Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

51–60 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#51
post #45
post #43

Earlier quoted context omitted.

I did not skip any parts, previous commenter is generalizing from this major security problem to a non-trustworthy NIST in general, and one power NIST has is to choose algorithms as standards which are known (to them) to be weak. While this is a discussion on probability and trustworthiness, where you can reasonably take stand on both sides, the argument itself is sound.

Yeah, you did. "any non-trivial numbers have to have a documented generation path, and any non-trivial numbers in those steps also have to have a documented generation path". This doesn't make any sense as a concern if you understand what Kyber is.

You conveniently skipped the "e.g." part.

Re: Mathematician warns US spies may be weakening next-gen encryption

#52

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

Half seriously, what's the difference between your career ruined via social credit being wiped by government or your career ruined via social credit being wiped on Twitter?

It's pretty simple to not be on Twitter. It's comparably hard to evade governments.

Re: Mathematician warns US spies may be weakening next-gen encryption

#53
post #26

Earlier quoted context omitted.

I think there's definitely probably some motivation in that, but I don't think it captures the whole issue. As in: I'm sure he probably personally feels emotional about that aspect of it, but the fact that he may have a personal emotional motivation does not make untrue any of the points he may be raising. But no disparagement to your point, I mean this sincerely: it is good work on that ad hominem if your goal is to…

CRYSTALS-Kyber is anything but a black box. It's an academic research project, about which a metric fuckload of rationale, critique, and rebuttal has been published openly.

Sorry, I should have been more clear; I meant the NSA process around these systems is a black box, because they are not publishing their internal calculus and activities around the development of these cryptosystems.

For instance, "showing your work" around the development of SHA0, or showing your internal research and attacks for CK.

Re: Mathematician warns US spies may be weakening next-gen encryption

#54
post #42

Earlier quoted context omitted.

Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.

Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.

He is basically being super nice about Kyber, and flames on NIST for selection being loose and tilted.

Re: Mathematician warns US spies may be weakening next-gen encryption

#55
post #27
post #17

Earlier quoted context omitted.

The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

SHA3 is fine but it's so slow, I don't many people that use it

Re: Mathematician warns US spies may be weakening next-gen encryption

#56
post #25

Earlier quoted context omitted.

True. But it's important to note that it is likely that, given the requirements of creating large, functioning systems of administration, it might be true that all governing systems are trying to solve the same types of problems. And it's worth remembering that, even in the US there exist examples of people who pushed for real change to these systems, and ended up detained, dead or simply disappeared. It might also b…

>This gives rise to the sense that democracy, at least in part, may be a deception that usefully provides people the illusion of a voice for change, while at the same time protecting the governing system by ensuring people do not seek more disruptive methods to alter it. As Churchill said, "democracy is the worst form of government, except all others". Are there elements in democracies that entrench the status quo? O…

I'm not an electoral mechanics geek but I appreciate the details, even if much of it flies over my head. Do you perchance have any resources where I could better understand such things?

Also, I think your points are very interesting but may benefit from some paragraphing for added clarity and coherence.

Another point of note is that, while interesting, it may be the case that no matter how much a government optimizes its electoral systems, it may still be subject to the other vulnerabilities listed above, which sadly might subsume any gains from such optimization.

Re: Mathematician warns US spies may be weakening next-gen encryption

#57
post #42

Earlier quoted context omitted.

Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.

Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.

Not exactly sure if explicitly declared output of the Kagi Universal Summarizer is allowed (will delete again if not, but I did not see a guideline for it), but I think this could be a start sparking further curiosity. (I don't know how accurate the output is, as I am not a domain expert in PQC or cryptography in general, for that matter)

Kagi Universal Summarizer output for "Summary":

This web page discusses the selection of the Kyber and NTRU cryptosystems as the quantum-resistant digital signature algorithms by the National Institute of Standards and Technology (NIST). It analyzes NIST's claims about the security levels of Kyber-512 compared to AES-128. While NIST argued Kyber-512's security level is boosted enough by memory access costs to meet the AES-128 threshold, the text raises uncertainties around accurately modeling such costs and argues NTRU may have advantages in flexibility and performance. Overall, the page questions whether NIST fully justified selecting Kyber-512 over NTRU given the uncertainties in quantifying the security of lattice-based cryptosystems against future attacks.

Kagi Universal Summarizer output for "Key moments":

- There is debate around whether Kyber-512 provides adequate security compared to the AES-128 benchmark. NIST claims it meets this level factoring in memory access costs, but others argue the analysis is uncertain.

- NIST's analysis added 40 bits of estimated security to Kyber-512's post-quantum security level due to memory costs, bringing it above the AES-128 threshold. Critics question this calculation.

- NTRU provides greater flexibility than Kyber in supporting a wider range of security levels. At some levels it also has better performance and security than Kyber options.

- The security of lattice-based cryptosystems like Kyber and NTRU is not fully understood, and there is a risk of better attacks being discovered in the future.

- Standardizing a system like Kyber-512 that may have limited security margin could be reckless given lattice cryptanalysis uncertainties.

- Critics argue NIST has not clearly explained its security evaluations and claims about Kyber-512's margin above AES-128.

- Memory access costs are important to lattice security but are not fully quantified in their impact on Kyber versus classical attacks on AES.

- Removing Kyber-512 could make NTRU the strongest candidate given its flexibility at multiple security levels.

- One paper argued multi-ciphertext attacks on Kyber may be as difficult as single-ciphertext attacks.

- There are calls for NIST to be transparent about its analysis and decision making regarding Kyber-512.

Re: Mathematician warns US spies may be weakening next-gen encryption

#58
post #27

Earlier quoted context omitted.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

SHA3 is fine but it's so slow, I don't many people that use it

Slow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.

Re: Mathematician warns US spies may be weakening next-gen encryption

#59
Ironically, the style and substance of DJB's engagement with his peers and with NIST is likely to sour both against his claims[0], credible though they(might) be. DJB's impression of NIST "stonewalling" could very well be their reluctance in engaging with an adversarial and increasingly deranged private citizen.

> We disagree with his analysis,” says Dustin Moody at NIST. “It’s a question for which there isn’t scientific certainty and intelligent people can have different views. We respect Dan’s opinion, but don’t agree with what he says.

That's great for a PopSci article, but I(and many others, I'm sure) would like to see the details of this analysis hashed out. DJB had his chance at making this happen, and blew it. However, that doesn't mean his questions[0] should go unanswered.

[0]: specifically talking about the calculation of the Kyber-512 security level here. Not his more conspiratorial claims.

Re: Mathematician warns US spies may be weakening next-gen encryption

#60
post #27

Earlier quoted context omitted.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

SHA3 is fine but it's so slow, I don't many people that use it

SHA3 is mostly a hedge for the risk SHA2 is broken.
Post reply on HN