Debunking NIST's calculation of the Kyber-512 security level
151–160 of 219 posts
Re: Debunking NIST's calculation of the Kyber-512 security level
#152Earlier quoted context omitted.
You mean ANSI/ISO/NIST and Dual_EC_DRBG, that everyone suspected had a backdoor before it was included as one of multiple options? https://en.m.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dua... Or the s-boxes in DES, that the NSA suggested to IBM + NIST's predecessor, so as to be resistant to then-not-widely-known differential cryptanalysis? https://web.archive.org/web/20120106042939/http://securespee...
One of those things happened after 9/11, and one of those things happened before. There is a widely held belief that the US IC changed fundamentally in terms of their regard for their own raison d’etre that day.
I'd like to think the US is in the midst of that now, with the Afghan withdrawal and Ukraine war.
Re: Debunking NIST's calculation of the Kyber-512 security level
#153Earlier quoted context omitted.
It works as a password hash for reasons having in part to do with why it isn’t a great general purpose cipher.
Can you expand, or link to an explanation?
Re: Debunking NIST's calculation of the Kyber-512 security level
#154If your codebase is hairy enough, and the problem to be solved is fundamentally fairly simple, sometimes it's better to rewrite than refactor. Doubly so if you believe a clever adversary has attempted to insert a subtle backdoor or bugdoor.
What would a better crypto selection process look like? I like the idea of incorporating "skin in the game" somehow... for example, the cryptographer who designs the scheme could wager some cash that it won't be broken within a particular timeframe. Perhaps a philanthropist could offer a large cash prize to anyone who's able to break the winning algorithm. Etc.
Re: Debunking NIST's calculation of the Kyber-512 security level
#155The unfortunate reality of this is that while he may be right , it is difficult to classify the responses (or non-response) from the NIST people as deceptive vs just not wanting to engage with someone coming from such an adversarial position. NIST is staffed by normal people who probably view aggressively worded requests for clarification in the same way that most of us have probably fielded aggressively worded bug r…
Edit: Just realized the author is djb, Daniel Bernstein, which I guess is semi-ironic for me because I was recently praising him on HN for an old, well-read blog post on ipv6. Thus, I guess I may take back a bit of what I said below, or least perhaps it would be better to say that I can better understand the adversarial tone given djb's history with NIST recommendations (more info at https://en.wikipedia.org/wiki/Dan…
The executive summary is above the fold:
Take a deep breath and relax. When cryptographers are analyzing the security of cryptographic systems, of course they don't make stupid mistakes such as multiplying numbers that should have been added.
If such an error somehow managed to appear, of course it would immediately be caught by the robust procedures that cryptographers follow to thoroughly review security analyses.
Furthermore, in the context of standardization processes such as the NIST Post-Quantum Cryptography Standardization Project (NISTPQC), of course the review procedures are even more stringent.
The only way for the security claims for modern cryptographic standards to turn out to fail would be because of some unpredictable new discovery revolutionizing the field.
Oops, wait, maybe not. In 2022, NIST announced plans to standardize a particular cryptosystem, Kyber-512. As justification, NIST issued claims regarding the security level of Kyber-512. In 2023, NIST issued a draft standard for Kyber-512.
NIST's underlying calculation of the security level was a severe and indefensible miscalculation. NIST's primary error is exposed in this blog post, and boils down to nonsensically multiplying two costs that should have been added.
How did such a serious error slip past NIST's review process? Do we dismiss this as an isolated incident? Or do we conclude that something is fundamentally broken in the procedures that NIST is following?
Re: Debunking NIST's calculation of the Kyber-512 security level
#156Earlier quoted context omitted.
Teams of cryptographers submit several proposals (and break each other's proposals). These people are well respected, largely independent, and assumed honest. Some of the mailing lists provided by NIST where cryptographers collaborated to review each other's work are public NIST may or may not consort with your friendly local neighborhood NSA people, who are bright and talented contributors in their own right. That's…
> NIST may or may not consort with your friendly local neighborhood NSA people It is worth noting that while breaking codes is a big part of the NSA's job, they also have a massive organization (NSA Cybersecurity, but I prefer the old name Information Assurance) that works to protect US and allied systems and cryptographic applications. In the balance, weakening American standards does little to help with foreign col…
While that makes logical sense, the previous actions of the NSA has demonstrated they're not a logical actor in regards to this stuff, or that there's more going on.
Re: Debunking NIST's calculation of the Kyber-512 security level
#157Earlier quoted context omitted.
Edit: Just realized the author is djb, Daniel Bernstein, which I guess is semi-ironic for me because I was recently praising him on HN for an old, well-read blog post on ipv6. Thus, I guess I may take back a bit of what I said below, or least perhaps it would be better to say that I can better understand the adversarial tone given djb's history with NIST recommendations (more info at https://en.wikipedia.org/wiki/Dan…
Even worse, I expected to find a part when he reports it and includes the responses/follow-up from that... But this is the first time it's published a far as I understand? Did I miss it in the wall of text? Or is it really a huge initial writeup that may end up with someone responding "oh, we did mess up, didn't we? Let's think how to deal with that."
He first raised the issue in April 2022.
Then in December 2022 he asked about the evaluation of Kyber's security and they posted this[1], which included a 2^40 multiple that he wasn't sure where it came from; if it came from where he thought it did (bogus math on numbers from a paper DJB himself coauthored), then that was troubling.
There was no response, so a few weeks later he posted his assumptions and asked if anyone else could come up with another possible explanation for what the NIST e-mail was assuming.
This did get a response[2], the main thrust of which was:
> While reviewers are free, as a fun exercise, to attempt to "disprove what NIST _appears_ to be claiming about the security margin," the results of this exercise would not be particularly useful to the standardization process. NIST's prior assertions and their interpretation are not relevant to the question of whether people believe that it is a good idea to standardize Kyber512.
After further prodding the response[3] was essentially a rather polite version of "You're the scientist and it's your model, why don't you tell us?" Which DJB considers dodging his question of "How did you get these numbers?"
At this point DJB posts[4] a dissection of the December 2022 e-mail, which is similar to the middle quarter of TFA.
1: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...
2: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...
3: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...
4: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...
Re: Debunking NIST's calculation of the Kyber-512 security level
#158That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…
It's all far too conspiratorial for me. Just show me the math as to why it's broken, I don't need a conspiratorial mind map drawing speculative lines between various topics. Do an appendix or two for that.