is indeed a claim here; in fact, it's probably the principle claim.
Yes, DJB brings up their known bribing of RSA wrt to the whole Dual-EC thing. But my read of that bit of info was the more general 'here's evidence that the NSA actively commits funding towards infecting standards' rather than 'the NSA's playbook just contains outright bribery and that's what we expect to find in the FOIA requests given to NIST'.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#255I'm not sure if I understand this part. I was under the impression that the OPM hack was a result of poor authn and authz controls, unrelated to cryptography. Was there a cryptography component sourced somewhere?
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#256Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#257Earlier quoted context omitted.
They don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.
Where does the non-cryptographer public find out about the current consensus of the literature? Genuine question.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#258Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#259Earlier quoted context omitted.
It is indeed a claim here; in fact, it's probably the principle claim.
I guess I'm not reading it that way. In fact, a FOIA request is going after official records, which I wouldn't expect would contain outright bribery. Yes, DJB brings up their known bribing of RSA wrt to the whole Dual-EC thing. But my read of that bit of info was the more general 'here's evidence that the NSA actively commits funding towards infecting standards' rather than 'the NSA's playbook just contains outright…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#260Earlier quoted context omitted.
I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.
Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…
Unfortunately, this would appear to be the bit we've not yet solved, nor are we likely to.