Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

101–110 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#101

Earlier quoted context omitted.

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

How is that in any way like working in an open kitchen?

Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

Re: Mathematician warns US spies may be weakening next-gen encryption

#102
Regrettably, while we are discussing the author's motives, we may inadvertently overlook the miscalculation by NIST. The crux of NIST's primary error lies in improperly multiplying two costs when they should have been added. If this assertion holds true, it would be prudent to at least revisit and revise their draft !

Re: Mathematician warns US spies may be weakening next-gen encryption

#103

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

Ha, you can say that in China too (about the US president lol).

United States of China.

Peoples Republic of United States.

Sounds the same.

Re: Mathematician warns US spies may be weakening next-gen encryption

#104
post #37
post #27

Earlier quoted context omitted.

NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.

The man walked into a bank many times over his life, no way he could decide to rob it one day.

And lest we forget Dual_EC_DRBG

Re: Mathematician warns US spies may be weakening next-gen encryption

#105
post #96

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

There is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not fro…

FWIW, I don't believe Bernstein is evil.

I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.

Re: Mathematician warns US spies may be weakening next-gen encryption

#107
post #93

Earlier quoted context omitted.

> My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time? [1] https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

Because Dual_EC_DRBG was very heavy handed. It was driven by NSA itself (and based on a paper named "Kleptography"!); the backdoor was obvious; and they had to ~bribe~ monetarily incentivize companies to actually implement and use it. Meanwhile, both NTRU and Kyber are lattice-based, and their designs came from honest attempts. To be an NSA effort, there would need to exist an exploitable flaw in Kyber, but not NTRU,…

There is definitely a selection bias if judging 'subtlety of NSA activities' by only examining 'NSA activities that were unsubtle enough to be discovered'.

Re: Mathematician warns US spies may be weakening next-gen encryption

#108

Earlier quoted context omitted.

You don't need to weak cryptography to work towards that end with passkeys. For key pairs that can be transferred, it's no different than the threat of password managers stealing your keys to the castle. You just have to trust the cloud and your entire hardware and software stack your password and passkey manager run on, and/or that nothing in that stack gets swapped out without you noticing. Similarly, I've yet to s…

I believe the Solokey meets your definition. The hardware schematics are open, as is the software running on it. The Precursor is also open hardware and software. If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet . And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall…

You'd have to choose your FPGA judiciously. The truly paranoid see the attack surface area of 100 GB of black box libraries needed to synthesize designs and appreciate the possibility of gateware trojans.

Re: Mathematician warns US spies may be weakening next-gen encryption

#109
post #24

Earlier quoted context omitted.

> that blog post for the past week https://blog.cr.yp.to/20231003-countcorrectly.html

Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.

How so? Its clear he's no journalist but I never found myself confused.

Re: Mathematician warns US spies may be weakening next-gen encryption

#110

Earlier quoted context omitted.

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

The people are still human beings. The process is still open to FOIA. It’s not perfect, but it’s the right solution.
Post reply on HN