Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

271–280 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#271

Earlier quoted context omitted.

I think you need to re-read my comment, because you have not comprehended what I just wrote.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. maybe you don't know what risible means, but it reads like you're saying that the NSA "somehow" coercing someone is unlikely, which i'm sure you can agree is a "very naive and trusting view"

Maybe he does know what risible means and is in fact extremely well informed, much better informed than you are, to the point where offering sarcasm on the apparent basis of absolutely nothing but what you've learnt from the internet is actually not a valuable contribution to the conversation but instead embarrassing. Have you considered this possibility as well?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#272
post #258

Earlier quoted context omitted.

This isn't the sort of shit you can start here, take a look at https://news.ycombinator.com/newsguidelines.html

If you think I went around looking to dig up dirt, I didn't. I just searched djb's name on Twitter to find more discussions about the subject, as post-quantum cryptography is an area I'm curious about. Regarding asking for a disclosure, I thought that was widely accepted around here. If the CEO of some company criticised a competitor's product, we would generally expect them to disclose that fact upfront. I thought t…

If you think I went around looking to dig up dirt

It doesn't matter, you can't toss stuff like that at people here, never mind characterize it the way you did, as a form of argument. It's in the guidelines, there are lots of moderator comments bout it, don't be doing it.

I thought that was appropriate here given the dismissive tone of GP.

It's not, no matter how 'dismissive' you think a comment is.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#273
post #263

Earlier quoted context omitted.

He said bribed, which quite explicitly means payment made to a person in a position of trust to corrupt his judgment . Coerced is not bribed. Period.

a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion

Where?

If you RTFA you'd know it pertains to bribery, not coercion.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#274
post #272

Earlier quoted context omitted.

If you think I went around looking to dig up dirt, I didn't. I just searched djb's name on Twitter to find more discussions about the subject, as post-quantum cryptography is an area I'm curious about. Regarding asking for a disclosure, I thought that was widely accepted around here. If the CEO of some company criticised a competitor's product, we would generally expect them to disclose that fact upfront. I thought t…

If you think I went around looking to dig up dirt It doesn't matter, you can't toss stuff like that at people here, never mind characterize it the way you did, as a form of argument. It's in the guidelines, there are lots of moderator comments bout it, don't be doing it. I thought that was appropriate here given the dismissive tone of GP. It's not, no matter how 'dismissive' you think a comment is.

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#275

Earlier quoted context omitted.

No. I don't think we should rely on formal standards, like FIPS, NIST, and the IETF. Like Bernstein himself, I do think we should rely on peer-reviewed expert cryptography. I use Chapoly, not a stream cipher I concocted myself, or some bizarro cipher cascade posted to HN. This is what I'm talking about when I mentioned the Noise Protocol Framework. If IETF standards happen to end up with good cryptography because the…

Standards are for people who are not experts in the field or don't have the time and energy to research the existing crypto and actually sift through them to try and decide what to trust and what not to trust. Lack of standardization might just make it harder for Joe to filter through the google searches and figure out what algorithm to use. He may just pick the first result on Google, which is an ad for the highest…

Standards are also essential for the interoperability of systems.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#276

Quoted post unavailable.

Not sure about the disclosure, having a grudge with djb is not particularly a minority thing.

Whatever "grudge" I have with Bernstein is, to say the least, grudging.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#277

Earlier quoted context omitted.

Two things can easily be true: that NIST mishandled a FOIA request, and that there isn't especially good reason to accept on faith Bernstein's concerns about the PQC process, which is unrelated to how they handle FOIA. Meanwhile: you haven't actually added any light to this subthread: the tweets we're talking about do not dismiss the suit. Cryptographic researchers that aren't stans of Daniel Bernstein (there are a l…

I am definitely not in that place. We clearly disagree on a few points. The issues raised in the blog post aren’t just about NIST mishandling the FOIA. By reducing it to the lawsuit, this is already a bad faith engagement. The blog post is primarily about the history of NSA sabotage as well as contemporary efforts, including (NIST’s) failures to stop this sabotage. Finally it finishes the recent history by raising th…

There's nothing "bad faith" about it. The tweet is supportive of the lawsuit, and not supportive of Bernstein's weird, heavily-telegraphed, long-predicted claims that a NIST contest he opted to participate in was corrupted by dint of not prioritizing his own designs.

Your bit about the "obviously Jewish family name" thing is itself risible, and you should be embarrassed for trying to make it a thing.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#278
post #275

Earlier quoted context omitted.

Standards are for people who are not experts in the field or don't have the time and energy to research the existing crypto and actually sift through them to try and decide what to trust and what not to trust. Lack of standardization might just make it harder for Joe to filter through the google searches and figure out what algorithm to use. He may just pick the first result on Google, which is an ad for the highest…

Standards are also essential for the interoperability of systems.

Formal standards aren't essential for interoperability.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#279
post #272

Earlier quoted context omitted.

If you think I went around looking to dig up dirt It doesn't matter, you can't toss stuff like that at people here, never mind characterize it the way you did, as a form of argument. It's in the guidelines, there are lots of moderator comments bout it, don't be doing it. I thought that was appropriate here given the dismissive tone of GP. It's not, no matter how 'dismissive' you think a comment is.

Quoted post unavailable.

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#280

Earlier quoted context omitted.

I'm not sure about corrupting NIST nor corrupting individual officials of NIST, but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. Running standards without full transparency, in my experiences of web security standards + web GPU standards is almost always due to hiding weaknesses,…

> ...but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. I agree with this. And I think that this is more likely to be the case. But I really think with all that we now know about US governmental organisations the possibility of backdoors or coercion should not be ruled out.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the world with unimpeachable reputations, and it's ludicrous to suggest that NSA could have compromised them.

The whole point of the competition structure is that you don't simply have to trust NIST; the competitors (and cryptographers who aren't even entrants in the contest) are peer reviewing each other, and NIST is refereeing.

What Bernstein is counting on here is that his cheering section doesn't know the names of any cryptographers besides "djb", Bruce Schneier, and maybe, just maybe, Joan Daemen. If they knew anything about who the PQC team members were, they'd shoot milk out their nose at the suggestion that NSA had suborned backdoors from them. What's upsetting is that he knows this, and he knows you don't know this, and he's exploiting that.

Post reply on HN