Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

301–310 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#301
post #293

Earlier quoted context omitted.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

"I think formal cryptographic standards are a force for evil." May I ask what you view as the alternative? (No formal cryptographic standard, or something else?)

Peer review and "informal standards". Good examples of things that were, until long after their widespread adoption, informal standards include Curve25519, Salsa20 and ChaCha20, and Poly1305. A great example of an informal standard that remains an informal standard despite near-universal adoption is WireGuard. More things like WireGuard. Less things like X.509.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#302

Earlier quoted context omitted.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Is that even a claim here? I'm on mobile right now so it's a bit hard for me to trawl through the DJB/NIST dialogue, but I thought his main complaint is that NIST didn't appear to have a proper and clear process for choosing the algorithms they did, when arguably better algorithms were available.…

It is indeed a claim here; in fact, it's probably the principle claim.

The actual claim is that NSA may have already spent a lot of time and effort to analyse PQC algorithm underlying problems without making their findings public.

DJB seems to suspect that they may influence NIST to select algorithms and parameters within the range of what they already know how to break.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#303

Earlier quoted context omitted.

> ...but I can easily imagine NIST committees not understanding something, being tricked, not looking closely, protecting big orgs by default (without maliciousness), and overall being sloppy. I agree with this. And I think that this is more likely to be the case. But I really think with all that we now know about US governmental organisations the possibility of backdoors or coercion should not be ruled out.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

My reading wasn't that he thinks they built backdoors into them, but that the NSA might be aware of weaknesses in some of them, and be trying to promote the algorithms they know how to break.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#304

Earlier quoted context omitted.

They don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.

I'm just saying, you're speaking as an expert in the field. Let's say you don't want to do design any of that stuff but you need some parts of those systems for the thing you're building. How do you decide what you can or can't trust without having deep knowledge of the subject matter? Maybe that's it, maybe you can't?

How do you know that Noise is a good design and that a cipher cascade isn't? Whatever (correctly) told you that, apply it to other cryptographic problems.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#305

Earlier quoted context omitted.

No. I don't think we should rely on formal standards, like FIPS, NIST, and the IETF. Like Bernstein himself, I do think we should rely on peer-reviewed expert cryptography. I use Chapoly, not a stream cipher I concocted myself, or some bizarro cipher cascade posted to HN. This is what I'm talking about when I mentioned the Noise Protocol Framework. If IETF standards happen to end up with good cryptography because the…

I guess this is my point: If you have strong mathematicians and cryptographers, you don't end up using NIST. There are lots of companies who have need for cryptography who don't know who to trust. What should they do in a world where the standards bodies are adversarial? Maybe this is just the future, if you don't know crypto you're doomed to either do the research or accept that you're probably backdoored? Seems lik…

So use whatever crypto Signal uses, or that WireGuard uses. You're not working in a vacuum. You don't even trust NIST to begin with, and yet we still encrypt things, so I'm a little confuddled by the argument that NIST's role as a trusted arbiter of cryptography is vital to our industry. NIST is mostly a force for evil!

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#306

Earlier quoted context omitted.

Trump Card: National Security

That's a valid reason (specifically, 1.4(g) listed at https://www.archives.gov/declassification/iscap/redaction-co... ). And while the NIST returning such a response is possible, it goes against the commitment to transparency. But still, that requires a response, and there hasn't been one.

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#307

Earlier quoted context omitted.

It is indeed a claim here; in fact, it's probably the principle claim.

The actual claim is that NSA may have already spent a lot of time and effort to analyse PQC algorithm underlying problems without making their findings public. DJB seems to suspect that they may influence NIST to select algorithms and parameters within the range of what they already know how to break.

Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a cooked spaghetti noodle is that he actually stoops to suggesting that NSA might have bribed one of the members of the PQC teams.

If he had something real to say, he wouldn't have embarrassed himself like that. How I think I know that is, I think any reasonable person would go way out of their way to avoid such an embarrassing claim, absent extraordinary evidence, of which he's presented none.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#308

Tangential question: while some FOIA requests do get stonewalled, I continue to be fascinated that they're honored in other cases. What exactly prevents the government from stonewalling practically every request that it doesn't like, until and unless it's ordered by a court to comply? Is there any sort of penalty for their noncompliance? Tangential to the tangent: is there any reason to believe FOIA won't be on the c…

I know someone who works in gov (Australia, not US) who told me all about a FOI request that he was stonewalling. From memory, the request was open ended and would have revealed more than it possibly intended it to, and would have revealed some proprietary trade secrets from a third party contractor. That said, it was probably a case that would attract some public interest. The biggest factors preventing governments…

At least in Australia I gather it it somewhat common for FOI offices to work with an FOI applicant to ask them to narrow the request if it is so broad as to cost too much or take too long to process, or is likely to just to be returned as hundreds of black pages.

Previous FOI responses show more savvy FOI applicants in the past have also (when they don't get the outcome they desired):

1. Formally requested review of decisions to withhold information from release. This almost always lead to more information being released.

2. Waited and tried requesting the same or similar information again in a later year when different people are involved.

3. Sent a follow up FOIA request for correspondence relating to how a previous (or unanswered) request was or is being processed by the FOI office and other parties responding to the request. This has previously shown somewhat humorous interactions with FOI offices such as "We're not going to provide that information because {lame excuse}" vs FOI office "You have to. CC:Executives" vs "No" vs Executives "It's not your information" etc etc.

4. Sent a follow up FOIA request for documentation, policies, training material and the likes for how FOI requests are assessed as well as how and by whom decisions are made to release or withhold information.

5. Sent a follow up FOIA request for documentation, policies, staffing levels, budgets, training material and the likes for how a typical event that the original FOIA request referred to would be handled (if details of a specific event are not being provided).

Responses to (2), (3) and (4) are probably more interesting to applicants than responses to (1), (2) and original requests, particularly when it is clear the applicant currently or previously has knowledge of what they're requesting.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#309
post #296

Earlier quoted context omitted.

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…

Not Dual EC, but ECDSA is used (by law) in EU smart tachograph systems for signing data.

ECDSA is almost universally used. It's deeply suboptimal in a variety of ways. But that's because it was designed in the 1990s, not because it's backdoored. This isn't a new line of argumentation for Bernstein; he has also implied that AES is Rijndael specifically because it was so commonly implemented with secret-dependent lookups (S-boxes, in the parlance); he's counting on a lay audience not knowing the distinction between an engineering principle mostly unknown at the time something was designed, and a literal backdoor.

What's annoying is that he's usually right, and sometimes even right in important new ways. But he runs the ball way past the end zone. Almost everybody in the field agrees with the core things he's saying, but almost nobody wants to get on board with his wild-eyed theories of how the suboptimal status quo is actually a product of the Lizard People.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#310
Why don’t we invert FOIA?

Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and to allow a private cause of action for citizens and waiver of immunity for bureaucrats.

We could carve out (or maybe not) specific things like allowing automatic redaction of employee PII and PII of citizens receiving government benefits.

After many decades, it’s clear that the current approach to FOIA and sunshine laws just isn’t working.

[ed] fixed autocorrect error

Post reply on HN