Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

121–130 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#121
post #70

Earlier quoted context omitted.

Every US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.

Most officials communicate in ways that circumvent FOIA.

Adding to this FOIA doesn't guarantee useful answers. Having gone through the process whilst in the military I found a few loopholes. They can give a bloated answer with boxes and boxes of useless mostly unrelated information. They did this to me. They can also decline to answer and just say it's classified. They can also just decline to answer through stalling tactics. It served my purpose and that was to stall them from collecting DNA.

Re: Mathematician warns US spies may be weakening next-gen encryption

#122
post #96

Earlier quoted context omitted.

There is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not fro…

FWIW, I don't believe Bernstein is evil. I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.

> which from the outside can look like his points are unrefutable.

Just to be sure, this is not how I see it at all. I'm relatively convinced that the thing isn't backdoored rather than buying into this particular conspiracy theory.

But yeah, in general that is a risk when one doesn't engage despite disagreeing

Re: Mathematician warns US spies may be weakening next-gen encryption

#123
post #23
post #21

Earlier quoted context omitted.

That's not fair. NIST has a documented history of working with the NSA, intentionally hiding that interaction, and the outcome was a major security problem. So it seems DJB believes that NIST has not provided sufficient documentation, and given their history it's reasonable to take a position that if they don't do that, the outcome cannot be trusted. So the issue is that once NIST did that the irrevocably destroy any…

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

is there some prohibition at the NSA on bribing Europeans?

Re: Mathematician warns US spies may be weakening next-gen encryption

#124
post #78

The article is a bit weird, so here's my summary of the situation, as someone in the security field: - Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored b…

If “an academic is sour they didn’t receive credit” and “an academic wants to help the world” are both on the menu, you should always linger over the first possibility. Hell, I’m an academic and you should consider it in regards to this post.

Re: Mathematician warns US spies may be weakening next-gen encryption

#125

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

I'm now picturing a slightly different government to ours, where the oversight bodies have the additional function of making sure officials don't talk to one another outside of recorded meetings under the public's eye.

It seems like a huge burden. It is the kind of thing, though, that in a parallel universe would make total sense: our representatives should be beholden to us.

Re: Mathematician warns US spies may be weakening next-gen encryption

#126
post #96

Earlier quoted context omitted.

There is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not fro…

FWIW, I don't believe Bernstein is evil. I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.

I'm a bit worried that we'll adopted an algorithm widely, only to be told “gotcha! here's how to break it”. After all, it would be a great way to prove once and for all that an algorithm selection process can be subverted.

Re: Mathematician warns US spies may be weakening next-gen encryption

#127
post #70

Earlier quoted context omitted.

Every US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.

Most officials communicate in ways that circumvent FOIA.

Hillary Clinton's email server is a famous example of attempting to avoid FOIA requests.

Re: Mathematician warns US spies may be weakening next-gen encryption

#128
post #78

The article is a bit weird, so here's my summary of the situation, as someone in the security field: - Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored b…

If “an academic is sour they didn’t receive credit” and “an academic wants to help the world” are both on the menu, you should always linger over the first possibility. Hell, I’m an academic and you should consider it in regards to this post.

Thanks for providing some context Matthew, I specifically went to mastodon to get your take on this.

Re: Mathematician warns US spies may be weakening next-gen encryption

#129
post #61
post #58

Earlier quoted context omitted.

Slow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.

Faster than Blake2/3? Not even close!

> Faster than Blake2/3? Not even close!

Blake2 was not created (December 2012) until after the SHA-3 competition, which ended on October 2012 (Keccak being the winner). It was Blake1 that was entered. Blake3 was released in 2020.

I'm sure a Keccak2/3 could have also been better than the original Keccak1, but that was not available either.

Post reply on HN