Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

141–150 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#142
post #133

Earlier quoted context omitted.

Hillary Clinton's email server is a famous example of attempting to avoid FOIA requests.

From what I hear, it's also an example of how ineptly run the State Dept's IT systems were. Complex tasks like "set up a new computer" had months of lead time.

That wouldn't explain the intentional destruction of the blackberry phones and the deletion of thousands of emails.

Re: Mathematician warns US spies may be weakening next-gen encryption

#143

Earlier quoted context omitted.

And SHA-1 is faster than SHA-2, with MD5 faster than both. But speed isn't the only reason to choose an algorithm.

As a non cryptographer this whole conversation chain has me confused. I though it was desirable for a good hashing algorithm to be slow to make brute force difficult.

[deleted]

Re: Mathematician warns US spies may be weakening next-gen encryption

#144

Earlier quoted context omitted.

And SHA-1 is faster than SHA-2, with MD5 faster than both. But speed isn't the only reason to choose an algorithm.

As a non cryptographer this whole conversation chain has me confused. I though it was desirable for a good hashing algorithm to be slow to make brute force difficult.

That's true for passwords (where you don't really use raw SHA or something, but rather something like bcrypt which is intentionally slow), not necessarily for all uses of passwords. E.g. computing a SHA sum of some binary doesn't need to be slow, it just has to be practically impossible to create a collision (which is what's required of every good cryptographic hash function).

Re: Mathematician warns US spies may be weakening next-gen encryption

#146
post #137

Earlier quoted context omitted.

I'm now picturing a slightly different government to ours, where the oversight bodies have the additional function of making sure officials don't talk to one another outside of recorded meetings under the public's eye. It seems like a huge burden. It is the kind of thing, though, that in a parallel universe would make total sense: our representatives should be beholden to us.

OTOH, ensuring our representatives are 100% beholden to us also means screaming in the next primary about every bipartisan deal made. Which has the net effect of decreasing the ability to reach nobody-is-happy compromises. Which is something else people say they want. I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well.

> I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well.

I hear that, and there's a case for it. Diplomacy, maneuvering and negotiation require secrets and enclaves.

So to allow for that you need a few things;

  -  Strict official records of affairs

  -  Strong penalties for fraud, malinfluence, intimidation

  -  Whistleblower protection
The last of these essential checks-and-balances has gone to shit our culture. Even if we pardoned Edward Snowden and made him a "hero of democracy" tomorrow, it's still a mountain of work to restore the essential sense of civic responsibility, patriotism and duty that allows those people who discover or witness corruption to step-up and challenge it safe in the knowledge that the law and common morality are on their side.

Re: Mathematician warns US spies may be weakening next-gen encryption

#147

Earlier quoted context omitted.

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

But how do we prove the cooks aren't talking to each other outside the kitchen?

Re: Mathematician warns US spies may be weakening next-gen encryption

#148

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

Half seriously, what's the difference between your career ruined via social credit being wiped by government or your career ruined via social credit being wiped on Twitter?

"due process"???

but we've gotta update this now that the law will turn to software

Re: Mathematician warns US spies may be weakening next-gen encryption

#149

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

It seems wildly shortsighted as well.

I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor.

In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust that it can spend on very narrow issues.

But over the years there have been enough strange things (Dual EC DRBG being the most notorious) that that trust, at least when it comes to crypto design, simply isn't there. My perception is that newer ECC standards promoted by NIST have been trusted substantially less than AES was when it was released, and I can think of a number of major issues over the years that would lead to this distrust.

The inevitable outcome is that NIST loses much of its influence on the industry, which certainly is not in its own interest.

Re: Mathematician warns US spies may be weakening next-gen encryption

#150

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

I'm now picturing a slightly different government to ours, where the oversight bodies have the additional function of making sure officials don't talk to one another outside of recorded meetings under the public's eye. It seems like a huge burden. It is the kind of thing, though, that in a parallel universe would make total sense: our representatives should be beholden to us.

Many governments do have laws like this, called "sunshine laws". Enforcing them can be difficult though, and often enough they fail to achieve the transparency that is their goal while also substantially hindering process.
Post reply on HN