Live data from Hacker News

NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

blog.cr.yp.to

471–480 of 494 posts

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#471
post #364

Earlier quoted context omitted.

I mean, if the source, training data, and query interface are public, it would be insanely difficult to hide a backdoor There i "designed" your impossible criterion in just a few obvious steps you could have inferred

There are many, many papers that show how you can make innocuous changes to inputs to make neutral nets produce the wrong result. You might be overestimating the difficulty of this process.

Could be worse. At least I don't dismiss entire classes of problems simply because they sound hard.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#472

Earlier quoted context omitted.

Rijndael was selected over Serpent for performance reasons.

I remember them saying that in a follow-on email on one of the mail list servers. That was not their original statement but I can't remember exactly what they said. I just remember it was quite smarmy and did not sit well with me coming from such an organization. Regardless Serpent won the challenge by their criteria but then they moved the goal posts after the fact. Both Rijndael and Serpent could have equally becom…

Please cite for me the most credible cryptographic researcher you can find who advocates cascades of ciphers. I'm not certain, but if I had to bet, I'd bet that you can't even find one.

You can believe whatever you want to believe, but the threshold you've just claimed to have for believing someone is compromised suggests that essentially every academic cryptographic researcher in the world is compromised.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#473

Earlier quoted context omitted.

I think it's naive and trusting only on the surface, but with some clear intent and goal underneath. In the past he has held a different stance, but it suddenly changed some time after Matasano.

Can I ask that, if you're going to accuse me of shilling in an HN thread, you at least come up with something that I'm shilling? I don't care what it is; you can say that I'm shilling for Infowars Life ProstaGuard Prostate Health Supplement with Saw Palmetto and Anti-Oxidant, for all I care, just identify something .

It's very disconcerting, for the sake of open and honest discourse, that you or someone else decided to flag (and thus censor) my reply to this request.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#474

Earlier quoted context omitted.

Thanks for this reply. Can you point to a specific gross thing?

Sorry, I picked my words carefully in that last comment.

Is this related to his PhD advising of Appelbaum and his declaration in Todd v. Lovecruft?

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#476
post #293

Earlier quoted context omitted.

"I think formal cryptographic standards are a force for evil." May I ask what you view as the alternative? (No formal cryptographic standard, or something else?)

Peer review and "informal standards". Good examples of things that were, until long after their widespread adoption, informal standards include Curve25519, Salsa20 and ChaCha20, and Poly1305. A great example of an informal standard that remains an informal standard despite near-universal adoption is WireGuard. More things like WireGuard. Less things like X.509.

As much as I like the design of WireGuard, the original paper made stronger claims of security than were achieved with respect to key exchange models. Peer review and informal standards failed in catching this. From my perspective, the true benefit of a formal standardisation process such as this is that it dangles such a publishable target in front of researchers that we formally verify/disprove these claims out in the open.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#477
post #448

Earlier quoted context omitted.

It’s not doublethink to say the programs should have been exposed and that Snowden was a traitor for exposing them in a manner that otherwise hurt our country. He could have done things properly, instead he dumped thousands of files unrelated to illegal surveillance to the media.

It absolutely is. Please read his book, it addresses this claim directly. You can't fix lawlessness by reporting the violation of law to the lawbreaker. This is also why police in the USA are out of control. You cannot fix a criminal conspiracy from within the criminal conspiracy . PS: nations don't exist, they are fictional abstractions. You cannot "hurt a country".

> You can't fix lawlessness by reporting the violation of law to the lawbreaker

You absolutely can, especially with something as multifaceted as a country.

> nations don't exist, they are fictional abstractions. You cannot "hurt a country".

They do and you can.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#478
post #385
post #207

Earlier quoted context omitted.

That's just wrong on so many levels. Troy Hunt has an excellent explanation: https://www.troyhunt.com/heres-why-your-static-website-needs...

Troy Hunt points out that HTTP traffic is sometimes MITMed in a way that clients and servers do not like, and HTTPS sometimes prevents that. I never said otherwise. I am saying for certain kinds of pages, it's not a major concern. Like for djb website. Why not use HTTPS for everything? Because it also has costs, not just benefits.

> Because it also has costs, not just benefits.

That's not really true. Certificates have been free for a long time and every CPU made within the last 10 years has AES acceleration. You can google white papers from companies like Cloudflare and Google, which actually show speedups with HTTP 2 or 3.

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#479

Earlier quoted context omitted.

> Everybody is on high alert. Being on high alert doesn't make Bernstein right. What exactly are you arguing for, with this? Pretty sure the dude you're replying to knows about the existence of cognitive biases, thanks.

It's pretty obvious, right? What Bernstein is saying here can (and probably is) a load of horseshit, and it's still a terrible idea to trust NIST. Seems like a simple argument.

Uh, would you take your simple argument and give me even a single sentence pointing out proof or clear indication it's horseshit. So far I only saw you arguing over words mostly

Re: NSA, NIST, and post-quantum crypto: my second lawsuit against the US government

#480

Earlier quoted context omitted.

It's pretty obvious, right? What Bernstein is saying here can (and probably is) a load of horseshit, and it's still a terrible idea to trust NIST. Seems like a simple argument.

Uh, would you take your simple argument and give me even a single sentence pointing out proof or clear indication it's horseshit. So far I only saw you arguing over words mostly

I'm comfortable that, in the zillion words I've self-indulgently written on this thread, I've established both my bona fides and where I'm coming from with respect to the issues at play here, so in the interests of not repeating myself, I'm not going to repeat myself.
Post reply on HN