Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

381–390 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#381

Earlier quoted context omitted.

Peer review and "informal standards". Good examples of things that were, until long after their widespread adoption, informal standards include Curve25519, Salsa20 and ChaCha20, and Poly1305. A great example of an informal standard that remains an informal standard despite near-universal adoption is WireGuard. More things like WireGuard. Less things like X.509.

Both formal and informal peer review are why I like the FOIA, and standards / competition discussion to be open in general. I actually dislike closed peer review, or at least without some sort of time-gated release. Likely scenarios, and that closed review hides: - Peer review happened... But was lame. Surprisingly common, and often the typical case. - If some discussion did come up on a likely attack... What? Was th…

You get that the most important "peer review" in the PQC contest took the form of published academic research, right? NIST doesn't even have the technical capability to do the work we're talking about. My understanding is that they refereed; they weren't the peer reviewers.

Replying to your edit I've been an academic peer reviewer too. For all of its weaknesses, that kind of peer review is the premise of the PQC contest --- indeed, it's the premise of pretty much all of modern cryptography.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#382

Earlier quoted context omitted.

I believe you have a very naive and trusting view of these US governmental bodies. I don't intend that to be an insult, but by now I think the jury is out that these agencies cannot be trusted (the NSA less so, than NIST).

I think it's naive and trusting only on the surface, but with some clear intent and goal underneath. In the past he has held a different stance, but it suddenly changed some time after Matasano.

Can I ask that, if you're going to accuse me of shilling in an HN thread, you at least come up with something that I'm shilling? I don't care what it is; you can say that I'm shilling for Infowars Life ProstaGuard Prostate Health Supplement with Saw Palmetto and Anti-Oxidant, for all I care, just identify something.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#383
post #353

Earlier quoted context omitted.

ECDSA is almost universally used. It's deeply suboptimal in a variety of ways. But that's because it was designed in the 1990s, not because it's backdoored. This isn't a new line of argumentation for Bernstein; he has also implied that AES is Rijndael specifically because it was so commonly implemented with secret-dependent lookups (S-boxes, in the parlance); he's counting on a lay audience not knowing the distinctio…

> he's counting on a lay audience not knowing the distinction between an engineering principle mostly unknown at the time something was designed, and a literal backdoor. When you discount his theories with that argument, your own reductio ad Lizardum (?) doesn’t help. There’s a world of distinction between NSA inserting backdoors, for which there’s good evidence but maybe not every time, and whatever you’re trying to…

You haven't explained how my argument discounts his theories. You're just unhappy that I used the term "Lizard People". Ok: I retract "Lizard People". Where does that leave your argument?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#384

Earlier quoted context omitted.

I'm not sure I'd use the same words, but yeah, the argument I'm refusing to dignify is that NSA could have been successful at bribing a member of one of the PQC teams. Like, what is that bribed person going to do? Look at the teams; they're ridiculously big. It doesn't even make sense. Again: part of my dismissiveness comes from how clear it is that Bernstein is counting on his cheering section not knowing any of thi…

One trivial example implied by the blog post: Such corruption could be involved in the non-transparent decision making process at NIST. Regarding Dual_EC: we still lack a lot of information about how this decision was made internally at NIST. That’s a core point: transparency was promised in the wake of discovered sabotage and it hasn’t arrived.

What do you mean, "how" the decision about Dual EC was made? It's an NSA-designed backdoor. NIST standardized it because NSA told them to. I'm sure NSA told NIST a story about why it was important to standardize it. The Kremlinology isn't interesting: it is NSA's chartered job to break cryptography, and nobody should ever trust them; the only thing NSA can do to improve cryptography is to literally publish secret attacks, and they're not going to do that.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#385
post #207
post #168

Earlier quoted context omitted.

Why? Http is simpler, less fragile, not dependent on good will of third parties, the content is public, and proving authenticity of text on Internet is always hard, even when served via the https scheme. I bet Bernstein thinks there is little point in forcing people to use https to read his page.

That's just wrong on so many levels. Troy Hunt has an excellent explanation: https://www.troyhunt.com/heres-why-your-static-website-needs...

Troy Hunt points out that HTTP traffic is sometimes MITMed in a way that clients and servers do not like, and HTTPS sometimes prevents that. I never said otherwise. I am saying for certain kinds of pages, it's not a major concern. Like for djb website.

Why not use HTTPS for everything? Because it also has costs, not just benefits.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#386
post #228

Perhaps the best way to build trust in a cryptographic algorithm is to have it devised by certifiably neutral general purpose mathematic neural net. It could even generate an algorithm so complicated it would be close to impossible for a human mind to comprehend the depth of it.

> It could even generate an algorithm so complicated it would be close to impossible for a human mind to comprehend the depth of it.

Okay... then some nefarious actor's above-human-intelligence neural network instantly decodes the algorithm deemed too complicated for human understanding?

I don't see how opaque neural nets are suddenly going to make security-through-obscurity work.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#387

Why is the link in the URL http: not https: ? Irony?

If you spend all day making bagels do you go home and make bagels for dinner? It's a static text blog, not a bank

See: "Here's Why Your Static Website Needs HTTPS" by Troy Hunt

https://www.troyhunt.com/heres-why-your-static-website-needs...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#389

Earlier quoted context omitted.

That person is very well known in this community, and in other communities as well. They are also known for making very specific arguments that people misinterpret and fight over, but the actual intent and literal meaning of the statements is most often correct (IMO). Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expo…

If that is the case, then what is the explanation for NIST (according to DJB) 1. not communicating their decision process to anywhere near the degree that they vowed to, and 2. stone-walling a FOIA request on the matter? > Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expose those that are a combination of careless wi…

The explanation for the FOIA process is that public bodies routinely get intransigent about FOIA requests and violate the statutes. Read upthread: I have worked with Bernstein's FOIA attorneys before. Like everyone else, I support the suit, even as I think it's deeply silly for Bernstein to equate it to Bernstein v US.

If you made me guess about why NIST denied his FOIA requests, I'd say that Bernstein probably royally pissed everyone at NIST off before he made those requests, and they denied them because they decided the requests were being made in bad faith.

But they don't get to do that, so they're going to be forced to give up the documents. I'm sure when that happens Bernstein will paint it as an enormous legal victory, but the fact is that these outcomes are absolutely routine.

When we were FOIA'ing the Police General Orders for all the suburbs of Chicago, my own municipality declined to release theirs. I'd already been working with Topic on a (much more important) FOIA case from a friend of mine, so I reached out asking for him to write a nastygram for me. The nastygram cost me money --- but he told me having him sue would not! It was literally cheaper for me to have him sue my town than to have him write a letter, because FOIA suits have fee recovery terms.

I really can't emphasize enough how much suing a public body to force compliance with FOIA is just a normal part of the process. It sucks! But it's utterly routine.

Post reply on HN