Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

21–30 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#21
post #8

Earlier quoted context omitted.

DJB has a historical record of being correct on crypto. His 'tantrums' led to Bernstein v. United States, which established source code as speech.

DJB is obviously a talented cryptographer, but he’s also clearly got a big ego. He’s drawing unfounded conclusions to discredit the work of other cryptographers whose work was chosen over his own.

That's not fair. NIST has a documented history of working with the NSA, intentionally hiding that interaction, and the outcome was a major security problem. So it seems DJB believes that NIST has not provided sufficient documentation, and given their history it's reasonable to take a position that if they don't do that, the outcome cannot be trusted.

So the issue is that once NIST did that the irrevocably destroy any basis to say "you can trust us". Hence they cannot have anything that they cannot document the source for. e.g. any non-trivial numbers have to have a documented generation path, and any non-trivial numbers in those steps also have to have a documented generation path.

Let's assume for now NIST is being 100% honest, and there's no attempted subterfuge. How can we distinguish that from them intentionally hiding subterfuge? Even though in this hypothetical where we're assuming no corruption, we have no way to know unless we have everything.

It's not reasonable for anyone at this point to have an algorithm that has any unexplained numbers, but for an organization that is again documented as having sabotaged standards it's absurd.

Re: Mathematician warns US spies may be weakening next-gen encryption

#22

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

NIST refereed a competition among the best-regarded academic cryptographers in the world. It didn't design any of these constructions, and practically all of the inputs into the competition, including the critiques of the submissions, came from academics (many of them not American).

One of the annoying things about how Bernstein is communicating about this is that he is counting on his audience not knowing this.

Re: Mathematician warns US spies may be weakening next-gen encryption

#23
post #21

Earlier quoted context omitted.

DJB is obviously a talented cryptographer, but he’s also clearly got a big ego. He’s drawing unfounded conclusions to discredit the work of other cryptographers whose work was chosen over his own.

That's not fair. NIST has a documented history of working with the NSA, intentionally hiding that interaction, and the outcome was a major security problem. So it seems DJB believes that NIST has not provided sufficient documentation, and given their history it's reasonable to take a position that if they don't do that, the outcome cannot be trusted. So the issue is that once NIST did that the irrevocably destroy any…

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme, and your first responsibility in discussing this honestly is to dispel that misconception.

Re: Mathematician warns US spies may be weakening next-gen encryption

#24
post #20

I've been in rooms watching cryptographers trying to figure out what exactly it is Bernstein was saying with that blog post for the past week, and I do not believe that Matthew Sparkes at The New Scientist understands it any better than they do. Since Sparkes doesn't have any direct reporting from Bernstein, and nobody here cares about the NIST quotes, the right thing to do here is to treat this story as a dupe.

> that blog post for the past week

https://blog.cr.yp.to/20231003-countcorrectly.html

Re: Mathematician warns US spies may be weakening next-gen encryption

#25

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

True. But it's important to note that it is likely that, given the requirements of creating large, functioning systems of administration, it might be true that all governing systems are trying to solve the same types of problems. And it's worth remembering that, even in the US there exist examples of people who pushed for real change to these systems, and ended up detained, dead or simply disappeared. It might also b…

>This gives rise to the sense that democracy, at least in part, may be a deception that usefully provides people the illusion of a voice for change, while at the same time protecting the governing system by ensuring people do not seek more disruptive methods to alter it.

As Churchill said, "democracy is the worst form of government, except all others". Are there elements in democracies that entrench the status quo? Of course, especially in countries like the UK and the US with single member district, first past the post systems that favor huge parties that never change. Here we have a pretty complex party list based system that is often critiqued as "too difficult to understand for the average voter", but when people want to change who rules the country they have more than 1 viable choice of opposition. You may say, nah, it is not about the system of voting, duopoly is a feature of "mature" democracies that have been around for 400 years. To which I'll give an example of Poland where the lower chamber of parliament (Sejm) is voted for party lists proportionally and it always has a mix of many parties, and the upper chamber (Senat) that uses the classic "first past the post" system and in the senate 2 major parties(the biggest party and the current biggest opposition party) always get 95%+ of the seats.

Re: Mathematician warns US spies may be weakening next-gen encryption

#26

[flagged]

I think there's definitely probably some motivation in that, but I don't think it captures the whole issue. As in: I'm sure he probably personally feels emotional about that aspect of it, but the fact that he may have a personal emotional motivation does not make untrue any of the points he may be raising. But no disparagement to your point, I mean this sincerely: it is good work on that ad hominem if your goal is to…

CRYSTALS-Kyber is anything but a black box. It's an academic research project, about which a metric fuckload of rationale, critique, and rebuttal has been published openly.

Re: Mathematician warns US spies may be weakening next-gen encryption

#27
post #17

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

Re: Mathematician warns US spies may be weakening next-gen encryption

#28
post #23
post #21

Earlier quoted context omitted.

That's not fair. NIST has a documented history of working with the NSA, intentionally hiding that interaction, and the outcome was a major security problem. So it seems DJB believes that NIST has not provided sufficient documentation, and given their history it's reasonable to take a position that if they don't do that, the outcome cannot be trusted. So the issue is that once NIST did that the irrevocably destroy any…

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

I don't think the problem is that kyber was designed weak. the fear is that the NSA/NIST saw an algorithm that was weaker than it should be and worked nice and hard to make sure it became the standard. the worry isn't a back door, it's unintentional mistakes that are being capitalized on.

Re: Mathematician warns US spies may be weakening next-gen encryption

#29

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

Where else are you going to go?

The EU, UK and Australia are all bad for this in various ways, having key-disclosure laws or trying to ban e2e or whatever else. I don’t know about you but I don’t consider China or Russia to be valid places to look for un-backdoored crypto either.

It seems (to this non-American) like one of the least-worst options. Maybe we could trust a Scandinavian country or Switzerland?

(Yes, I have missed out huge swathes of the world, which I mostly know little about…)

Re: Mathematician warns US spies may be weakening next-gen encryption

#30
post #23

Earlier quoted context omitted.

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

I don't think the problem is that kyber was designed weak. the fear is that the NSA/NIST saw an algorithm that was weaker than it should be and worked nice and hard to make sure it became the standard. the worry isn't a back door, it's unintentional mistakes that are being capitalized on.

Applying this logic, there is literally nothing NIST could have done here other than not run the competition in the first place; if it's not enough that almost every participant in the competition agrees that it was well conducted --- if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything --- then all you're really saying is that there's no way to create a trustworthy standard.

And, to that, I say: hell yes. Cryptographic standards are, in my view, a force for evil. Nobody uses Blake2 because it's "standardized"; they use it because there's a rough consensus of credible, credentialed cryptographers that it's strong, and it's obviously fast. We can do Internet cryptography without entities like NIST and the IETF.

This is something Bernstein believes as well; he's said it before (I have my view on standards in part because of his own). But he's not being honest about that here: had his submission won, he'd have endorsed the competition, even though the exact same logic holds --- he should, by this logic, trust his own submission less if it wins.

But I also want to be especially candid here: this "NIST is acting as the catspaw of NSA by selecting the weakest standard" argument is also the standard rhetorical fallback for arguers who have just this instant learned that NIST didn't itself design CRYSTALS-Kyber, but don't want to surrender their credibility by admitting it.

Post reply on HN