Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

361–370 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#361

Earlier quoted context omitted.

The actual claim is that NSA may have already spent a lot of time and effort to analyse PQC algorithm underlying problems without making their findings public. DJB seems to suspect that they may influence NIST to select algorithms and parameters within the range of what they already know how to break.

Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a coo…

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#362

Earlier quoted context omitted.

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I think it's naive and trusting only on the surface, but with some clear intent and goal underneath. In the past he has held a different stance, but it suddenly changed some time after Matasano.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#363
My background is in normal, enterprise-saas-style software development projects, and the whole notion of post-quantum crypto kind of baffles me.

Funnily enough, this post coincides with the release of a newsletter issue[0] by a friend of mine - unzip.dev - about lattice-based cryptography.

A bit of a shameless plug, but it really is a great bit of intro for noobs in the area like myself.

[0] https://unzip.dev/0x00a-lattice-based-cryptography/

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#364
post #228

Perhaps the best way to build trust in a cryptographic algorithm is to have it devised by certifiably neutral general purpose mathematic neural net. It could even generate an algorithm so complicated it would be close to impossible for a human mind to comprehend the depth of it.

"Certifiably neutral" So, by a process that hasn't been designed yet. Especially when one considers how opaque most neutral nets are to human scrutiny.

I mean, if the source, training data, and query interface are public, it would be insanely difficult to hide a backdoor

There i "designed" your impossible criterion in just a few obvious steps you could have inferred

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#365
post #312

Earlier quoted context omitted.

It's just a vanilla FOIA lawsuit, of the kind hundreds of people file every month when public bodies fuck up FOIA. If NIST puts up any kind of fight (I don't know why they would), it'll be fun to watch Matt and Wayne, you know, win a FOIA case. There's a lot of nerd utility in knowing more about how FOIA works! But you're not going to get the secrets of the Kennedy assassination by reading this thing.

I will draw to your attention two interesting facts. First, OpenSSH has disregarded the winning (crystals) variants, and implemented hybrid NTRU-Prime. The Bernstein blog post discusses hybrid designs. "Use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired…

It's not the first time either and it won't be the last. NIST chose Rijndael over Serpent for the AES standard even though Serpent won. I vaguely recall they gave some smarmy answer. I don't think anyone submitted a FOIA not that it would matter. I've been through that bloated semi-pseudo process and saw how easy it was to stall people not answer a simple question.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#366

Earlier quoted context omitted.

There's nothing "bad faith" about it. The tweet is supportive of the lawsuit, and not supportive of Bernstein's weird, heavily-telegraphed, long-predicted claims that a NIST contest he opted to participate in was corrupted by dint of not prioritizing his own designs. Your bit about the "obviously Jewish family name" thing is itself risible, and you should be embarrassed for trying to make it a thing.

Your augment that the selection doesn’t pick his designs doesn’t square with SPHINCS+ winning, and with others remaining in the running. His former PhD student won with Kyber. Bernstein did very well here and you’re misleading people by suggesting he had his ass handed to him. He has published (and it is linked from the blog) his views on how to run cryptographic contests before their recent selection finished (late)…

I didn't even notice a "punching down about mental health" thing. You wrote a long comment, I skimmed it. Your allegation that Filippo and Matt Green are antisemitic is ludicrous.

I didn't say Bernstein had his ass handed to him. I said that he wrote thousands and thousands of words about his reasons to mistrust NIST (not just here but elsewhere, and often), but still participated in the PQC contest, raising these concerns only at its conclusion.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#367

Earlier quoted context omitted.

What are the aims of the lawsuit? NIST fucked up a FOIA response. The thing you do when a public body gives you an unsatisfactory FOIA response is that you sue them. I've been involved in similar suits. I'd be surprised if NIST doesn't just cough up the documents to make this go away. "Can NIST's decisions on crystals be overturned by the court?" Let me help you out with that: no, you can't use a FOIA suit to "overtu…

I assume that the point was that NSA is against using hybrid algorithms like the one used by OpenSSH, which combine a traditional algorithm with a post-quantum algorithm, arguing that using both algorithms is an unnecessary complication. The position of D. J. Bernstein and also of the OpenSSH team is that the prudent approach is to use only hybrid algorithms until enough experience is gained with the post-quantum alg…

Fucking everybody's position is to combine classical key exchanges with PQC KEMs. It wasn't NIST's job to standardize a classical+PQC construction. The point of the contest is to figure out which PQC constructions to use. NIST also didn't recommend that everyone implement their cryptographic handshakes in a memory-safe language. But not doing that is going to get a bunch of people owned by NSA too. Do you see how silly this argument is?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#368
post #195
post #168

Earlier quoted context omitted.

Why? Http is simpler, less fragile, not dependent on good will of third parties, the content is public, and proving authenticity of text on Internet is always hard, even when served via the https scheme. I bet Bernstein thinks there is little point in forcing people to use https to read his page.

MITM could change what the client receives, right?

Yes. But if you worry about being a target for MITM attacks, https alone does not fix that problem. You need some reliable verification mechanism that is hard to fool. The current CA system or "trust on first use" are only partial, imperfect mechanisms.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#369

Earlier quoted context omitted.

How do you know that Noise is a good design and that a cipher cascade isn't? Whatever (correctly) told you that, apply it to other cryptographic problems.

I see. So maybe what you’re really saying is “why are you writing a system that has cryptographic primitives if you’re not a cryptographer/mathematician?”

No, that is not at all what I am saying.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#370
post #323

Earlier quoted context omitted.

I don't think you understand what's going on here. The point of the PQC "contest" is to figure out which PQC constructions to use. It's not to design hybrid classical/PQC schemes: everybody already knows how to do that. The idea that NIST should have recommended CRYSTALS-Kyber+Curve25519 is a little like suggesting that they should have recommended Rijndael+DES-EDE. It's simply not NIST's job to tell tls-wg how to fi…

That would make it seem that the lengthy hybrid discussion in the blog is a misdirection. I will grant you that this does support your argument. EDIT: Actually, what you have said does not seem at all correct. In DJB's Apon complaint, we find this text: 'For example, in email to pqc-forum dated 30 Oct 2019 15:38:10 +0000 (2019), NIST posted technical comments regarding hybrid encryption modes and asked for feedback “…

Look, I'm just not going to dignify the argument that there is somehow some controversy over the NIST PQC contest not recommending higher-level constructions to plug PQC KEMs into Curve25519 key exchanges. I get that this seems like a super interesting controversy to you, because Bernstein's blog post is misleading you, but this simply isn't a real controversy.
Post reply on HN