Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

461–470 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#461

Earlier quoted context omitted.

It can be everybody involved. It should include NIST based on the history alone. Some of the commentary on this topic is by people who also denied DUAL_EC until (correctly) conceding that it was actually a backdoor, actually deployed, and that it is embarrassing for both NSA and NIST. This sometimes looks like reactionary denialism. It’s a safe position that forces others to do a lot of work, it seems good faith with…

I'm people who denied that Dual EC was a backdoor (my position wasn't an unusual one; it was that Dual EC was too stupid to actually use, which made it an unlikely backdoor). Dan Bernstein didn't educate me about that; like anybody else who held that position, the moment I learned that real products in the industry were built with libraries that defaulted to Dual EC, the jig was up. I'm honest about what I'm saying a…

How could any serious security researcher have been in doubt about Dual EC? The design did not not make any sense at all. Not until you consider that it is designed with a back door, then it is a sleek minimal design that does exactly what it needs to do and not a whole lot more.

If you couldn't see that from a mile away, then you might be too naive to work in security.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#462
post #354

Earlier quoted context omitted.

Not necessarily. A person could remember a password that contains name of their loved one differently in their brain than some arbitrary string of letters and numbers. Those letters and numbers can each be "encoded" differently in their brain - e.g. maybe the letter 'S' is linked in their brain to snakes because it kind of looks like one. Or any kind of weird connections of certain parts of the password to a smell th…

> [...] but you were talking about accessing data in a human brain. No, I wasn't. I used bytes as a unit of measurement of data. I guess if I said "characters" instead of "bytes" people would stop trying to explain this to me. Although I sort of doubt that, because I said "yes, I know" and then get another paragraph explaining the same thing to me.

No, you're moving the goalposts. You were specifically talking saying "to wirelessly read a few specific bytes of data from the brain of an unknowing person".

You do not read bytes of data from the brain, because there are no bytes in the brain. You read information (in whatever weird form and format the brain has it), and in order to store it in whatever digital storage device you have, only then convert it into bytes and store those bytes.

It's like if you were saying "I read three words of English text from this book written in Chinese".

But yeah, at this point, we're arguing pure semantics. :)

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#463

Earlier quoted context omitted.

> … I didn't acknowledge the majesty of the argument I had been confronted with. Gee, thanks, I think. Sorry to say we don’t agree on your summary of my comment. > Filippo Valsorda wrote a tweet that included a meme from "It's Always Sunny In Philadelphia" From this, we already have serious disagreements. It’s part of a series of tweets amplified by others. It isn’t a single tweet in isolation even when we only look…

"Crazy" is not the word I would use about what you've written here. It is unlikely you and I are going to have any productive dialog after this, which is totally fine; I'm happy to disengage here.

Okay, I’m happy to disengage as well. Thank you for your time and also for your insight.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#464

Earlier quoted context omitted.

I'm people who denied that Dual EC was a backdoor (my position wasn't an unusual one; it was that Dual EC was too stupid to actually use, which made it an unlikely backdoor). Dan Bernstein didn't educate me about that; like anybody else who held that position, the moment I learned that real products in the industry were built with libraries that defaulted to Dual EC, the jig was up. I'm honest about what I'm saying a…

How could any serious security researcher have been in doubt about Dual EC? The design did not not make any sense at all. Not until you consider that it is designed with a back door, then it is a sleek minimal design that does exactly what it needs to do and not a whole lot more. If you couldn't see that from a mile away, then you might be too naive to work in security.

I don't know, why don't you take this question to Bruce Schneier?

"Sleek, minimal design". Heh.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#465

Earlier quoted context omitted.

It's not the first time either and it won't be the last. NIST chose Rijndael over Serpent for the AES standard even though Serpent won. I vaguely recall they gave some smarmy answer. I don't think anyone submitted a FOIA not that it would matter. I've been through that bloated semi-pseudo process and saw how easy it was to stall people not answer a simple question.

Rijndael was selected over Serpent for performance reasons.

I remember them saying that in a follow-on email on one of the mail list servers. That was not their original statement but I can't remember exactly what they said. I just remember it was quite smarmy and did not sit well with me coming from such an organization. Regardless Serpent won the challenge by their criteria but then they moved the goal posts after the fact.

Both Rijndael and Serpent could have equally become more performant in the AES-NI CPU instruction sets and I am also not ok with how that evolved either. Cipher fixation is a security vulnerability. AES-NI CPU instructions should have included a few ciphers for performance. Probably Rijndael, Serpent and Twofish. There are folks in the cryptography community that are very much against using more than one cipher and that makes it clear to me they have been compromised or manipulated by something.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#466
post #265
post #93

Earlier quoted context omitted.

Here's the counter-argument that I've seen in cryptography circles: Dual EC, a PRNG built on an asymmetric crypto template, was kind of a ham fisted and obvious NOBUS back door. The math behind it made such a backdoor entirely plausible. That's less obvious in other cases. Take the NIST ECC curves. If they're backdoored it means the NSA knows something about ECC we don't know and haven't discovered in the 20+ years s…

SM2 (Chinese), GOST (Russian) and NIST P (American) parameters are "you'll just have to straight up assume these are something up our sleeve numbers". ECGDSA/brainpool (German) and ECKCDSA (Korean) standards make an attempt to explain how they chose recommended parameters but at least for brainpool parameters, the justifications fall short. The DiSSECT[1] project recently published this year is an excellent approach…

That’s a great project, thank you for the link. Take my upvote stranger.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#467
post #265
post #93

Earlier quoted context omitted.

Here's the counter-argument that I've seen in cryptography circles: Dual EC, a PRNG built on an asymmetric crypto template, was kind of a ham fisted and obvious NOBUS back door. The math behind it made such a backdoor entirely plausible. That's less obvious in other cases. Take the NIST ECC curves. If they're backdoored it means the NSA knows something about ECC we don't know and haven't discovered in the 20+ years s…

SM2 (Chinese), GOST (Russian) and NIST P (American) parameters are "you'll just have to straight up assume these are something up our sleeve numbers". ECGDSA/brainpool (German) and ECKCDSA (Korean) standards make an attempt to explain how they chose recommended parameters but at least for brainpool parameters, the justifications fall short. The DiSSECT[1] project recently published this year is an excellent approach…

Interesting link, and yes it does look like the GOST curves are really suspect. I didn't see a graph for the NIST curves and they do not appear to have called them out.

There's a big difference though with the GOST curves. They were generated in what seems to be a 100% opaque manner, meaning they could have been back-calculated from something.

The NIST curves were generated in a way that was verifiably pseudorandom (generation involved a hash of a constant) but the constant was not explained. This makes it effectively impossible to straight-up back-calculate these curves from something else. NIST/NSA would have had to brute force search for parameters giving rise to breakable curves, which is the basis of the reasoning I've seen by cryptographers I quoted above.

Note that the cryptographers I've seen make this argument aren't arguing that the NIST curves could not be suspect. What they're arguing is that if they are in fact vulnerable and were found by brute force search using 90s computers, all of elliptic curve cryptography may be suspect. If we (hypothetically) knew for a fact they were vulnerable but did not know the vulnerability, we'd know that some troubling percentage of ECC curves are vulnerable to something we don't know and would have no way of checking other curves. We'd also have no way of knowing if other ECC constructions like Edwards curves or Koblitz curves are more or less vulnerable.

So the argument is: either the NIST curves are likely okay, or maybe don't use ECC at all.

Bruce Schneier was for a time a proponent of going back to RSA and classical DH but with large (4096+ bit) keys for this reason. RSA has some implementation gotchas but the math is better understood than ECC. Not sure if he still advocates this.

Personally I think the most likely origin of the NIST constants was /dev/urandom. Remember that these were generated back in the 1990s before things like curve rigidity was a popular topic of discussion in cryptography circles. The goal was to get working curves with some desirable properties and that's about it.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#468
post #157

Earlier quoted context omitted.

Speaking of dual-EC -- it does seem like 2 questions seem to be often debated, but it can't be neglected that some of the vocal debaters may be NSA shills: 1. does the use of standards actually help people, or make it easier for the NSA to determine which encryption method was used? 2. are there encryption methods that actually do not suffer from reductions in randomness or entropy etc when just simply running the al…

1. Formal, centralized crypto standards, be they NIST or IETF, are a force for evil. 2. All else equal, fewer dependencies on randomness are better. But all else is not equal, and you can easily lose security by adding determinism to designs willy-nilly in an effort to minimize randomness dependencies. Nothing is, any time in the conceivable future, change to make a broken RNG not game-over. So the important thing re…

The problem with formal centralized standards is that they tend to become ceilings rather than floors for quality, and it's hard to write them otherwise. They do however serve a function in keeping total snake oil crypto out of government and industry. Having some rubber stamp from people who at least know something keeps people with no knowledge of cryptography from buying the latest absolutely uncrackable post-quantum military grade AES-4096 cryptography product.

I'm also not sold on the idea that informal popularity contests or academic processes (which are often themselves opaque) are always superior to formalized cryptography standards. It's absolutely possible for modern intelligence agencies to infiltrate, steer, and subvert decentralized communities and private sector institutions. We see it all the time.

IMHO Internet culture is unbelievably naive about this. Everyone of course believes that they are hip and smart enough to spot astroturf and could never be conned. Everyone thinks only other people who are obviously less savvy and smart than them could be conned. "Wake up sheeple!" is never spoken to the mirror.

For all we know the NIST curves and AES are stronger than the other stuff and there's an astroturf effort to get non-government entities not to use them! Get the hipsters using vulnerable stuff while NIST/NSA keep recommending the good stuff for classified government use. How do we know DJB doesn't work for the NSA? (I do not believe any of this.!)

This way is madness. So I stick with the rule of "solid evidence or go home" when it comes to allegations and with general consensus of people who seem to know more than myself when it comes to algorithms and constructions.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#469

Earlier quoted context omitted.

> "I may believe almost all of this is overblown and silly, as like a matter of cryptographic research ..." Am I misunderstanding you, or are you saying that you believe almost all of DJB's statements claiming that NIST/NSA is doctoring cryptography is overblown and silly? If that's the case, would you mind elaborating?

I believe the implication that NIST or NSA somehow bribed one of the PQC researchers to weaken a submission is risible. I believe that NIST is obligated to be responsive to FOIA requests, even if the motivation behind those requests is risible.

No post body was provided.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#470
post #398

Earlier quoted context omitted.

FFS nobody is saying that the general idea of being skeptical is unreasonable. And nobody is being ridiculed for doing such. This subthread is about the contents of tptacek’s comment, which doesn't do what you are saying. Saying DJB’s claims are inconceivable is the mischaracterization. People are very eager to paint a picture nobody intended so they can say something and be right. I use djb’s crypto. Everybody knows…

You said this up thread and I find it incorrect: > If you RTFA you'd know it pertains to bribery, not coercion By quoting the article it seems the text directly contradicts your summary as being too narrow. General coercion is also be included as part of the concerns raised by TFA . He isn’t just talking about NSA giving a person a sack of money. Meanwhile in this thread and on Twitter, many people are indeed doing t…

The article discusses it generally but uses bribery as the example. Perhaps that’s the confusion. Someone said the idea that we’re gonna find bribes is silly. Someone else said that’s insane, how could you not imagine the govt doing something coercive. Reply was that’s not what I said. Another challenge follows asserting that the gov’t is generally shady and coercive. I tried to clarify what I see as the confusion (bribery vs coercion as an example used in the article). Sorry if my statement was overly broad, my intention was to say we’re probably mostly on the same side and arguing over semantics. Maybe not all of the world is (e.g. Twitter), but it seemed like the case here. Maybe not and tptacek believes the gov’t is infallible. IDK. I like DJB and appreciate what he’s doing.
Post reply on HN