Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

61–70 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#61
post #58

Earlier quoted context omitted.

SHA3 is fine but it's so slow, I don't many people that use it

Slow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.

Faster than Blake2/3? Not even close!

Re: Mathematician warns US spies may be weakening next-gen encryption

#62
post #29

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

Where else are you going to go? The EU, UK and Australia are all bad for this in various ways, having key-disclosure laws or trying to ban e2e or whatever else. I don’t know about you but I don’t consider China or Russia to be valid places to look for un-backdoored crypto either. It seems (to this non-American) like one of the least-worst options. Maybe we could trust a Scandinavian country or Switzerland? (Yes, I ha…

Wasn’t Crypto AG - the Swiss company that was, oops, secretly owned by the CIA and West German intelligence - established by a Swede?

Re: Mathematician warns US spies may be weakening next-gen encryption

#63
post #11

I believe the push for passkeys is another avenue for this.

You don't need to weak cryptography to work towards that end with passkeys. For key pairs that can be transferred, it's no different than the threat of password managers stealing your keys to the castle. You just have to trust the cloud and your entire hardware and software stack your password and passkey manager run on, and/or that nothing in that stack gets swapped out without you noticing. Similarly, I've yet to s…

I believe the Solokey meets your definition. The hardware schematics are open, as is the software running on it.

The Precursor is also open hardware and software.

If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet .

And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall security posture would likely be weaker, but you could be confident, hopefully, that nobody has put some kind of backdoor into the hardware you designed yourself to run atop a generic array of logic gates.

Re: Mathematician warns US spies may be weakening next-gen encryption

#64
post #29

Earlier quoted context omitted.

Where else are you going to go? The EU, UK and Australia are all bad for this in various ways, having key-disclosure laws or trying to ban e2e or whatever else. I don’t know about you but I don’t consider China or Russia to be valid places to look for un-backdoored crypto either. It seems (to this non-American) like one of the least-worst options. Maybe we could trust a Scandinavian country or Switzerland? (Yes, I ha…

Wasn’t Crypto AG - the Swiss company that was, oops, secretly owned by the CIA and West German intelligence - established by a Swede?

Ha, there go my two 'good' options in one fell swoop!

Re: Mathematician warns US spies may be weakening next-gen encryption

#65
post #58

Earlier quoted context omitted.

SHA3 is fine but it's so slow, I don't many people that use it

Slow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.

Comparable in software, to what? Password hashes? :)

Re: Mathematician warns US spies may be weakening next-gen encryption

#66

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

I did not dig through all the links in that twitter thread, but the first few tweets are pretty misleading.

The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far ahead of what's being submitted that all they have to do is push NIST to pick an algorithm they know how to break.

Now, I have no knowledge of any of this, so I have no idea if DJB's argument is insanely paranoid like the author of the thread implies (with the GIF in the 3rd tweet). All I can see is that the author's claim is a gross mischaracterization of what DJB wrote.

Re: Mathematician warns US spies may be weakening next-gen encryption

#67

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

Thank you for posting this – it is important context:

"When his schemes won’t get picked by NIST, people will think it’s because they are not backdoored, and will point at the FOIA lawsuit as evidence."

Re: Mathematician warns US spies may be weakening next-gen encryption

#68

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Re: Mathematician warns US spies may be weakening next-gen encryption

#69
post #57
post #42

Earlier quoted context omitted.

Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.

Not exactly sure if explicitly declared output of the Kagi Universal Summarizer is allowed (will delete again if not, but I did not see a guideline for it), but I think this could be a start sparking further curiosity. (I don't know how accurate the output is, as I am not a domain expert in PQC or cryptography in general, for that matter) Kagi Universal Summarizer output for "Summary": This web page discusses the sel…

I don’t think this contributes to the conversation. There is clearly social context to this situation and copy pasting a machine-generated summary is no more helpful than reading the article at face value.

Re: Mathematician warns US spies may be weakening next-gen encryption

#70

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Every US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.
Post reply on HN