Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

411–420 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#411
post #323

Earlier quoted context omitted.

That would make it seem that the lengthy hybrid discussion in the blog is a misdirection. I will grant you that this does support your argument. EDIT: Actually, what you have said does not seem at all correct. In DJB's Apon complaint, we find this text: 'For example, in email to pqc-forum dated 30 Oct 2019 15:38:10 +0000 (2019), NIST posted technical comments regarding hybrid encryption modes and asked for feedback “…

Look, I'm just not going to dignify the argument that there is somehow some controversy over the NIST PQC contest not recommending higher-level constructions to plug PQC KEMs into Curve25519 key exchanges. I get that this seems like a super interesting controversy to you, because Bernstein's blog post is misleading you, but this simply isn't a real controversy.

Hopefully, the judge will help, as before.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#412
post #350
post #316

Earlier quoted context omitted.

The main concern that I have is the NIST refusal to consider a hybrid design as described in the blog, coupled with the fact that OpenSSH has disregarded NIST and standardized on hybrid NTRU-Prime. There had to be substance to accomplish this, and it moves all of UNIX plus Microsoft away from crystals. It would seem hugely damaging to crystals as the winner of the latest round.

Repeating this here. We (OpenSSH) have not disregarded NIST, we just added a PQ algorithm before NIST finished their competition and we'll almost certainly add support for the finalist fairly soon.

I will eagerly await their arrival, and be sure to sysupgrade.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#413

Earlier quoted context omitted.

You don’t get it clearly. They’re playing dirty. At best the FOIA will receive a document made on the fly with nothing of value. The rules don’t apply to the NSA. You can do exactly nothing. But NIST, you can do something about - reject any standard they approve. It’s your choice what algorithm you use, and we know NIST will select a broken algorithm for the NSA, so just ignore their ‘standard’. The best solution is…

You should tell Bernstein that! Your logic implies he's wasting his time with the suit.

"You shouldn't fight because the baddies are strong!" is a horrible argument in my book. Discouraging and disparaging other people's attempts is even worse.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#414
post #349
post #312

Earlier quoted context omitted.

I will draw to your attention two interesting facts. First, OpenSSH has disregarded the winning (crystals) variants, and implemented hybrid NTRU-Prime. The Bernstein blog post discusses hybrid designs. "Use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired…

We (OpenSSH) haven't "disregarded" the winning variants, we added NTRU before the standardisation process was finished and we'll almost certainly add the NIST finalists fairly soon.

I will eagerly await the new kex and keytypes, and will be sure to sysupgrade.

I will be very curious if the default kex shifts away from NTRU-Prime.

I might also point out that crystals-kyber was coequal to NTRU-Prime at the time that you set your new default kex.

I trust that the changelog will have a detailed explanation of all the changes that you will make, and why.

I will "ssh-rotate" whatever you decide.

https://www.linuxjournal.com/content/ssh-key-rotation-posix-...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#415

Earlier quoted context omitted.

> I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. Could you elaborate on this? I didn't get this from the article at all. There's no researcher(s) being implicated as far as I can tell. What I read is the accusation of NIST's decision-making process possibly being influenced by the NSA, something that we know has happened before. Say N teams of s…

Nobody should trust NIST. I don't even support NIST's mission; even if you assembled a trustworthy NIST, I would oppose it. The logical problem with the argument Bernstein makes about NSA picking the least trustworthy scheme is that it applies to literally any scheme NIST picks. It's unfalsifiable. If he believes it, his FOIA effort is a waste of time (he cannot FOIA NSA's secret PQC attack knowledge). The funny thin…

> The logical problem with the argument Bernstein makes about NSA picking the least trustworthy scheme is that it applies to literally any scheme NIST picks. It's unfalsifiable.

That may be true in the strict sense, but in practice, I think there would be a material distinction between a NIST process of "we defer our decision to the majority opinion of a set of three researchers with unimpeachable reputations" (a characterization from another comment) and a process of "NSA said we should pick X."

In the strict sense, I can't trust either process, but in practice [edit: as an absolute layperson who has to trust someone], I'd trust the first process infinitely more (as I would absolutely distrust the second process).

> The funny thing here is, I actually do accept his logic, perhaps even more than he does.

That's actually what I got from your other comments to this story. But that confused me, because it was also what I got from the article. The first two thirds of the article are spent entirely on presenting NIST as an untrustworthy body based on decades of history. Apart from the title, PQC isn't even mentioned until the last third, and that part, to me, was basically "NIST's claims of reform are invalidated if it turns out that NSA influenced the decision-making process again".

My vibe was that both of your positions are more or less in agreement, though I have to say I didn't pick up on any accusations of corruption of a PQC researcher in the article (I attribute that to me being a layperson in the matter).

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#416
post #312

Earlier quoted context omitted.

I will draw to your attention two interesting facts. First, OpenSSH has disregarded the winning (crystals) variants, and implemented hybrid NTRU-Prime. The Bernstein blog post discusses hybrid designs. "Use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired…

It's not the first time either and it won't be the last. NIST chose Rijndael over Serpent for the AES standard even though Serpent won. I vaguely recall they gave some smarmy answer. I don't think anyone submitted a FOIA not that it would matter. I've been through that bloated semi-pseudo process and saw how easy it was to stall people not answer a simple question.

Rijndael was selected over Serpent for performance reasons.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#417

Earlier quoted context omitted.

Of course it was not NIST's job to standardize a hybrid algorithm and nobody claims such a thing. However the silly position is that of the NSA, as shown in https://web.archive.org/web/20220529202244im_/https://pbs.tw... which attempts to strongly discourage the use of any "crypto redundancy" and says that they will not approve such algorithms.

Obviously people do claim that the NIST contest is suspect because it doesn't approve hybrid schemes; there are people who claim it on this thread.

Ostensibly, nistpqc is about finding safe crypto, first for TLS, second for ssh. You will argue differently, but we all expect the same end product.

NIST has specifically asked for guidance on hybrid crypto (as well you know), as I documented elsewhere on this page.

You assert that NIST only accepts pure post-quantum crypto. They ask for hybrid.

Color me jaded.

EDIT: Just for you, my fine fellow!

'For example, in email to pqc-forum dated 30 Oct 2019 15:38:10 +0000 (2019), NIST posted technical comments regarding hybrid encryption modes and asked for feedback “either here on the pqc-forum or by contacting us at pqc-comments@nist.gov” (emphasis added).'

https://www.google.com/url?q=https://groups.google.com/a/lis...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#418

Earlier quoted context omitted.

It's not the first time either and it won't be the last. NIST chose Rijndael over Serpent for the AES standard even though Serpent won. I vaguely recall they gave some smarmy answer. I don't think anyone submitted a FOIA not that it would matter. I've been through that bloated semi-pseudo process and saw how easy it was to stall people not answer a simple question.

Rijndael was selected over Serpent for performance reasons.

This is what I know; wish I knew more.

AES won due to software performance.

https://www.moserware.com/2009/09/stick-figure-guide-to-adva...

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#419
post #417

Earlier quoted context omitted.

Obviously people do claim that the NIST contest is suspect because it doesn't approve hybrid schemes; there are people who claim it on this thread.

Ostensibly, nistpqc is about finding safe crypto, first for TLS, second for ssh. You will argue differently, but we all expect the same end product. NIST has specifically asked for guidance on hybrid crypto (as well you know), as I documented elsewhere on this page. You assert that NIST only accepts pure post-quantum crypto. They ask for hybrid. Color me jaded. EDIT: Just for you, my fine fellow! 'For example, in ema…

Thanks, it's nice not to have to link somewhere deep into the thread to support the point I just made.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#420
post #161
post #94

side question : I've only recently started to digg a bit deeper into crypto algorithms ( looking into various types of curves etc), and it gave me the uneasing feeling that the whole industry is relying on the expertise of only a handful of guys to actually ensure that crypto schemes used today are really working. Am i wrong ? are there actually thousands and thousands of people with the expertise to actually proove…

Most programmers don't need to prove crypto algorithms. There are many situations where you can just use TLS 1.3 and let it choose the ciphers. If you really need to build a custom protocol or file format, you can still use libsodium's secretbox, crypto_box, and crypto_kx functions which use the right algorithms.

The grandparent post is asking about the people who need to know enough to program TLS to

> let it choose

Post reply on HN