Earlier quoted context omitted.
So use whatever crypto Signal uses, or that WireGuard uses. You're not working in a vacuum. You don't even trust NIST to begin with, and yet we still encrypt things, so I'm a little confuddled by the argument that NIST's role as a trusted arbiter of cryptography is vital to our industry. NIST is mostly a force for evil!
Signal’s crypto doesn’t solve all problems (neither does wireguard). For example, we built private information recovery using the first production grade open source implementation of oblivious RAM ( https://mobilecoin.com/overview/explain-like-i'm-five/fog you’ll want to skip to the software engineer section) so that organizations could obliviously store and recover customer transactions without being able to observe…
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
371–380 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#372Earlier quoted context omitted.
> he actually stoops to suggesting that NSA might have bribed one of the members of the PQC teams I don't know anyone in the teams to judge their moral fiber, but I'm 100% sure the NSA is not above what is suggested and your weird outrage at the suggestion seems surprising knowing what is public knowledge about how the NSA operates. There are arguments here about NSA pressure on NIST. You miss the point because appar…
It can be everybody involved. It should include NIST based on the history alone. Some of the commentary on this topic is by people who also denied DUAL_EC until (correctly) conceding that it was actually a backdoor, actually deployed, and that it is embarrassing for both NSA and NIST. This sometimes looks like reactionary denialism. It’s a safe position that forces others to do a lot of work, it seems good faith with…
I'm honest about what I'm saying and what I've said. You are not meeting the same bar. For instance, here you're insinuating that my problem on this thread is that I think NIST is good, or trustworthy, or that NSA would never have the audacity to try to bribe anybody. Of course, none of that is true.
I don't know how seriously you expect anybody to take you. You wrote 13-paragraph comment on this thread based on Filippo's use of an "It's Always Sunny In Philadelphia Meme", saying that it was a parody of "A Beautiful Mind", which is about John Nash, who was mentally ill, and also an anti-semite, ergo Filippo Valsorda is an anti-semite who punches down at the mentally ill. It's right there for everybody to read.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#373Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#374Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#375Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#376Earlier quoted context omitted.
Two things can easily be true: that NIST mishandled a FOIA request, and that there isn't especially good reason to accept on faith Bernstein's concerns about the PQC process, which is unrelated to how they handle FOIA. Meanwhile: you haven't actually added any light to this subthread: the tweets we're talking about do not dismiss the suit. Cryptographic researchers that aren't stans of Daniel Bernstein (there are a l…
I am definitely not in that place. We clearly disagree on a few points. The issues raised in the blog post aren’t just about NIST mishandling the FOIA. By reducing it to the lawsuit, this is already a bad faith engagement. The blog post is primarily about the history of NSA sabotage as well as contemporary efforts, including (NIST’s) failures to stop this sabotage. Finally it finishes the recent history by raising th…
This right here is a comment that makes the following argument, which I will helpfully outline:
* Filippo Valsorda wrote a tweet that included a meme from "It's Always Sunny In Philadelphia"
* That meme is a parody of "A Beautiful Mind"
* "A Beautiful Mind" is about John Nash --- hold on to that fact, because the argument is about to bifurcate
* John Nash was mentally ill
* John Nash was virulently anti-semitic (hold on to your butts...)
* Ergo, Filippo Valsorda is both bigoted against the mentally ill, and also an anti-semite.
Can we do other memes like this? I'd like your exegesis of the "Homer Simpson dissolves backwards into the hedges" meme next!
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#377Earlier quoted context omitted.
I don't think it's a bad thing to push back and demand transparency. At the very least the pressure helps keep NIST honest. Keep reminding them over and over and over again about dual-EC and they're less likely to try stupid stuff like that again.
Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#378Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#379Earlier quoted context omitted.
"I think formal cryptographic standards are a force for evil." May I ask what you view as the alternative? (No formal cryptographic standard, or something else?)
Peer review and "informal standards". Good examples of things that were, until long after their widespread adoption, informal standards include Curve25519, Salsa20 and ChaCha20, and Poly1305. A great example of an informal standard that remains an informal standard despite near-universal adoption is WireGuard. More things like WireGuard. Less things like X.509.
Likely scenarios, and that closed review hides:
- Peer review happened... But was lame. Surprisingly common, and often the typical case.
- If some discussion did come up on a likely attack... What? Was the rebuttal and final discussion satisfactory?
It's interesting if some gov team found additional things... But I'm less worried about that, they're effectively just an 'extra' review committee. Though as djb fears, a no-no if they ask to weaken something... And hence another reason it's good for the history of the alg to be public.
Edit: Now that storage and video are cheap, I can easily imagine a shift to requiring all emails + meetings to be fully published.
Edit: I can't reply some reason, but having been an academic reviewer, including for security, and won awards for best of year/decade academic papers, I can say academic peer review may not be doing what most people think, eg, it is often more about novelty and trends and increments from a 1 hour skim. Or catching only super obvious things outsiders and fresh researchers mess up on. Very diff from say a yearlong $1M dedicated pentest. Which I doubt happened. It's easy to tell which kind of review happened when reading a report... Hence me liking a call for openness here.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#380Earlier quoted context omitted.
Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…
Thank you for actually explaining your POV. I don't understand how you expected me or the other commenters to gather this from your original comment. If it's worth anything, you have changed my opinion on this. You raise very good points.
I spent almost 2 decades as a Daniel Bernstein ultra-fan --- he's a hometown hero, and also someone whose work was extremely important to me professionally in the 1990s, and, to me at least, he has always been kind and cheerful; he even tried to give us some ideas for ECC challenges for Cryptopals. I know what it's like to be in the situation of (a) deeply admiring Bernstein and (b) only really paying attention to one cryptographer in the world (Bernstein).
But talk to a bunch of other cryptographers --- and, also, learn about the work a lot of other cryptographers are doing --- and you're going to hear stories. I'm not going to say Bernstein has a bad reputation; for one thing, I'm not qualified to say that, and for another I don't think "bad" is the right word. So I'll put it this way: Bernstein has a fucked up reputation in his field. I am not at all happy to say that, but it's true.