Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

391–400 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#391
post #303

Earlier quoted context omitted.

Even when you're trying to be charitable, you're wildly missing the point. I don't give a fuck about NIST or NSA. I don't trust either of them and I don't even buy into the premise of what NIST is supposed to be doing: I think formal cryptographic standards are a force for evil. The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the…

My reading wasn't that he thinks they built backdoors into them, but that the NSA might be aware of weaknesses in some of them, and be trying to promote the algorithms they know how to break.

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#392

Earlier quoted context omitted.

While I am skeptical of US domestic surveillance, Snowden leaked this information in the worst possible way. Try internal whistleblower channels first. Not being heard? Mail to members of Congress? Contact congress? Contact the media? Instead he fled to an adversary with classified material. That's not good faith behavior imo. Traitor

Regarding trying internal channels, Snowden says he tried this > despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deep…

https://www.congress.gov/congressional-report/114th-congress...

There is no record that he attempted to use internal channels. He would have been afforded whistleblower protection had he went to Congress with his findings.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#393

Earlier quoted context omitted.

a risible distinction- a cursory reading of the article will reveal that bribery was only brought forth as an example of coercion

It's a fun word, right? "Risible"? I chose it carefully, though.

Michael Palin in Monty Python's Life of Brian, "Do you find it... risible?"

https://youtu.be/kx_G2a2hL6U?t=177

(I don't have anything constructive to add to the conversation. ¯\_(ツ)_/¯ )

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#394

Earlier quoted context omitted.

Your augment that the selection doesn’t pick his designs doesn’t square with SPHINCS+ winning, and with others remaining in the running. His former PhD student won with Kyber. Bernstein did very well here and you’re misleading people by suggesting he had his ass handed to him. He has published (and it is linked from the blog) his views on how to run cryptographic contests before their recent selection finished (late)…

I didn't even notice a "punching down about mental health" thing. You wrote a long comment, I skimmed it. Your allegation that Filippo and Matt Green are antisemitic is ludicrous. I didn't say Bernstein had his ass handed to him. I said that he wrote thousands and thousands of words about his reasons to mistrust NIST (not just here but elsewhere, and often), but still participated in the PQC contest, raising these co…

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#395

Earlier quoted context omitted.

The actual claim is that NSA may have already spent a lot of time and effort to analyse PQC algorithm underlying problems without making their findings public. DJB seems to suspect that they may influence NIST to select algorithms and parameters within the range of what they already know how to break.

Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a coo…

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#396

Earlier quoted context omitted.

Huh? Of course NSA spent a lot of time and effort analyzing algorithms without making their findings public. That is their literal job. The peer review NIST is refereeing happened in the open. When people broke SIDH, they didn't whisper it anyone's ear: they published a paper. That's how this stuff works. Bernstein doesn't have a paper to show you; all he has is innuendo. How you know his argument is as limp as a coo…

Quoted post unavailable.

I'm pretty comfortable with the people who do and don't take me seriously.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#397

Earlier quoted context omitted.

Dual_EC keeps getting brought up, but I have to ask: does anybody have any real evidence that it was widely deployed? My recollection is that it basically didn't appear anywhere outside of a handful of not-widely-used FIPS-certified libraries, and wasn't even the default in any of them except RSA's BSAFE. The closest thing we have to evidence that Dual_EC was exploited in the wild seems to be a bunch of circumstantia…

It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…

I don't think Juniper used BSAFE in ScreenOS -- they seem to have put together their own Dual EC implementation on top of OpenSSL, sometime around 2008. (This doesn't change your point, of course.)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#398
post #273

Earlier quoted context omitted.

Where? If you RTFA you'd know it pertains to bribery, not coercion.

To quote the article: At the risk of belaboring the obvious: An attacker won't have to say "Oops, researcher X is working in public and has just found an attack; can we suppress this somehow?" if the attacker had the common sense to hire X years earlier, meaning that X isn't working in public. People arguing that there can't be sabotage because submission teams can't be bribed are completely missing the point. He goe…

FFS nobody is saying that the general idea of being skeptical is unreasonable. And nobody is being ridiculed for doing such. This subthread is about the contents of tptacek’s comment, which doesn't do what you are saying. Saying DJB’s claims are inconceivable is the mischaracterization. People are very eager to paint a picture nobody intended so they can say something and be right.

I use djb’s crypto. Everybody knows his speculation. Everybody knows why he’s pursuing more information. Nobody disagrees more information would be a public good. Some people are more skeptical than others that he’ll find anything substantial.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#399

Earlier quoted context omitted.

One says he’s doing it wrong. The other says he hopes that he wins, of course! Meanwhile they go on to attack Bernstein, mischaracterize his writing, completely dismiss his historical analysis, mock him with memes as a conspiracy theorist, and to top it off they question his internal motivations (which they somehow know) as some kind of a sore loser which is demonstrably false. The plot twist for the last point: he i…

Two things can easily be true: that NIST mishandled a FOIA request, and that there isn't especially good reason to accept on faith Bernstein's concerns about the PQC process, which is unrelated to how they handle FOIA. Meanwhile: you haven't actually added any light to this subthread: the tweets we're talking about do not dismiss the suit. Cryptographic researchers that aren't stans of Daniel Bernstein (there are a l…

You wrote a large number of comments on this so I am asking this here since it's fresh.

Can you comment on why you think djb thinks it is worth investigating if the NSA is attempting to destroy cryptography with weak pqc standards? I read through some of the entries NIST just announced and there are indeed attacks, grave attacks, that exist against Kyber and Falcon. I have no reason to believe the authors of those specs work with the NSA. Wouldn't a more reasonable conclusion be that we need to do more work on pqc? Maybe I have it wrong and he is just trying to rule out that possibility but his long rant which was 80% about NIST and their history with the dual EC backdoor really points at djb concluding the NSA is deliberately trying to weaken crypto by colluding with a bunch of people who probably don't care about money or the NSA's goals that much.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#400
post #397

Earlier quoted context omitted.

It was widely deployed. NSA got it into BSAFE, which I would have said "nobody uses BSAFE, it's not 1996 anymore", but it turned out a bunch of closed-source old-school hardware products were using BSAFE. The most notable BSAFE victims were Juniper/Netscreen. Everybody who claimed Dual EC was a backdoor was right, and that backdoor was materially relevant to our industry. I couldn't believe something as dumb as Dual…

I don't think Juniper used BSAFE in ScreenOS -- they seem to have put together their own Dual EC implementation on top of OpenSSL, sometime around 2008. (This doesn't change your point, of course.)

Yeah, I think you're right; the Juniper revelation also happened months after the BULLRUN stuff --- I remember being upset about how Greenwald and his crew had hidden all the Snowden docs in a SCIF to "carefully review them", with the net result that we went many months without knowing that one of the most popular VPN appliances was backdoored.
Post reply on HN