Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

31–40 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#31
Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him".

I want to push back on this a little by linking this Twitter thread:

https://nitter.net/FiloSottile/status/1555669786826244096

It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers.

It's entirely possible to be a brilliant cryptographer and also a petty person, those things aren't mutually exclusive.

Re: Mathematician warns US spies may be weakening next-gen encryption

#34
post #23
post #21

Earlier quoted context omitted.

That's not fair. NIST has a documented history of working with the NSA, intentionally hiding that interaction, and the outcome was a major security problem. So it seems DJB believes that NIST has not provided sufficient documentation, and given their history it's reasonable to take a position that if they don't do that, the outcome cannot be trusted. So the issue is that once NIST did that the irrevocably destroy any…

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

It is very likely the NSA has an good understanding of the weaknesses of various algorithms in the face of their technology. After all that's their job. The comment above also makes sense when the NIST is advised by the NSA to influence their processes as to choose algorithms to their liking, no design by NIST needed.

Re: Mathematician warns US spies may be weakening next-gen encryption

#35
post #34
post #23

Earlier quoted context omitted.

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

It is very likely the NSA has an good understanding of the weaknesses of various algorithms in the face of their technology. After all that's their job. The comment above also makes sense when the NIST is advised by the NSA to influence their processes as to choose algorithms to their liking, no design by NIST needed.

The "major security problem" the previous commenter is referring to is an NSA design, not a competition winner. I think what's happened here is that you've read the preceding comment too generously, in particular by skipping big chunks of it.

Re: Mathematician warns US spies may be weakening next-gen encryption

#36

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

Sounds like it's time that academia form a crypto equivalent of NIST amongst universities so they can put out transparent versions of new cryptographic algorithms that can be traced back to their birth so that other cryptographers can look for holes, if NIST is unwilling to be open about their processes.

Re: Mathematician warns US spies may be weakening next-gen encryption

#37
post #27
post #17

Earlier quoted context omitted.

The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

The man walked into a bank many times over his life, no way he could decide to rob it one day.

Re: Mathematician warns US spies may be weakening next-gen encryption

#39

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

Sounds like it's time that academia form a crypto equivalent of NIST amongst universities so they can put out transparent versions of new cryptographic algorithms that can be traced back to their birth so that other cryptographers can look for holes, if NIST is unwilling to be open about their processes.

Why aren't other participants in the competition --- most of them didn't win! --- saying the same thing? Why are the only two kinds of people making this argument a contest loser writing inscrutable 50,000 word manifestos and people on message boards who haven't followed any of the work in this field?

Re: Mathematician warns US spies may be weakening next-gen encryption

#40
post #23

Earlier quoted context omitted.

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

I don't think the problem is that kyber was designed weak. the fear is that the NSA/NIST saw an algorithm that was weaker than it should be and worked nice and hard to make sure it became the standard. the worry isn't a back door, it's unintentional mistakes that are being capitalized on.

[deleted]
Post reply on HN