Earlier quoted context omitted.
I mean, if the source, training data, and query interface are public, it would be insanely difficult to hide a backdoor There i "designed" your impossible criterion in just a few obvious steps you could have inferred
There are many, many papers that show how you can make innocuous changes to inputs to make neutral nets produce the wrong result. You might be overestimating the difficulty of this process.
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
471–480 of 494 posts
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#472Earlier quoted context omitted.
Rijndael was selected over Serpent for performance reasons.
I remember them saying that in a follow-on email on one of the mail list servers. That was not their original statement but I can't remember exactly what they said. I just remember it was quite smarmy and did not sit well with me coming from such an organization. Regardless Serpent won the challenge by their criteria but then they moved the goal posts after the fact. Both Rijndael and Serpent could have equally becom…
You can believe whatever you want to believe, but the threshold you've just claimed to have for believing someone is compromised suggests that essentially every academic cryptographic researcher in the world is compromised.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#473Earlier quoted context omitted.
I think it's naive and trusting only on the surface, but with some clear intent and goal underneath. In the past he has held a different stance, but it suddenly changed some time after Matasano.
Can I ask that, if you're going to accuse me of shilling in an HN thread, you at least come up with something that I'm shilling? I don't care what it is; you can say that I'm shilling for Infowars Life ProstaGuard Prostate Health Supplement with Saw Palmetto and Anti-Oxidant, for all I care, just identify something .
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#474Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#475Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#476Earlier quoted context omitted.
"I think formal cryptographic standards are a force for evil." May I ask what you view as the alternative? (No formal cryptographic standard, or something else?)
Peer review and "informal standards". Good examples of things that were, until long after their widespread adoption, informal standards include Curve25519, Salsa20 and ChaCha20, and Poly1305. A great example of an informal standard that remains an informal standard despite near-universal adoption is WireGuard. More things like WireGuard. Less things like X.509.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#477Earlier quoted context omitted.
It’s not doublethink to say the programs should have been exposed and that Snowden was a traitor for exposing them in a manner that otherwise hurt our country. He could have done things properly, instead he dumped thousands of files unrelated to illegal surveillance to the media.
It absolutely is. Please read his book, it addresses this claim directly. You can't fix lawlessness by reporting the violation of law to the lawbreaker. This is also why police in the USA are out of control. You cannot fix a criminal conspiracy from within the criminal conspiracy . PS: nations don't exist, they are fictional abstractions. You cannot "hurt a country".
You absolutely can, especially with something as multifaceted as a country.
> nations don't exist, they are fictional abstractions. You cannot "hurt a country".
They do and you can.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#478Earlier quoted context omitted.
That's just wrong on so many levels. Troy Hunt has an excellent explanation: https://www.troyhunt.com/heres-why-your-static-website-needs...
Troy Hunt points out that HTTP traffic is sometimes MITMed in a way that clients and servers do not like, and HTTPS sometimes prevents that. I never said otherwise. I am saying for certain kinds of pages, it's not a major concern. Like for djb website. Why not use HTTPS for everything? Because it also has costs, not just benefits.
That's not really true. Certificates have been free for a long time and every CPU made within the last 10 years has AES acceleration. You can google white papers from companies like Cloudflare and Google, which actually show speedups with HTTP 2 or 3.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#479Earlier quoted context omitted.
> Everybody is on high alert. Being on high alert doesn't make Bernstein right. What exactly are you arguing for, with this? Pretty sure the dude you're replying to knows about the existence of cognitive biases, thanks.
It's pretty obvious, right? What Bernstein is saying here can (and probably is) a load of horseshit, and it's still a terrible idea to trust NIST. Seems like a simple argument.
Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
#480Earlier quoted context omitted.
It's pretty obvious, right? What Bernstein is saying here can (and probably is) a load of horseshit, and it's still a terrible idea to trust NIST. Seems like a simple argument.
Uh, would you take your simple argument and give me even a single sentence pointing out proof or clear indication it's horseshit. So far I only saw you arguing over words mostly