Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

91–100 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#91
post #78

The article is a bit weird, so here's my summary of the situation, as someone in the security field: - Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored b…

> My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda.

Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time?

[1] https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

Re: Mathematician warns US spies may be weakening next-gen encryption

#92
post #66

Earlier quoted context omitted.

I did not dig through all the links in that twitter thread, but the first few tweets are pretty misleading. The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far…

> no idea if DJB's argument is insanely paranoid Isn't paranoia an essential job requirement for cryptographers?

Cryptography: is incorrect because and should therefore be . This allows a ciphertext produced by X to be breakable in 2²¹ operations when 2¹¹ messages are known to the attacker.

Paranoia: NSA bribes the independent reviewers and is backdooring the whole thing because everyone knows the military and intelligence services are two decades ahead of public research and we just don't know what the algorithm flaw is yet, but I'm telling you, they're keeping something behind!

I am not saying djb (or anyone) does the latter, example is given exaggerated for illustrative purposes only. The cryptographer's example is also exaggerated, as it does matter how algorithms are chosen and there's a measure of subjectivity involved. Still, I would not say that paranoia is the job of a cryptographer.

Re: Mathematician warns US spies may be weakening next-gen encryption

#93
post #78

The article is a bit weird, so here's my summary of the situation, as someone in the security field: - Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored b…

> My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time? [1] https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

Because Dual_EC_DRBG was very heavy handed. It was driven by NSA itself (and based on a paper named "Kleptography"!); the backdoor was obvious; and they had to ~bribe~ monetarily incentivize companies to actually implement and use it.

Meanwhile, both NTRU and Kyber are lattice-based, and their designs came from honest attempts. To be an NSA effort, there would need to exist an exploitable flaw in Kyber, but not NTRU, known only to the NSA. And it's not like NTRU as a whole got disqualified; only the fastest variant did.

That's the problem with spy agencies, you never know what they are capable of. But if it was an NSA effort, it would be, by far, the most subtle one uncovered so far.

Re: Mathematician warns US spies may be weakening next-gen encryption

#94

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Why not? Have you ever worked in an open kitchen?

If you can't do your work for the public under public scrutiny, you shouldn't.

Re: Mathematician warns US spies may be weakening next-gen encryption

#95
post #78

The article is a bit weird, so here's my summary of the situation, as someone in the security field: - Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored b…

> My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time? [1] https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

On the other hand, DES is an example of where people were sure that NSA persuaded IBM to weaken it but, to quote Bruce Schneier, "It took the academic community two decades to figure out that the NSA 'tweaks' actually improved the security of DES". https://www.cnet.com/news/privacy/saluting-the-data-encrypti...>

Re: Mathematician warns US spies may be weakening next-gen encryption

#96

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

There is so much to unpack in that thread and its references. A lot of he said she said.

For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not from the company themselves, and keeps things confidential. It's how we resolve the conflict where you can't just claim you're sick for unspecified reasons indefinitely and continue to expect money, but the employer isn't entitled to know your medical dossier either. This lets you have medical confidentiality and long-term sick leave where the employer can trust that appropriate action is being taken because they trust the impartial doctor to verify that. This is brought up as part of the conflict between djb, the author, and the university they work for. This isn't the only thing they allude to not knowing about while abuse was alleged to be allowed to happen by djb and others. I believe most of what is written, but at the same time, the problem is clearly being exacerbated by not using coworkers, friends, or even google/ddg to find out what legal system you've moved into. Djb even suggested they should take legal action, and HR offered arbitration, but the person declined both. So now the evidence amounts to their word on a blog and the alleged perpetrators faced zero consequences.

As much as such references serve to convince me of djb=evil, they also convince me there may be more to the story than one side.

Obviously I've just highlighted one thing here, there's a lot more he-said-she-said going on elsewhere in the threads that could give one pause in believing one side verbatim, even if they're likely right in spirit

Re: Mathematician warns US spies may be weakening next-gen encryption

#98
I’m not qualified enough to say who’s right or wrong but I’ve noticed a fair amount of comments invalidating the claims because of the author’s motives, ie. He’s a sore looser and has a big ego. I don’t see why that invalidates his claim that the algorithm is weaker than claimed. “Jerks” can be right too.

People are people and they come and go, but these NIST standards stay a long time.

Re: Mathematician warns US spies may be weakening next-gen encryption

#99
post #86
post #42

Earlier quoted context omitted.

Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.

Here's my honest shot at it: In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims. To make that argument, he points out a fairly egregious math mistake (the whole "2^40+2^40" bit) and then shows that NIST was inconsistent in applying the rules of the contest it refereed. He also offers an explanation for why NIST would be so inconsistent about it, namely that they were in…

I’ve not followed the PQC competition very closely, but I don’t think djb’s arguments significantly impact whether you should use KYBER-512. From my reading, as someone with a decent amount of crypto knowledge, all the evidence suggests that it is more than secure enough. The rest of the stuff is at the level of “submit an erratum”, not “omg cancel the whole thing”.

If anything, this reinforces my belief that KYBER is a good design. If this is the best he can come up with to try and discredit it, then it must be pretty solid.

Re: Mathematician warns US spies may be weakening next-gen encryption

#100
post #99
post #86

Earlier quoted context omitted.

Here's my honest shot at it: In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims. To make that argument, he points out a fairly egregious math mistake (the whole "2^40+2^40" bit) and then shows that NIST was inconsistent in applying the rules of the contest it refereed. He also offers an explanation for why NIST would be so inconsistent about it, namely that they were in…

I’ve not followed the PQC competition very closely, but I don’t think djb’s arguments significantly impact whether you should use KYBER-512. From my reading, as someone with a decent amount of crypto knowledge, all the evidence suggests that it is more than secure enough. The rest of the stuff is at the level of “submit an erratum”, not “omg cancel the whole thing”. If anything, this reinforces my belief that KYBER i…

The last part I agree with - clearly KYBER isn't trivially broken if this is the best he can come up with.

What doesn't seem clear to me, and I'd appreciate if you could tell me why you think differently, is that KYBER-512 isn't as strong as it was targeted to be. I find djb's argument on this narrow point fairly convincing: KYBER-512 isn't as secure as AES-128 (by the methods used to measure "secure" in this competition).

Given that I already generally use AES-256, why shouldn't I treat this the same way as AES-128?

That is, "it's probably fine-ish, but if you have the power, just go one bigger".

Post reply on HN