Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

431–440 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#431
post #95

Earlier quoted context omitted.

"Roll your own crypto" typically refers to making your own algorithm or implementation of an algorithm not choosing the algorithm.

Would you really want every random corporation having some random person pick from the list of open source cipher packages? Which last I checked , still included things like 3DES, MD5, etc. You might as well hand a drunk monkey a loaded sub machine gun.

What’s wrong with 3DES?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#432

Earlier quoted context omitted.

You're probably right about my original comment, and I apologize. These threads are full of very impassioned, very poorly-informed comments --- I'm not saying I'm well-informed about NIST PQC, because I'm not, but, I mean, just, wow --- and in circumstances like that I tend to play my cards very close to my chest; it's just a deeply ingrained message board habit of mine. I can see how it'd be annoying. I spent almost…

Can you elaborate on his reputation?

Based only on random conversations and no serious interrogation of what happened, so take it for the very little this pure statement of opinion is worth, I'd say he has, chiefly, and in my own words, a reputation for being a prickly drama queen.

He has never been that to me; I've had just a few personal interactions with him, and they've been uniformly positive. My feeling is that he was generous with his time and expertise when I had questions, and pleasant and welcoming in person.

He has, in the intervening years, done several things that grossed me the fuck out, though. There are certainly people who revel in hating the guy. I'm not one of them.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#433

Earlier quoted context omitted.

I think it's naive and trusting only on the surface, but with some clear intent and goal underneath. In the past he has held a different stance, but it suddenly changed some time after Matasano.

Can I ask that, if you're going to accuse me of shilling in an HN thread, you at least come up with something that I'm shilling? I don't care what it is; you can say that I'm shilling for Infowars Life ProstaGuard Prostate Health Supplement with Saw Palmetto and Anti-Oxidant, for all I care, just identify something .

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#434

Earlier quoted context omitted.

One trivial example implied by the blog post: Such corruption could be involved in the non-transparent decision making process at NIST. Regarding Dual_EC: we still lack a lot of information about how this decision was made internally at NIST. That’s a core point: transparency was promised in the wake of discovered sabotage and it hasn’t arrived.

What do you mean, "how" the decision about Dual EC was made? It's an NSA-designed backdoor. NIST standardized it because NSA told them to. I'm sure NSA told NIST a story about why it was important to standardize it. The Kremlinology isn't interesting: it is NSA's chartered job to break cryptography, and nobody should ever trust them; the only thing NSA can do to improve cryptography is to literally publish secret att…

What do I mean? Iran-Contra, Watergate, or a 9/11 report style report, like levels of investigation. Given how widely read the BULLRUN stories were, it’s not credible to suggest the details aren’t important.

The American people deserve to know who picked up the phone or held a meeting to make this happen. Who was present, who at NIST knew what, and so on. Who internally had objections and indeed who set the policy in the first place. What whistleblower protections were in place and why didn’t the IG have involvement in public? Why did we have to learn about this from Snowden?

NSA has a dual mandate, on that I hope we can agree. It’s my understanding that part of their job is to secure things and that part of their job is to break stuff.

NIST has no such dual mandate, heads should roll at NIST. We probably agree that NSA probably won’t be accountable in any meaningful sense, but NIST must be - we are stuck with them. Not trusting them isn’t an option for anyone who files their taxes or banks or does any number of other regulated activities that require using NIST standards.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#435
post #235

Near the end of the post – after 50 years of axe grinding – djb does eventually get to the point wrt pqcrypto. I find the below excerpt particularly damning. Why not wrap nascent pqcrypto in classical crypto? Suspect! -- The general view today is that of course post-quantum cryptography should be an extra layer on top of well-established pre-quantum cryptography. As the French government cybersecurity agency (Agence…

This is the least compelling argument Bernstein makes in the whole post, because it's simply not the job of the NIST PQC program to design or recommend hybrid classical/PQC schemes. Is it fucky and weird if NSA later decides to recommend against people using hybrid key establishment? Yes. Nobody should listen to NSA about that, or anything else. But NIST ran a PQC KEM and signature contest, not a secure transport sta…

It’s compelling in context. If the NSA influenced NIST standards 3x in the past — DES, DSA, Dual EC — then shouldn’t we be on high alert this 4th time around?

That NSA is already recommending against hybrid, instead of waiting for the contest results, might signal they’ve once again managed to game the standardization process itself.

At the very least — given the exhaustive history in this post — you’d like to know what interactions NSA and NIST have had this time around. Thus, djb’s FOIA. And thus the lawsuit when the FOIA went unanswered. It all seems very reasonable to me.

What’s that old saying, “fool me thrice…”?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#436

Earlier quoted context omitted.

Your augment that the selection doesn’t pick his designs doesn’t square with SPHINCS+ winning, and with others remaining in the running. His former PhD student won with Kyber. Bernstein did very well here and you’re misleading people by suggesting he had his ass handed to him. He has published (and it is linked from the blog) his views on how to run cryptographic contests before their recent selection finished (late)…

I didn't even notice a "punching down about mental health" thing. You wrote a long comment, I skimmed it. Your allegation that Filippo and Matt Green are antisemitic is ludicrous. I didn't say Bernstein had his ass handed to him. I said that he wrote thousands and thousands of words about his reasons to mistrust NIST (not just here but elsewhere, and often), but still participated in the PQC contest, raising these co…

> I didn't even notice a "punching down about mental health" thing. You wrote a long comment, I skimmed it.

That tracks, okay. It’s the weekend and I’m a nobody on the internet. Thank you for talk the time to continue to engage with me.

> Your allegation that Filippo and Matt Green are antisemitic is ludicrous.

That isn’t an allegation that I am making, you are misunderstanding and misrepresenting my statements. My comment even disclaimed that this probably isn’t intentional, merely that it is one read of that meme. My core point is this: posting that meme is unhelpful in a thread about Bernstein’s supposedly harmful behavior. Maybe you think it’s a funny joke, I don’t.

Either way - funny joke or not - it certainly isn’t a healthy discourse for “the community” to call someone names and to dismiss them as some kind of unhinged conspiracy theorist.

> I didn't say Bernstein had his ass handed to him.

Indeed, I did not claim to quote you there. I am characterizing your words into what I understand as your point. Let’s call this “the sore loser discourse” - it is repeated in this thread by others. It seems to be implied by my read when you say: “…he opted to participate in was corrupted by dint of not prioritizing his own designs.” I preemptively acknowledge that I may have misunderstood you.

What do you mean to convey by “dint of not” roughy? Don’t SPHINCS+ (Standardized in round three) and Classic McEliece (still in the running) count as prioritizing his designs? Also, what is wrong with participating in this standardization process? He seems to be unhappy with NIST before, and during the process, and with ample cause. By participating, it’s clear he has learned more and by winning parts of the competition, he’s not a sore loser.

If he wasn’t a part of this competition, people would probably dismiss his criticism as simply being outside. It’s harder to dismiss him if he is part of it, and even harder when his submissions win. It isn’t a clean sweep, but it’s lifetime achievement levels for some people to have a hand in just one such algorithm, selected in such a process. He has a hand in several remaining submissions as far as I understand the process and the submissions.

> I said that he wrote thousands and thousands of words about his reasons to mistrust NIST (not just here but elsewhere, and often),

So you note he has been saying these things for a long time. On that we agree.

> but still participated in the PQC contest,

You go on to note that he then participated in the process. He is documented in his attempts to use the process tools to raise specific issues and to try to have them settled by NIST as promised, with transparency. NIST has failed to bring that transparency.

Confusingly (to me anyway) your next statement continues with a contradiction:

> raising these concerns only at its conclusion

Which is it? Was he constantly raising these issues or only raising them at the end (of round three)?

Alternatively I could read this as “at its (the blog post) conclusion” which would be extremely confusing. I presume this isn’t what you meant but if so, okay, I am really missing the point.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#437
post #398

Earlier quoted context omitted.

To quote the article: At the risk of belaboring the obvious: An attacker won't have to say "Oops, researcher X is working in public and has just found an attack; can we suppress this somehow?" if the attacker had the common sense to hire X years earlier, meaning that X isn't working in public. People arguing that there can't be sabotage because submission teams can't be bribed are completely missing the point. He goe…

FFS nobody is saying that the general idea of being skeptical is unreasonable. And nobody is being ridiculed for doing such. This subthread is about the contents of tptacek’s comment, which doesn't do what you are saying. Saying DJB’s claims are inconceivable is the mischaracterization. People are very eager to paint a picture nobody intended so they can say something and be right. I use djb’s crypto. Everybody knows…

You said this up thread and I find it incorrect:

> If you RTFA you'd know it pertains to bribery, not coercion

By quoting the article it seems the text directly contradicts your summary as being too narrow. General coercion is also be included as part of the concerns raised by TFA. He isn’t just talking about NSA giving a person a sack of money.

Meanwhile in this thread and on Twitter, many people are indeed doing the things you say that nobody is doing.

We almost all use Bernstein’s crypto — some as mere users, others as developers, etc. I’m not sure what that brings to the discussion.

I’m glad we agree that his work to gather more information is a public good.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#438
post #435

Earlier quoted context omitted.

This is the least compelling argument Bernstein makes in the whole post, because it's simply not the job of the NIST PQC program to design or recommend hybrid classical/PQC schemes. Is it fucky and weird if NSA later decides to recommend against people using hybrid key establishment? Yes. Nobody should listen to NSA about that, or anything else. But NIST ran a PQC KEM and signature contest, not a secure transport sta…

It’s compelling in context. If the NSA influenced NIST standards 3x in the past — DES, DSA, Dual EC — then shouldn’t we be on high alert this 4th time around? That NSA is already recommending against hybrid, instead of waiting for the contest results, might signal they’ve once again managed to game the standardization process itself. At the very least — given the exhaustive history in this post — you’d like to know w…

Everybody is on high alert. Being on high alert doesn't make Bernstein right.

I don't even support the premise of NIST crypto standardization, let alone trust them to do it.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#439

Earlier quoted context omitted.

Can I ask that, if you're going to accuse me of shilling in an HN thread, you at least come up with something that I'm shilling? I don't care what it is; you can say that I'm shilling for Infowars Life ProstaGuard Prostate Health Supplement with Saw Palmetto and Anti-Oxidant, for all I care, just identify something .

Quoted post unavailable.

[deleted]

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#440
post #354

Earlier quoted context omitted.

There is the concept of "byte" when talking about a string of characters which make up a password, though, which is why I said bytes. But yes, I am aware, and your statement just further supports my point.

Not necessarily. A person could remember a password that contains name of their loved one differently in their brain than some arbitrary string of letters and numbers. Those letters and numbers can each be "encoded" differently in their brain - e.g. maybe the letter 'S' is linked in their brain to snakes because it kind of looks like one. Or any kind of weird connections of certain parts of the password to a smell th…

>[...] but you were talking about accessing data in a human brain.

No, I wasn't. I used bytes as a unit of measurement of data. I guess if I said "characters" instead of "bytes" people would stop trying to explain this to me. Although I sort of doubt that, because I said "yes, I know" and then get another paragraph explaining the same thing to me.

Post reply on HN