Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

281–290 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#281
post #240

Earlier quoted context omitted.

I think you need to re-read my comment, because you have not comprehended what I just wrote.

You said: > the motivation behind those requests is risible. It is quite hilarious that NIST suckered the industry into actually using Dual-EC, despite being worse than the other possible choices in nearly every respect. And this ignores the fact that the backdoor was publicly known for years . This actually happened; it’s not a joke. The motivation behind the FOIA requests is to attempt to see whether any funny busi…

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE.

The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantial evidence around its role in the OPM hack which, if true, is much more of a "self own" than anything else.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#282
post #73

Perhaps the old advice (“never roll your own crypto”) should be reevaluated? If you’re creative enough, you could combine and apply existing algorithms in such ways that it would be very difficult to decrypt? Think 500 programmatic combinations (steps) of encryption applying different algorithms. Content encrypted in this way would require knowledge of the encryption sequence in order to execute the required steps in…

No not at all, that advice is still good. Even more important if your are talking about modifying algorithms. Your gonna want proofs of resistance or immunity to certain classes of attacks. A subtle change can easily make a strong primitive useless.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#283
post #255

> The same people tend to have trouble grasping that most of the vulnerabilities exploited and encouraged by NSA are also exploitable by the Chinese government. These people start with the assumption that Americans are the best at everything; ergo, we're also the best at espionage. If the Chinese government stole millions of personnel records from the U.S. government, records easily usable as a springboard for furthe…

This is my understanding as well. I asked this very same question less than a week ago[1], and now it's the first Google result when you search "OPM Dual_EC_DRBG."

The response to my comment covers some circumstantial evidence. But I'm not personally convinced; human factors are a much more parsimonious explanation.

[1]: https://news.ycombinator.com/item?id=32286528

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#284

Earlier quoted context omitted.

Post-quantum cryptography is essentially a full-employment program for elite academic public key cryptographers, which is largely what the "winning" PQC teams consist of. So, yeah, suggesting that one of those teams was compromised by an intelligence agency is "conspiracy theory level". Nobody is denying the legitimacy of the suit itself. NIST is obligated to follow public records law, and public records law is impor…

Has the general notion of "conspiracy theory" ever carried any positive value? It only seems to exist to discredit "doubters against the majority consensus" without substance. But I guess words like "crank" wouldn't even exist if there weren't many people like it, so it carries some "definitional" value. Because they show total disregard for someones opinion (in a more formal way: "unlike you/them, i completely agree…

Our notion of "crank"/conspiracy theory is a logical consequence of "extraordinary claims require extraordinary evidence." When that evidence isn't provided all that remains is an exceptionally convoluted explanation, generally involving more parties than necessary, hence "conspiracy."

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#285

Earlier quoted context omitted.

All you're saying here is that NIST failed to comply with FOIA. That's not unusual. No public body does a reliably good job of complying with FOIA, and many public bodies seem to have a bad habit of pre-judging the "merits" of FOIA requests, when no merit threshold exists for their open records requirements. NIST failing to comply with FOIA makes them an intransigent public body, like all the rest of them, from your…

> It emphatically does not lend support to any of this litigants concerns about the PQC process. I agree with most of what you're saying except for this. In my view, unlike some of the other organisations you mentioned, the _only value_ of NIST is in the quality and transparency of its processes. My reading of the DJB/NIST FOI dialogue is that there is reason to believe NIST has serious process problems that go far b…

The peer review NIST is refereeing happened in the open. Thus far, Bernstein is the only person making these claims. For all the words he burns on NIST's sordid history, he chose to participate in this NIST-run process, and imploded publicly only after the results were announced. There are dozens of cryptographers with reputations in the field comparable to Bernstein's who also participated. Bernstein is the only one suggesting that NSA bribed the contest winners.

From what I can tell, nobody who actually works in this field is taking any of this seriously; what I see is a whole lot of eye rolling and "there he goes again". But you don't get any of that on HN, because HN isn't a forum for cryptography researchers. All you get is Bernstein's cheering section.

I was part of Bernstein's cheering section! I understand the feeling. And, like, I'm still using ChaPoly and 25519 in preference to any of the alternatives! He's done hugely important work. But he has, not to put too fine a point on it, a fucked up reputation among his peers in cryptography research, and he's counting on you not to know that, and to confuse a routine, workaday FOIA lawsuit with some monumental new bit of litigation.

It's a deeply cynical thing for him to be doing.

He could have just announced, in his lovably Bernsteinian† way, that NIST had failed in its FOIA obligations, and he was holding them to account. I'd be cheering too. But he wrote a screed that culminated in an allegation that NSA had bribed members of PQC teams to weaken their submissions. Simply risible; it's embarrassing to be part of a community that dignifies that argument, even if I absolutely get why it's happening. I have contempt for him for exploiting all of you.

None of this is to take anything away from his FOIA suit. I stan his FOIA attorneys. The suit, boring as it is, is a good thing. He should win, and he almost certainly will; L&L wouldn't have taken the case if he wasn't going to. Just keep in mind, people sue and win over FOIA mistakes all the time. In Illinois, you even get fee recovery when you win. This isn't Bernstein v United States!

I'm not being snarky; I was a multiple-decades-long admirer of that style.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#286
post #240

Earlier quoted context omitted.

You said: > the motivation behind those requests is risible. It is quite hilarious that NIST suckered the industry into actually using Dual-EC, despite being worse than the other possible choices in nearly every respect. And this ignores the fact that the backdoor was publicly known for years . This actually happened; it’s not a joke. The motivation behind the FOIA requests is to attempt to see whether any funny busi…

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…

It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen.

Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual EC was a real backdoor; it seemed like such idiotic tradecraft. But the belief that Dual EC was so bad as tradecraft that it couldn't be real was, apparently, part of the tradecraft! Bernstein is right about that (even if he came to the conclusion at basically the same time as everyone else --- like, the instant you find out Juniper/Netscreen is using Dual EC, the jig is up).

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#287
post #263

Earlier quoted context omitted.

He said bribed, which quite explicitly means payment made to a person in a position of trust to corrupt his judgment . Coerced is not bribed. Period.

a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion

It's a fun word, right? "Risible"? I chose it carefully, though.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#288

Earlier quoted context omitted.

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…

It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…

Thanks. I suppose I live a charmed life for thinking that nobody was using BSAFE :-)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#289

Earlier quoted context omitted.

It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…

Thanks. I suppose I live a charmed life for thinking that nobody was using BSAFE :-)

I promise you, I know the feeling.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#290

Earlier quoted context omitted.

> "I may believe almost all of this is overblown and silly, as like a matter of cryptographic research ..." Am I misunderstanding you, or are you saying that you believe almost all of DJB's statements claiming that NIST/NSA is doctoring cryptography is overblown and silly? If that's the case, would you mind elaborating?

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

> risible

just in case someone else never heard this word before:

> arousing or provoking laughter

Post reply on HN