Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

351–360 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#351

Earlier quoted context omitted.

The person is saying one thing then denying saying that thing and being a jerk about it. Either a bot or someone with a broken thesaurus. Glad you pointed it out because it’s ridiculous/risible.

That person is very well known in this community, and in other communities as well. They are also known for making very specific arguments that people misinterpret and fight over, but the actual intent and literal meaning of the statements is most often correct (IMO). Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expo…

If that is the case, then what is the explanation for NIST (according to DJB) 1. not communicating their decision process to anywhere near the degree that they vowed to, and 2. stone-walling a FOIA request on the matter?

> Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expose those that are a combination of careless with their reading and willing to make assumptions rather than ask questions is unknown to me

Communicating badly and then acting smug when misunderstood is not cleverness (https://xkcd.com/169/).

If many people do not understand the argument being made, it doesn't matter how "exacting" the language is - the writer failed at communicating. I don't have a stake in this, but from afar this thread looks like tptacek making statements so terse as to be vague, and then going "Gotcha! That's not the right interpretation!" when somebody attempts to find some meaning in them.

In short: If standard advice is "you should ask questions to understand my point", you're doing it wrong. This isn't "HN gathers to tease wisdom out of tptacek" - it's on him to be understood by the readers (almost all of which are lurkers!). Unless he doesn't care about that, but only about shouting (what he thinks are) logically consistent statements into the void.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#352
I have the feelings the govs around the world get more and more sued related to serious digital matters. Here, once the heat wave is finally over, I will see again my lawyer about the interoperability of gov related sites with noscript/basic (x)html browsers.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#353
post #296

Earlier quoted context omitted.

Not Dual EC, but ECDSA is used (by law) in EU smart tachograph systems for signing data.

ECDSA is almost universally used. It's deeply suboptimal in a variety of ways. But that's because it was designed in the 1990s, not because it's backdoored. This isn't a new line of argumentation for Bernstein; he has also implied that AES is Rijndael specifically because it was so commonly implemented with secret-dependent lookups (S-boxes, in the parlance); he's counting on a lay audience not knowing the distinctio…

> he's counting on a lay audience not knowing the distinction between an engineering principle mostly unknown at the time something was designed, and a literal backdoor.

When you discount his theories with that argument, your own reductio ad Lizardum (?) doesn’t help. There’s a world of distinction between NSA inserting backdoors, for which there’s good evidence but maybe not every time, and whatever you’re trying to paint his theory as by invoking the Lizard People.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#354

Earlier quoted context omitted.

Memory and experience aren't encoded in the brain like traditional computers. There's no concept of a "byte" when thinking about the human computational model.

There is the concept of "byte" when talking about a string of characters which make up a password, though, which is why I said bytes. But yes, I am aware, and your statement just further supports my point.

Not necessarily. A person could remember a password that contains name of their loved one differently in their brain than some arbitrary string of letters and numbers. Those letters and numbers can each be "encoded" differently in their brain - e.g. maybe the letter 'S' is linked in their brain to snakes because it kind of looks like one. Or any kind of weird connections of certain parts of the password to a smell they smelled twenty years ago. This would all deeply affect how the actual string of character is actually "stored" in the brain.

Yes, after you'd extract the password from their brain, you would then convert it to a string of bytes and store it on your digital storage device, but you were talking about accessing data in a human brain.

The point is, human brain is weird when looked at from point of view of data storage. :)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#355
post #310

Why don’t we invert FOIA? Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and…

The carve-out you mention is a decent idea on paper, but in practice is a difficult process. There's really no way to do it in any significant degree without basically putting all gov to a complete halt. Consider that government is not staffed with technical people, nor necessarily critically minded people to implement these systems.

There are ways to push for FOIA improvements that don't require this sort of drastic approach. Problem is, it takes a lot of effort on the parts of FOIA requesters, through litigation and change in the laws. Things get surprisingly nuanced when you really get down into what a "record" is, specifically for digital information. I definitely wouldn't want to have "data" open by default in this manner, because it would lead to privacy hell.

Another component of this all is to consider contractors and subcontractors. Would they fall under this? If so, to what degree? If not, how do we prevent laundering of information through contractors/subcontractors?

To a large degree, a lot of "positive" transparency movements like the one you suggest can ironically lead to reduced transparency in some of the more critical sides of transparency. A good example of that is "open data", which gives an appearance of providing complete data, but without the legal requirements to enforce it. Makes gov look good but it de-incentivizes transparency pushback and there's little way to identify whether all relevant information is truly exposed. I would imagine similar would happen here.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#356
post #310

Why don’t we invert FOIA? Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and…

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#357
post #310

Why don’t we invert FOIA? Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and…

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#358
post #273

Earlier quoted context omitted.

a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion

Where? If you RTFA you'd know it pertains to bribery, not coercion.

To quote the article:

At the risk of belaboring the obvious: An attacker won't have to say "Oops, researcher X is working in public and has just found an attack; can we suppress this somehow?" if the attacker had the common sense to hire X years earlier, meaning that X isn't working in public. People arguing that there can't be sabotage because submission teams can't be bribed are completely missing the point.

He goes on to say: I coined the phrase "post-quantum cryptography" in 2003. It's not hard to imagine that the NSA/IDA post-quantum attack team was already hard at work before that, that they're years ahead of the public in finding attacks, and that NSA has been pushing NISTPQC to select algorithms that NSA secretly knows how to break.

Does this seem unreasonable, and if so, why?

He also remarks: Could such a weakness also be exploited by other large-scale attackers? Best bet is that the answer is yes. Would this possibility stop NSA from pushing for the weakness? Of course not.

Doesn’t sound to me like he only has concerns about bribery. Corruption of the standards to NSA’s benefit is one overarching issue. It’s not the only one, he has concerns about non-American capabilities as well.

The are many methods for the NSA to achieve a win.

Ridiculing people for worrying about this is totally lame and is harmful to the community.

To suggest a few dozen humans are beyond reproach from attack by the most powerful adversaries to ever exist is extremely naive at best. However that literally isn’t even a core point as Bernstein notes clearly.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#359

Earlier quoted context omitted.

I guess this is my point: If you have strong mathematicians and cryptographers, you don't end up using NIST. There are lots of companies who have need for cryptography who don't know who to trust. What should they do in a world where the standards bodies are adversarial? Maybe this is just the future, if you don't know crypto you're doomed to either do the research or accept that you're probably backdoored? Seems lik…

So use whatever crypto Signal uses, or that WireGuard uses. You're not working in a vacuum. You don't even trust NIST to begin with, and yet we still encrypt things, so I'm a little confuddled by the argument that NIST's role as a trusted arbiter of cryptography is vital to our industry. NIST is mostly a force for evil!

Signal’s crypto doesn’t solve all problems (neither does wireguard).

For example, we built private information recovery using the first production grade open source implementation of oblivious RAM (https://mobilecoin.com/overview/explain-like-i'm-five/fog you’ll want to skip to the software engineer section) so that organizations could obliviously store and recover customer transactions without being able to observe them. The signal protocol’s techniques might be part of a cryptographic solution but it is not a silver-bullet.

I guess, notably, we never looked at NIST when designing it so maybe that’s the end of the discussion there.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#360

Earlier quoted context omitted.

I'm just saying, you're speaking as an expert in the field. Let's say you don't want to do design any of that stuff but you need some parts of those systems for the thing you're building. How do you decide what you can or can't trust without having deep knowledge of the subject matter? Maybe that's it, maybe you can't?

How do you know that Noise is a good design and that a cipher cascade isn't? Whatever (correctly) told you that, apply it to other cryptographic problems.

I see. So maybe what you’re really saying is “why are you writing a system that has cryptographic primitives if you’re not a cryptographer/mathematician?”
Post reply on HN