Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

421–430 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#421

Earlier quoted context omitted.

I see. So maybe what you’re really saying is “why are you writing a system that has cryptographic primitives if you’re not a cryptographer/mathematician?”

No, that is not at all what I am saying.

Let me ask this another way. I know how we determined noise was a good standard and that was talking to a lot of people who had built sophisticated crypto systems and then doing the research ourselves, but that’s only because we had the people on staff who had the capacity to evaluate such systems.

If we didn’t have those people, how would you suggest figuring out which system to implement?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#422

Earlier quoted context omitted.

No, that is not at all what I am saying.

Let me ask this another way. I know how we determined noise was a good standard and that was talking to a lot of people who had built sophisticated crypto systems and then doing the research ourselves, but that’s only because we had the people on staff who had the capacity to evaluate such systems. If we didn’t have those people, how would you suggest figuring out which system to implement?

Peer review is a good start. Noise, and systems derived from it like WireGuard, are peer reviewed (check scholar.google.com for starters), and NIST had nothing at all to do with it.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#423
post #233

Earlier quoted context omitted.

I'm working on a project that involves a customized version of some unclassified, non-intelligence software for a defense customer at my job (not my ideal choice of market, but it wasn't weapons so okay with it). Some of the people on the project come from the deeper end of that industry, with several TS/SCI contract and IC jobs on their resumes. We were looking over some errors on the sshd log and it was saying it c…

I think the term "doublethink" was invented specifically for government functionaries like the IC guy you describe. Being consistently and perfectly dogmatic requires holding two contradictory beliefs in your head at once. It's a skill.

It’s not doublethink to say the programs should have been exposed and that Snowden was a traitor for exposing them in a manner that otherwise hurt our country.

He could have done things properly, instead he dumped thousands of files unrelated to illegal surveillance to the media.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#424

Earlier quoted context omitted.

You wrote a large number of comments on this so I am asking this here since it's fresh. Can you comment on why you think djb thinks it is worth investigating if the NSA is attempting to destroy cryptography with weak pqc standards? I read through some of the entries NIST just announced and there are indeed attacks, grave attacks, that exist against Kyber and Falcon. I have no reason to believe the authors of those sp…

You'd have to ask Bernstein. I think it's helpful to take a bit of time (I know this is a big ask) to go see how Bernstein has comported himself in other standards groups; the CFRG curve standardization discussion is a good example. The reason I said there's a lot of eye-rolling about this post among cryptographers is that I think this is pretty normal behavior for Bernstein. I used to find it inspiring; he got himse…

ok, thanks. I didn't know that about djb's history as far as picking fights with standards groups. I don't know much about him outside of the primitives he designed. That makes some sense in context now because the implication just seemed like a stretch. Cryptosystems break and have flaws in them, that's nothing new. It's just strange to leap to "The NSA did it", but again, I didn't know he just tends to accuse people of that.

I agree about the PQC stuff and committees. Anyways, thanks for clarifying this.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#425

Earlier quoted context omitted.

You'd have to ask Bernstein. I think it's helpful to take a bit of time (I know this is a big ask) to go see how Bernstein has comported himself in other standards groups; the CFRG curve standardization discussion is a good example. The reason I said there's a lot of eye-rolling about this post among cryptographers is that I think this is pretty normal behavior for Bernstein. I used to find it inspiring; he got himse…

ok, thanks. I didn't know that about djb's history as far as picking fights with standards groups. I don't know much about him outside of the primitives he designed. That makes some sense in context now because the implication just seemed like a stretch. Cryptosystems break and have flaws in them, that's nothing new. It's just strange to leap to "The NSA did it", but again, I didn't know he just tends to accuse peopl…

Just bear in mind that this is just opinions and hearsay on my part. Like, I think there's value in relaying what I think I know and what I've heard, but I'm not a cryptographer, I paid almost no attention to the PQC stuff (in fact, I pretty much only ever swapped PQC into my resident set when Bernstein managed to start drama with other cryptographers whose names I knew), and there are possibly other sides to these stories. I've seen Bernstein drama where it's pretty clear he's deeply in the wrong, and I've seen Bernstein drama where it's pretty clear he wasn't.

The suit is good. NIST isn't allowed to clown up FOIA; they have to do it right.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#426
post #312

Earlier quoted context omitted.

I will draw to your attention two interesting facts. First, OpenSSH has disregarded the winning (crystals) variants, and implemented hybrid NTRU-Prime. The Bernstein blog post discusses hybrid designs. "Use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired…

>What are the aims of the lawsuit? Can the NIST decision on crystals be overturned by the court, and is that the goal? It sounds to me like the goal is to find out if there's any evidence of the NSA adding weaknesses into any of the algorithms. That information would allow people to avoid using those algorithms.

I think the fact that NIST refuses yo give any information on that is enough evidence in of itself.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#427
post #363

My background is in normal, enterprise-saas-style software development projects, and the whole notion of post-quantum crypto kind of baffles me. Funnily enough, this post coincides with the release of a newsletter issue[0] by a friend of mine - unzip.dev - about lattice-based cryptography. A bit of a shameless plug, but it really is a great bit of intro for noobs in the area like myself. [0] https://unzip.dev/0x00a-l…

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#428

Earlier quoted context omitted.

>What are the aims of the lawsuit? Can the NIST decision on crystals be overturned by the court, and is that the goal? It sounds to me like the goal is to find out if there's any evidence of the NSA adding weaknesses into any of the algorithms. That information would allow people to avoid using those algorithms.

I think the fact that NIST refuses yo give any information on that is enough evidence in of itself.

The town I live in just outside of Chicago refused to disclose their police General Orders to me; I had to engage the same attorneys Bernstein did to get them. What can I infer from their refusal? That the General Orders include their instructions from the Lizard People overlords?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#429
post #411

Earlier quoted context omitted.

Look, I'm just not going to dignify the argument that there is somehow some controversy over the NIST PQC contest not recommending higher-level constructions to plug PQC KEMs into Curve25519 key exchanges. I get that this seems like a super interesting controversy to you, because Bernstein's blog post is misleading you, but this simply isn't a real controversy.

Hopefully, the judge will help, as before.

It's somewhat unlikely that there will even be a judge here.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#430

Earlier quoted context omitted.

Thank you for actually explaining your POV. I don't understand how you expected me or the other commenters to gather this from your original comment. If it's worth anything, you have changed my opinion on this. You raise very good points.

You're probably right about my original comment, and I apologize. These threads are full of very impassioned, very poorly-informed comments --- I'm not saying I'm well-informed about NIST PQC, because I'm not, but, I mean, just, wow --- and in circumstances like that I tend to play my cards very close to my chest; it's just a deeply ingrained message board habit of mine. I can see how it'd be annoying. I spent almost…

Can you elaborate on his reputation?
Post reply on HN