Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

261–270 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#261

Earlier quoted context omitted.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I'm not sure about corrupting NIST nor corrupting individual officials of NIST, but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. Running standards without full transparency, in my experiences of web security standards + web GPU standards is almost always due to hiding weaknesses,…

> ...but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy.

I agree with this. And I think that this is more likely to be the case. But I really think with all that we now know about US governmental organisations the possibility of backdoors or coercion should not be ruled out.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#262
post #255

> The same people tend to have trouble grasping that most of the vulnerabilities exploited and encouraged by NSA are also exploitable by the Chinese government. These people start with the assumption that Americans are the best at everything; ergo, we're also the best at espionage. If the Chinese government stole millions of personnel records from the U.S. government, records easily usable as a springboard for furthe…

If, rather than hoarding offensive tools & spying, the NSA had interpreted its mission as being to harden the security of government infrastructure (surely even more firmly within the remit of national security) and spent its considerable budget in that direction, would authn and authz controls have been used at the OPM?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#263
post #248

Earlier quoted context omitted.

No part of what I said had anything to do with what NSA would or wouldn't attempt to do. If you don't understand what I wrote, ask questions. What you did instead was leap to stupid conclusions.

You used obscure language to make yourself look smart and deal with the resulting confusion by calling people stupid instead of clarifying what was said. Please get your ego in order.

He said bribed, which quite explicitly means payment made to a person in a position of trust to corrupt his judgment. Coerced is not bribed. Period.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#264

Earlier quoted context omitted.

I think you need to re-read my comment, because you have not comprehended what I just wrote.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. maybe you don't know what risible means, but it reads like you're saying that the NSA "somehow" coercing someone is unlikely, which i'm sure you can agree is a "very naive and trusting view"

Nowhere does the comment say that the NSA "somehow" coercing someone is unlikely. Hence, it's fair question whether the comment had been comprehended, because it seems it hasn't in this thread. If comprehension begets intelligence than conclusions born from misunderstanding exude stupidity.

And, dropping the pedantry, it's quite frustrating to be deliberately or casually or in whatever way misrepresented by drive-by commenters in an otherwise apt discussion thread. Your comment and the one tptacek responded to are patronizing and dismissive and really don't contribute to any interesting discourse on the topic. I think it's fair to dismiss stupid drive-by low-effort quips, personally.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#265
post #93

Earlier quoted context omitted.

The NSA wants "NOBUS" (NObody-But-US) backdoors. It is in their interest to make a good show of fixing easily-detected vulnerabilities while keeping their own intentional ones a secret. The fantasy they are trying to sell to politicians is that people can keep secrets from other people but not from the government; that they can make uncrackable safes that still open when presented with a court warrant. This isn't spe…

Here's the counter-argument that I've seen in cryptography circles: Dual EC, a PRNG built on an asymmetric crypto template, was kind of a ham fisted and obvious NOBUS back door. The math behind it made such a backdoor entirely plausible. That's less obvious in other cases. Take the NIST ECC curves. If they're backdoored it means the NSA knows something about ECC we don't know and haven't discovered in the 20+ years s…

SM2 (Chinese), GOST (Russian) and NIST P (American) parameters are "you'll just have to straight up assume these are something up our sleeve numbers".

ECGDSA/brainpool (German) and ECKCDSA (Korean) standards make an attempt to explain how they chose recommended parameters but at least for brainpool parameters, the justifications fall short.

The DiSSECT[1] project recently published this year is an excellent approach to estimating whether parameters selected (often without justification) are suspicious. GOST parameters were found to be particularly suspicious.

I wonder if a similar project could be viable for assessing parameters of other types of cryptographic algorithms e.g. Rijndael S-box vs. SM4 S-box selection?

[1] https://dissect.crocs.fi.muni.cz/

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#267
post #258

Quoted post unavailable.

This isn't the sort of shit you can start here, take a look at https://news.ycombinator.com/newsguidelines.html

If you think I went around looking to dig up dirt, I didn't. I just searched djb's name on Twitter to find more discussions about the subject, as post-quantum cryptography is an area I'm curious about.

Regarding asking for a disclosure, I thought that was widely accepted around here. If the CEO of some company criticised a competitor's product, we would generally expect them to disclose that fact upfront. I thought that was appropriate here given the dismissive tone of GP.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#268
post #263
post #248

Earlier quoted context omitted.

You used obscure language to make yourself look smart and deal with the resulting confusion by calling people stupid instead of clarifying what was said. Please get your ego in order.

He said bribed, which quite explicitly means payment made to a person in a position of trust to corrupt his judgment . Coerced is not bribed. Period.

a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#270
post #183

An expert, prominent, and someone who the whole cryptography community listens to, and he calls out the lies, crimes, and blatant hypocrisy of his own government. I genuinely fear that he will be suicided one of these days.

I think the United States is more about charging people with crimes and ruining their lives that way rather than disappearing people. Russia might kill you with Polonium and make sure everyone knows it, but America will straight up “legally“ torture you in prison via several means and then argue successfully that those methods were legal and convince the world you weren’t tortured. Anyone who’s a target for that trea…

The FBI will just interview you over whatever and then charge you for lying to a federal agent or dig up some other unrelated dirt. While the original investigation gets mysteriously dropped a year later.
Post reply on HN