Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

451–460 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#451

Earlier quoted context omitted.

You don’t get it clearly. They’re playing dirty. At best the FOIA will receive a document made on the fly with nothing of value. The rules don’t apply to the NSA. You can do exactly nothing. But NIST, you can do something about - reject any standard they approve. It’s your choice what algorithm you use, and we know NIST will select a broken algorithm for the NSA, so just ignore their ‘standard’. The best solution is…

You should tell Bernstein that! Your logic implies he's wasting his time with the suit.

he is

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#452
post #413

Earlier quoted context omitted.

You should tell Bernstein that! Your logic implies he's wasting his time with the suit.

"You shouldn't fight because the baddies are strong!" is a horrible argument in my book. Discouraging and disparaging other people's attempts is even worse.

I’m not saying don’t fight. I’m saying don’t let your opponent define the rules of the game.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#453
post #435

Earlier quoted context omitted.

It’s compelling in context. If the NSA influenced NIST standards 3x in the past — DES, DSA, Dual EC — then shouldn’t we be on high alert this 4th time around? That NSA is already recommending against hybrid, instead of waiting for the contest results, might signal they’ve once again managed to game the standardization process itself. At the very least — given the exhaustive history in this post — you’d like to know w…

Everybody is on high alert. Being on high alert doesn't make Bernstein right. I don't even support the premise of NIST crypto standardization, let alone trust them to do it.

> Everybody is on high alert. Being on high alert doesn't make Bernstein right.

What exactly are you arguing for, with this? Pretty sure the dude you're replying to knows about the existence of cognitive biases, thanks.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#454
post #355
post #310

Why don’t we invert FOIA? Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and…

The carve-out you mention is a decent idea on paper, but in practice is a difficult process. There's really no way to do it in any significant degree without basically putting all gov to a complete halt. Consider that government is not staffed with technical people, nor necessarily critically minded people to implement these systems. There are ways to push for FOIA improvements that don't require this sort of drastic…

A private right of action and waiver of immunity solves most of the “bad actor” problems.

The big issue is how to preserve what actually needs to be secret (in the interest of the USA, not the interests of the bureaucracy) while forcing everything else to be public.

A lot of things are secret that don’t need to be secret; that’s a side effect of mandatory data classification and normal bureaucratic incentives- you won’t get in trouble for over-classifying, and classified information is a source of bureaucratic power. So you have to introduce a really strong personal incentive to offset that or nothing will ever change.

Personally, I don’t think that information should be classified if it came from public sources. Or maybe only allow such information to be classified for a short period of time, eg one year.

The longer and/or higher the classification level, the more effort should be involved, to create disincentives to over-classification.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#455

Earlier quoted context omitted.

Everybody is on high alert. Being on high alert doesn't make Bernstein right. I don't even support the premise of NIST crypto standardization, let alone trust them to do it.

> Everybody is on high alert. Being on high alert doesn't make Bernstein right. What exactly are you arguing for, with this? Pretty sure the dude you're replying to knows about the existence of cognitive biases, thanks.

It's pretty obvious, right? What Bernstein is saying here can (and probably is) a load of horseshit, and it's still a terrible idea to trust NIST. Seems like a simple argument.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#456
post #444

Earlier quoted context omitted.

Peer review is a good start. Noise, and systems derived from it like WireGuard, are peer reviewed (check scholar.google.com for starters), and NIST had nothing at all to do with it.

It is incredibly hard to get a good grasp of the consensus in a literature as a non-expert just by searching Google Scholar. People spend years in graduate school to learn to do that. Are there reputable journals or conference proceedings that you specifically recommend reading for high-quality literature reviews?

There's nothing you're going to read, with or without trustworthy standards, that is going to enable you to design safe novel applications of cryptography. Encrypting a file, setting up a secure transport, and (if you're extraordinarily careful and do a lot of reading) exchanging secure messages are all within reach without anything resembling postgraduate education.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#457

Earlier quoted context omitted.

Based only on random conversations and no serious interrogation of what happened, so take it for the very little this pure statement of opinion is worth, I'd say he has, chiefly, and in my own words , a reputation for being a prickly drama queen. He has never been that to me; I've had just a few personal interactions with him, and they've been uniformly positive. My feeling is that he was generous with his time and e…

Thanks for this reply. Can you point to a specific gross thing?

Sorry, I picked my words carefully in that last comment.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#458
So... Common pattern:. NSA, it's representatives or affiliates make claims that longer key lengths are unnecessary or have too much of a performance cost.

So... I make the claim again. Let's multiply all key lengths by 10. Ie. 2048 bit RSA becomes 20480 bit RSA.

Who here thinks that's a bad idea? Previously on HN such ideas have been downvoted and comments have been made against them. I wonder, who has it been doing that, and what were their motives?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#459
So this lawsuit is to try and force the release of some documents that might be embarrassing.

However, if the lawsuit is won, I would think it very unlikely the documents aren't rewritten 'on national security ' grounds before release.

So nothing will be learned either way.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#460
post #447

Earlier quoted context omitted.

This is completely unrelated to the question being asked by the parent. They aren't asking about the average programmer. They are asking how many people in the world can truly 'prove' (to some reasonable degree) that the cryptography in use and the algorithms that are implementing that cryptography are 'secure' (to some reasonable degree). Put another way, they are asking how many people in the world could verify tha…

My point was that you don't need "thousands and thousands of people with the expertise to actually proove that the algorithms used today are really safe". If the demand existed, there would be a lot more of those people.

Again, parent poster didn't say there was a need for thousands. They were asking how many there is a demand for. One? Ten? Hundred? That's the question that is being asked.
Post reply on HN