Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

401–410 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#401

Earlier quoted context omitted.

Two things can easily be true: that NIST mishandled a FOIA request, and that there isn't especially good reason to accept on faith Bernstein's concerns about the PQC process, which is unrelated to how they handle FOIA. Meanwhile: you haven't actually added any light to this subthread: the tweets we're talking about do not dismiss the suit. Cryptographic researchers that aren't stans of Daniel Bernstein (there are a l…

You wrote a large number of comments on this so I am asking this here since it's fresh. Can you comment on why you think djb thinks it is worth investigating if the NSA is attempting to destroy cryptography with weak pqc standards? I read through some of the entries NIST just announced and there are indeed attacks, grave attacks, that exist against Kyber and Falcon. I have no reason to believe the authors of those sp…

You'd have to ask Bernstein. I think it's helpful to take a bit of time (I know this is a big ask) to go see how Bernstein has comported himself in other standards groups; the CFRG curve standardization discussion is a good example. The reason I said there's a lot of eye-rolling about this post among cryptographers is that I think this is pretty normal behavior for Bernstein.

I used to find it inspiring; he got himself crosswise against the IETF DNS working group, which actively ostracized him, and I thought the stance he took there was almost heroic (also, I hate DNSSEC, and so does he). But when you see that same person get in weird random fights with other people, over and over again, well: there's a common thread there.

Is it worth investigating whether NSA is trying weaken PQC? Sure. Nobody should trust NSA. Nobody should trust NIST! There's value in NIST catalyzing all the academic asymmetric cryptography researchers into competing against each other, so the PQC event probably did everybody a service. But no part of that value comes from NIST blessing the result.

It's probably helpful for you to know that I think PQC writ large is just a little bit silly. Quantum computers of unusual size? I don't believe they exist. I think an under-appreciated reason government QC spending happens is because government spending is a goal in and of itself; one of NSA's top 3 missions is to secure more budget for NSA --- it might even be the #1 goal. Meanwhile, PQC is a full-employment program for academic cryptographers working on "Fun" asymmetric schemes that would otherwise be totally ignored in an industry that has more or less standardized on the P-curves and Curve25519.

Be that as it may: whether or not NSA is working to "weaken" CRYSTALS-Kyber is besides the point. NSA didn't invent CRYSTALS. A team of cryptographers, including some huge names in modern public key crypto research, did. Does NSA have secret attacks against popular academic crypto schemes? Probably. You almost hope so, because we pay them a fuckload of a lot of money to develop those attacks. But you can say that about literally every academic cryptosystem.

You probably also don't need me to tell you again how much I think formal cryptographic standards are a force for evil in the industry.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#402

Earlier quoted context omitted.

> "I may believe almost all of this is overblown and silly, as like a matter of cryptographic research ..." Am I misunderstanding you, or are you saying that you believe almost all of DJB's statements claiming that NIST/NSA is doctoring cryptography is overblown and silly? If that's the case, would you mind elaborating?

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible.

Could you elaborate on this? I didn't get this from the article at all. There's no researcher(s) being implicated as far as I can tell.

What I read is the accusation of NIST's decision-making process possibly being influenced by the NSA, something that we know has happened before.

Say N teams of stellar researchers submit proposals, and they review their peers. For the sake of argument, let's say that no flaw is found in any proposal; every single one is considered perfect.

NIST then picks algorithm X.

It is critical to understand the decision making process behind the picking of X, crucially so when the decision-making body has a history of collusion.

Because even if all N proposals are considered perfect by all possible researchers, if the NSA did influence NIST in the process, history would suggest that X would be the least trustable of all proposals.

And that's the main argument I got from the article.

Yes, stone-walling a FOIA request may be common, but in the case of NIST, there is ample precedent for malfeasance.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#403

Earlier quoted context omitted.

That person is very well known in this community, and in other communities as well. They are also known for making very specific arguments that people misinterpret and fight over, but the actual intent and literal meaning of the statements is most often correct (IMO). Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expo…

If that is the case, then what is the explanation for NIST (according to DJB) 1. not communicating their decision process to anywhere near the degree that they vowed to, and 2. stone-walling a FOIA request on the matter? > Whether this is a byproduct of trying to be exacting in the language used that tends to cause people interpretive problems or a specific tactic to expose those that are a combination of careless wi…

> If that is the case, then what is the explanation for NIST (according to DJB) 1. not communicating their decision process to anywhere near the degree that they vowed to, and 2. stone-walling a FOIA request on the matter?

Why are you asking me, when I was clear I was just stating my interpretation of his position, and he had already replied to me with even more clarification to his position?

> Communicating badly and then acting smug when misunderstood is not cleverness

I don't disagree. My observations should not be taken as endorsement for a specific type of behavior, if that's indeed what is being done.

That said, while I may dislike how the conversation plays out, I can't ignore that very often he has an intricate and we'll thought out position that is expressed succinctly, and in the few cases where someone treats the conversation with respect and asks clarifying questions rather than makes assumptions the conversation is clear and understanding is quickly reached between most parties.

I'm hesitant to lay the blame all on one side when the other side is the one jumping to conclusions and then refusing to accept their mistake when it's pointed out.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#404

Earlier quoted context omitted.

Regarding trying internal channels, Snowden says he tried this > despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deep…

https://www.congress.gov/congressional-report/114th-congress... There is no record that he attempted to use internal channels. He would have been afforded whistleblower protection had he went to Congress with his findings.

> There is no record that he attempted to use internal channels

From the beginning of the Snowden quote:

> I could not legally go to the official channels that direct NSA employees have available to them

In addition, I find it difficult to take any congressional report on this matter, including the one you cited, seriously given that their primary source is a group of people who have repeatedly lied to Congress without consequence.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#405
post #364

Earlier quoted context omitted.

"Certifiably neutral" So, by a process that hasn't been designed yet. Especially when one considers how opaque most neutral nets are to human scrutiny.

I mean, if the source, training data, and query interface are public, it would be insanely difficult to hide a backdoor There i "designed" your impossible criterion in just a few obvious steps you could have inferred

There are many, many papers that show how you can make innocuous changes to inputs to make neutral nets produce the wrong result. You might be overestimating the difficulty of this process.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#406

Earlier quoted context omitted.

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Could you elaborate on this? I didn't get this from the article at all. There's no researcher(s) being implicated as far as I can tell. What I read is the accusation of NIST's decision-making process possibly being influenced by the NSA, something that we know has happened before. Say N teams of s…

Nobody should trust NIST.

I don't even support NIST's mission; even if you assembled a trustworthy NIST, I would oppose it.

The logical problem with the argument Bernstein makes about NSA picking the least trustworthy scheme is that it applies to literally any scheme NIST picks. It's unfalsifiable. If he believes it, his FOIA effort is a waste of time (he cannot FOIA NSA's secret PQC attack knowledge).

The funny thing here is, I actually do accept his logic, perhaps even more than he does. I don't think there's any reason to place more trust in NIST's PQC selections than other well-reviewed competing proposals. I trust the peer review of the competitors, but not NIST's process at all.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#407
post #235

Near the end of the post – after 50 years of axe grinding – djb does eventually get to the point wrt pqcrypto. I find the below excerpt particularly damning. Why not wrap nascent pqcrypto in classical crypto? Suspect! -- The general view today is that of course post-quantum cryptography should be an extra layer on top of well-established pre-quantum cryptography. As the French government cybersecurity agency (Agence…

This is the least compelling argument Bernstein makes in the whole post, because it's simply not the job of the NIST PQC program to design or recommend hybrid classical/PQC schemes. Is it fucky and weird if NSA later decides to recommend against people using hybrid key establishment? Yes. Nobody should listen to NSA about that, or anything else. But NIST ran a PQC KEM and signature contest, not a secure transport standardization. Sir, this is a Wendy's.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#408

Earlier quoted context omitted.

I assume that the point was that NSA is against using hybrid algorithms like the one used by OpenSSH, which combine a traditional algorithm with a post-quantum algorithm, arguing that using both algorithms is an unnecessary complication. The position of D. J. Bernstein and also of the OpenSSH team is that the prudent approach is to use only hybrid algorithms until enough experience is gained with the post-quantum alg…

Fucking everybody's position is to combine classical key exchanges with PQC KEMs. It wasn't NIST's job to standardize a classical+PQC construction. The point of the contest is to figure out which PQC constructions to use. NIST also didn't recommend that everyone implement their cryptographic handshakes in a memory-safe language. But not doing that is going to get a bunch of people owned by NSA too. Do you see how sil…

Of course it was not NIST's job to standardize a hybrid algorithm and nobody claims such a thing.

However the silly position is that of the NSA, as shown in

https://web.archive.org/web/20220529202244im_/https://pbs.tw...

which attempts to strongly discourage the use of any "crypto redundancy" and says that they will not approve such algorithms.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#409

Earlier quoted context omitted.

https://www.congress.gov/congressional-report/114th-congress... There is no record that he attempted to use internal channels. He would have been afforded whistleblower protection had he went to Congress with his findings.

> There is no record that he attempted to use internal channels From the beginning of the Snowden quote: > I could not legally go to the official channels that direct NSA employees have available to them In addition, I find it difficult to take any congressional report on this matter, including the one you cited, seriously given that their primary source is a group of people who have repeatedly lied to Congress witho…

Why do you take Snowden's word as gospel but dismiss a bipartisan Congressional Committee's findings? I think that you are biased and nothing will change your mind. Let's agree to disagree.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#410

Earlier quoted context omitted.

Fucking everybody's position is to combine classical key exchanges with PQC KEMs. It wasn't NIST's job to standardize a classical+PQC construction. The point of the contest is to figure out which PQC constructions to use. NIST also didn't recommend that everyone implement their cryptographic handshakes in a memory-safe language. But not doing that is going to get a bunch of people owned by NSA too. Do you see how sil…

Of course it was not NIST's job to standardize a hybrid algorithm and nobody claims such a thing. However the silly position is that of the NSA, as shown in https://web.archive.org/web/20220529202244im_/https://pbs.tw... which attempts to strongly discourage the use of any "crypto redundancy" and says that they will not approve such algorithms.

Obviously people do claim that the NIST contest is suspect because it doesn't approve hybrid schemes; there are people who claim it on this thread.
Post reply on HN