I've been in rooms watching cryptographers trying to figure out what exactly it is Bernstein was saying with that blog post for the past week, and I do not believe that Matthew Sparkes at The New Scientist understands it any better than they do. Since Sparkes doesn't have any direct reporting from Bernstein, and nobody here cares about the NIST quotes, the right thing to do here is to treat this story as a dupe.
> that blog post for the past week https://blog.cr.yp.to/20231003-countcorrectly.html
Mathematician warns US spies may be weakening next-gen encryption
41–50 of 218 posts
Re: Mathematician warns US spies may be weakening next-gen encryption
#42Earlier quoted context omitted.
> that blog post for the past week https://blog.cr.yp.to/20231003-countcorrectly.html
Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.
This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.
Re: Mathematician warns US spies may be weakening next-gen encryption
#43Earlier quoted context omitted.
It is very likely the NSA has an good understanding of the weaknesses of various algorithms in the face of their technology. After all that's their job. The comment above also makes sense when the NIST is advised by the NSA to influence their processes as to choose algorithms to their liking, no design by NIST needed.
The "major security problem" the previous commenter is referring to is an NSA design, not a competition winner. I think what's happened here is that you've read the preceding comment too generously, in particular by skipping big chunks of it.
Re: Mathematician warns US spies may be weakening next-gen encryption
#44Earlier quoted context omitted.
Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.
Ha, you can say that in China too (about the US president lol).
Re: Mathematician warns US spies may be weakening next-gen encryption
#45Earlier quoted context omitted.
The "major security problem" the previous commenter is referring to is an NSA design, not a competition winner. I think what's happened here is that you've read the preceding comment too generously, in particular by skipping big chunks of it.
I did not skip any parts, previous commenter is generalizing from this major security problem to a non-trustworthy NIST in general, and one power NIST has is to choose algorithms as standards which are known (to them) to be weak. While this is a discussion on probability and trustworthiness, where you can reasonably take stand on both sides, the argument itself is sound.
Re: Mathematician warns US spies may be weakening next-gen encryption
#46Earlier quoted context omitted.
so essentially: "because you only have worse choices"
Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.
Re: Mathematician warns US spies may be weakening next-gen encryption
#47Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.
These is somewhat better than not having such a system at all.
If nothing else, you get to benefit from public analysis and pick another of the algorithms that get proposed in the competition, even if it's not the NIST-blessed one.
Re: Mathematician warns US spies may be weakening next-gen encryption
#48Earlier quoted context omitted.
NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.
The man walked into a bank many times over his life, no way he could decide to rob it one day.
The original argument is not "they created encryption that isn't broken before". The argument is "encryption created by competitions that are only refereed by NIST is trustworthy"