Earlier quoted context omitted.
Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…
My reading wasn't that he thinks they built backdoors into them, but that the NSA might be aware of weaknesses in some of them, and be trying to promote the algorithms they know how to break.
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
391–400 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#392Earlier quoted context omitted.
While I am skeptical of US domestic surveillance, Snowden leaked this information in the worst possible way. Try internal whistleblower channels first. Not being heard? Mail to members of Congress? Contact congress? Contact the media? Instead he fled to an adversary with classified material. That's not good faith behavior imo. Traitor
Regarding trying internal channels, Snowden says he tried this > despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deep…
There is no record that he attempted to use internal channels. He would have been afforded whistleblower protection had he went to Congress with his findings.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#393Earlier quoted context omitted.
a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion
It's a fun word, right? "Risible"? I chose it carefully, though.
https://youtu.be/kx_G2a2hL6U?t=177
(I don't have anything constructive to add to the conversation. ¯\_(ツ)_/¯ )
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#394Earlier quoted context omitted.
Your augment that the selection doesn’t pick his designs doesn’t square with SPHINCS+ winning, and with others remaining in the running. His former PhD student won with Kyber. Bernstein did very well here and you’re misleading people by suggesting he had his ass handed to him. He has published (and it is linked from the blog) his views on how to run cryptographic contests before their recent selection finished (late)…
I didn't even notice a "punching down about mental health" thing. You wrote a long comment, I skimmed it. Your allegation that Filippo and Matt Green are antisemitic is ludicrous. I didn't say Bernstein had his ass handed to him. I said that he wrote thousands and thousands of words about his reasons to mistrust NIST (not just here but elsewhere, and often), but still participated in the PQC contest, raising these co…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#395Earlier quoted context omitted.
The actual claim is that NSA may have already spent a lot of time and effort to analyse PQC algorithm underlying problems without making their findings public. DJB seems to suspect that they may influence NIST to select algorithms and parameters within the range of what they already know how to break.
Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a coo…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#396Earlier quoted context omitted.
Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a coo…
Quoted post unavailable.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#397Earlier quoted context omitted.
Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…
It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#398Earlier quoted context omitted.
Where? If you RTFA you'd know it pertains to bribery, not coercion.
To quote the article: At the risk of belaboring the obvious: An attacker won't have to say "Oops, researcher X is working in public and has just found an attack; can we suppress this somehow?" if the attacker had the common sense to hire X years earlier, meaning that X isn't working in public. People arguing that there can't be sabotage because submission teams can't be bribed are completely missing the point. He goe…
I use djb’s crypto. Everybody knows his speculation. Everybody knows why he’s pursuing more information. Nobody disagrees more information would be a public good. Some people are more skeptical than others that he’ll find anything substantial.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#399Earlier quoted context omitted.
One says he’s doing it wrong. The other says he hopes that he wins, of course! Meanwhile they go on to attack Bernstein, mischaracterize his writing, completely dismiss his historical analysis, mock him with memes as a conspiracy theorist, and to top it off they question his internal motivations (which they somehow know) as some kind of a sore loser which is demonstrably false. The plot twist for the last point: he i…
Two things can easily be true: that NIST mishandled a FOIA request, and that there isn't especially good reason to accept on faith Bernstein's concerns about the PQC process, which is unrelated to how they handle FOIA. Meanwhile: you haven't actually added any light to this subthread: the tweets we're talking about do not dismiss the suit. Cryptographic researchers that aren't stans of Daniel Bernstein (there are a l…
Can you comment on why you think djb thinks it is worth investigating if the NSA is attempting to destroy cryptography with weak pqc standards? I read through some of the entries NIST just announced and there are indeed attacks, grave attacks, that exist against Kyber and Falcon. I have no reason to believe the authors of those specs work with the NSA. Wouldn't a more reasonable conclusion be that we need to do more work on pqc? Maybe I have it wrong and he is just trying to rule out that possibility but his long rant which was 80% about NIST and their history with the dual EC backdoor really points at djb concluding the NSA is deliberately trying to weaken crypto by colluding with a bunch of people who probably don't care about money or the NSA's goals that much.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#400Earlier quoted context omitted.
It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…
I don't think Juniper used BSAFE in ScreenOS -- they seem to have put together their own Dual EC implementation on top of OpenSSL, sometime around 2008. (This doesn't change your point, of course.)