Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

71–80 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#71
post #70

Earlier quoted context omitted.

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Every US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.

Is every conversation in a rest room recorded and available?

If you don't trust people creating cryptography standards you cannot really leave gaps, can you?

Re: Mathematician warns US spies may be weakening next-gen encryption

#72
post #37

Earlier quoted context omitted.

The man walked into a bank many times over his life, no way he could decide to rob it one day.

You are creating a strawman. The original argument is not "they created encryption that isn't broken before". The argument is "encryption created by competitions that are only refereed by NIST is trustworthy"

So it’s worse. They already robbed a bank in the past.

Re: Mathematician warns US spies may be weakening next-gen encryption

#73

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

Half seriously, what's the difference between your career ruined via social credit being wiped by government or your career ruined via social credit being wiped on Twitter?

> or your career ruined via social credit being wiped on Twitter?

Whose career got ruined actually? Johnny Depp is still making movies, Rammstein just announced a 2024 tour, JKR still is making millions upon millions every year with Harry Potter, Trump is likely to be the Republican candidate in 2024. "Cancel culture" isn't real.

Re: Mathematician warns US spies may be weakening next-gen encryption

#74
post #52

Earlier quoted context omitted.

Half seriously, what's the difference between your career ruined via social credit being wiped by government or your career ruined via social credit being wiped on Twitter?

It's pretty simple to not be on Twitter. It's comparably hard to evade governments.

Just because you are not on Twitter (or Facebook, or whatever) won't stop other people from tweeting lies about you. And the public image that you have on social media matters a lot in this society. See also: "Cancel culture".

Re: Mathematician warns US spies may be weakening next-gen encryption

#76

Earlier quoted context omitted.

You don't need to weak cryptography to work towards that end with passkeys. For key pairs that can be transferred, it's no different than the threat of password managers stealing your keys to the castle. You just have to trust the cloud and your entire hardware and software stack your password and passkey manager run on, and/or that nothing in that stack gets swapped out without you noticing. Similarly, I've yet to s…

I believe the Solokey meets your definition. The hardware schematics are open, as is the software running on it. The Precursor is also open hardware and software. If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet . And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall…

Nice, last time I looked the Solo Hacker Edition was completely out of stock.

Looks like the Solo HE lets you load your own firmware on to it, but it doesn't let you load your own signing or encryption key to ensure firmware updates are trusted. Apparently the Solo HE can be flashed once permanently by overwriting the bootloader, though.

The non-HE versions of the Solo 1 and 2 will load new firmware signed by Solokey.

Earlier this year I looked into this and remember finding out that it was either the Solo 1/2, Somu or one of the Nitrokey products that, while shipping with a secure element, didn't actually use the secure element.

Re: Mathematician warns US spies may be weakening next-gen encryption

#77

Such a sad time for science. We really seem to be entering the new dark ages. There is no room for curiosity or intellect anymore. The institutions cannot be trusted and people rightly do not trust them.

The dark ages are called dark, partly because little history was recorded. That period saw more technological innovation than the well documented imperial period before it which was technologically stagnant in comparison. We live in the best documented period in history, but our technology could stagnate independently of that, or even due to it.

Re: Mathematician warns US spies may be weakening next-gen encryption

#78
The article is a bit weird, so here's my summary of the situation, as someone in the security field:

- Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored by Berstein).

- His main complaint is that NIST is playing fast and loose with the selection process, and had disqualified a fast NTRU variant due to barely not meeting a certain security threshold. The missing variant makes NTRU look slower and less flexible than it actually is.

- Meanwhile, NIST accepted a similar fast Kyber variant based on shaky assumptions. Berstein argues at length that it doesn't meet the security threshold either and should be disqualified. Funnily, NIST used Berstein's own research in (seemingly) incorrect fashion to argue for Kyber's security.

- There's an air of impropriety, as if NIST was favoring one algorithm over the other, for unknown reasons. And in the beginning of the post, Berstein shows the results of his recent lawsuit to reveal more information about the internal NIST process: it seems that NIST and NSA met more often than previously thought.

My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. One could argue that Berstein is sour that his algorithm might not be picked, and is trying underhanded tactics. On the other hand, he does have excellent reputation, and convincingly argues that NIST made an important mistake and is not transparent enough.

[0] https://www.metzdowd.com/pipermail/cryptography/2016-March/0...

[1] https://blog.cr.yp.to/20231003-countcorrectly.html

Re: Mathematician warns US spies may be weakening next-gen encryption

#79
post #27
post #17

Earlier quoted context omitted.

The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

A competition is the perfect way to subvert a standard. A competition looks 'open', but in fact you can 'collaborate' with any team to make your weakened encryption and then persuade the judging panel to rate it highly.

Re: Mathematician warns US spies may be weakening next-gen encryption

#80
post #70

Earlier quoted context omitted.

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Every US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.

Most officials communicate in ways that circumvent FOIA.
Post reply on HN