Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

291–300 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#291
post #248

Earlier quoted context omitted.

You used obscure language to make yourself look smart and deal with the resulting confusion by calling people stupid instead of clarifying what was said. Please get your ego in order.

The person is saying one thing then denying saying that thing and being a jerk about it. Either a bot or someone with a broken thesaurus. Glad you pointed it out because it’s ridiculous/risible.

That person is very well known in this community, and in other communities as well.

They are also known for making very specific arguments that people misinterpret and fight over, but the actual intent and literal meaning of the statements is most often correct (IMO).

Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expose those that are a combination of careless with their reading and willing to make assumptions rather than ask questions is unknown to me, but that doesn't change how it tends to play out, from my perspective.

In this case, I'll throw you a bone and restate his position as I understand it.

NIST ran the competition in question in a way such that all the judges referred each other, and all are very well known in the cryptographic field, and the suggestion by someone with more common game that they could be bribes in this manner (note not that the NSA would not attempt it, but the implication they would succeed with the people in question) is extremely unlikely, and that DJB would suggest as much knowing his fame may matter to people more than the facts of who these people are, is problematic.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#292

Earlier quoted context omitted.

I guess I'm not reading it that way. In fact, a FOIA request is going after official records, which I wouldn't expect would contain outright bribery. Yes, DJB brings up their known bribing of RSA wrt to the whole Dual-EC thing. But my read of that bit of info was the more general 'here's evidence that the NSA actively commits funding towards infecting standards' rather than 'the NSA's playbook just contains outright…

The FOIA issue is 100% legitimate. NIST is required to comply with FOIA.

You don’t get it clearly. They’re playing dirty. At best the FOIA will receive a document made on the fly with nothing of value. The rules don’t apply to the NSA. You can do exactly nothing. But NIST, you can do something about - reject any standard they approve. It’s your choice what algorithm you use, and we know NIST will select a broken algorithm for the NSA, so just ignore their ‘standard’. The best solution is using layers of crypto, trusting no single algorithm.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#293

Earlier quoted context omitted.

> ...but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. I agree with this. And I think that this is more likely to be the case. But I really think with all that we now know about US governmental organisations the possibility of backdoors or coercion should not be ruled out.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

"I think formal cryptographic standards are a force for evil."

May I ask what you view as the alternative? (No formal cryptographic standard, or something else?)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#294

Earlier quoted context omitted.

> ...but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. I agree with this. And I think that this is more likely to be the case. But I really think with all that we now know about US governmental organisations the possibility of backdoors or coercion should not be ruled out.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

> If they knew anything about who the PQC team members were, they'd shoot milk out their nose at the suggestion that NSA had suborned backdoors from them.

Please point to this suggestion.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#295
post #222

Earlier quoted context omitted.

First, last I checked, Filippo does not in fact work at Google. Second: the guidelines on this site forbid you to write comments like this; in fact, this pattern of comments is literally the most frequent source of moderator admonitions on HN. Filippo hardly needs me to defend his reputation, but, as a service to HN and to you in particular, I'd want to raise your awareness of the risk of beclowning yourself by sugge…

Quoted post unavailable.

It's funny how you think it's a mic drop that you didn't bother to check basic facts before attempting to defame someone by name, anonymous commenter.

I just told you this was a dumb hill to die on, but I can't stop you from commenting like this.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#296
post #240

Earlier quoted context omitted.

You said: > the motivation behind those requests is risible. It is quite hilarious that NIST suckered the industry into actually using Dual-EC, despite being worse than the other possible choices in nearly every respect. And this ignores the fact that the backdoor was publicly known for years . This actually happened; it’s not a joke. The motivation behind the FOIA requests is to attempt to see whether any funny busi…

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…

Not Dual EC, but ECDSA is used (by law) in EU smart tachograph systems for signing data.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#297

Earlier quoted context omitted.

Believing both "Don't roll your own crypto" and "Don't trust the standards" would seem to leave the average developer in something of a quandry, no?

No. I don't think we should rely on formal standards, like FIPS, NIST, and the IETF. Like Bernstein himself, I do think we should rely on peer-reviewed expert cryptography. I use Chapoly, not a stream cipher I concocted myself, or some bizarro cipher cascade posted to HN. This is what I'm talking about when I mentioned the Noise Protocol Framework. If IETF standards happen to end up with good cryptography because the…

I guess this is my point: If you have strong mathematicians and cryptographers, you don't end up using NIST.

There are lots of companies who have need for cryptography who don't know who to trust. What should they do in a world where the standards bodies are adversarial?

Maybe this is just the future, if you don't know crypto you're doomed to either do the research or accept that you're probably backdoored? Seems like a rough place to be...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#298

Earlier quoted context omitted.

The FOIA issue is 100% legitimate. NIST is required to comply with FOIA.

You don’t get it clearly. They’re playing dirty. At best the FOIA will receive a document made on the fly with nothing of value. The rules don’t apply to the NSA. You can do exactly nothing. But NIST, you can do something about - reject any standard they approve. It’s your choice what algorithm you use, and we know NIST will select a broken algorithm for the NSA, so just ignore their ‘standard’. The best solution is…

You should tell Bernstein that! Your logic implies he's wasting his time with the suit.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#299
post #294

Earlier quoted context omitted.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

> If they knew anything about who the PQC team members were, they'd shoot milk out their nose at the suggestion that NSA had suborned backdoors from them. Please point to this suggestion.

Reload the page, scroll to the top, and click the title, which will take you to the blog post we're commenting on, which makes the suggestion.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#300

Earlier quoted context omitted.

Look, my point is that there are lots of companies around the world who can’t afford highly skilled mathematicians and cryptographers on staff. These institutions rely on NIST to help them determine what encryption systems may make sense. If NIST is truly adversarial, the public has a right to know and determine how to engage going forward.

They don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.

I'm just saying, you're speaking as an expert in the field. Let's say you don't want to do design any of that stuff but you need some parts of those systems for the thing you're building. How do you decide what you can or can't trust without having deep knowledge of the subject matter?

Maybe that's it, maybe you can't?

Post reply on HN