Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

161–170 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#161

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

Strong agree. I've heard Bernstein described before now has having "all the subtlety of The Incredible Hulk". Quite possibly there's some things he can get away with only because he's a brilliant cryptographer.

Designing curve25519 was, in terms of practical impact, an achievement I'd put in the same category as inventing RSA or Diffie-Hellman. Not because the ideas were new, but because they came together in a way that produces something that "just works" in practice, and you don't have to worry about invalid curve points and twist attacks and accidentally using the addition formula for a point doubling and many other things. The idea that instead of a framework where you can plug in your own parameter choices and some of them might be secure, you can just build a crypto library that does one thing well, was certainly new enough that no-one else seemed to be doing it at the time. The fact that when I need a key for real, most of the time I do `ssh-keygen -t ed25519` or the equivalent in other systems speaks for itself.

As does the fact that github has deprecated the ssh-dss key type and recommends ed25519 and the default: in the contest between Ed25519 and DSA/ECDSA for digital signatures, Bernstein wins hands down and NIST has egg on their face. Although I have no proof of malice, I haven't yet heard a rational explanation for just how badly ECDSA mangles the Schnorr protocol in exactly the way that means a lot of implementations end up with horrible security holes.

And then there's the Snowden leaks and DUAL_EC. "The NSA has interfered with crypto standards in the past, reliable leaks show it was part of their mission statement, and they could be doing so again." is to me a statement backed up by plausible evidence that's very far from the usual conspiracy theories. This is not faked-moon-landings territory.

And I should also say, there are a lot of ways of being evil that to my knowledge no-one has ever accused Bernstein of: as far as I know, he's never been accused of raping or sexually assaulting anyone, nor has he said anything particularly racist or pushed any far-right ideology. He has been accused of insulting and occasionally threatening people who disagree with him on technical matters, but he's not what we usually mean by "bad/evil person, avoid if possible".

I'd say he has a fairly spotless track record in cryptographic protocol design, and a fairly stained one in interacting with other humans. When he's pushing back against design decisions that actually are stupid/evil, that's an asset; in lots of other cases it's not.

Re: Mathematician warns US spies may be weakening next-gen encryption

#162

Earlier quoted context omitted.

> view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. Without any /sarcasm tags I have to take that on face value, and frankly there are few words to fully describe what a colossally stupid idea (not your idea, I am sure) that is. Belief in containable backdoors is the height of naivety a…

> Belief in containable backdoors is the height of naivety What if it is acceptable for potential enemies to (eventually) also have access to that backdoor, and your goal in providing the backdoor is just to give the masses a false belief that they can communicate secretly? Obviously those in the know would not use the flawed system, but instead would have a similar/better one without the intentional flaws.

> Obviously those in the know would not use the flawed system

Perhaps the clearest argument against such a ploy is the TETRA radio system. Turns out in this case that "the masses" are our:

- police and emergency services

- military and civil defence forces

- diplomatic and political security, escorts, attaches and close security

You see the problem is this concept of "in the know". It's an insoluble information-hazard and boundary problem;

Two people can keep a secret, if one of them is dead.

Re: Mathematician warns US spies may be weakening next-gen encryption

#163
post #95

Earlier quoted context omitted.

> My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time? [1] https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

On the other hand, DES is an example of where people were sure that NSA persuaded IBM to weaken it but, to quote Bruce Schneier, "It took the academic community two decades to figure out that the NSA 'tweaks' actually improved the security of DES". https://www.cnet.com/news/privacy/saluting-the-data-encrypti... >

NSA did persuade them to weaken DES by shortening the key size. The "magic S-boxes" were chosen to be resistant to differential cryptanalysis (which was successfully kept secret for decades to come) but that doesn't change the fact NSA had the means to break DES by brute force.

Re: Mathematician warns US spies may be weakening next-gen encryption

#164
post #157
post #23

Earlier quoted context omitted.

This is a comment that only makes sense if you believe NIST designed CRYSTALS-Kyber, or had a significant hand in its design. But nothing of the sort happened. The CRYSTALS team is overwhelmingly academic and overwhelmingly European. It's frustrating that Bernstein has communicated about this without making that clear, because it's obvious that lots of people believe NIST went off in a room and came up with a scheme,…

It doesn't actually matter. NIST should not be involved at all. Jesus this is basic, if all they're doing is refereeing a competition there's really no excuse for them to be involved at all.

They're the American national standards organization. The point of the competition is to pick a standard.

Re: Mathematician warns US spies may be weakening next-gen encryption

#165
post #30

Earlier quoted context omitted.

I don't think the problem is that kyber was designed weak. the fear is that the NSA/NIST saw an algorithm that was weaker than it should be and worked nice and hard to make sure it became the standard. the worry isn't a back door, it's unintentional mistakes that are being capitalized on.

Applying this logic, there is literally nothing NIST could have done here other than not run the competition in the first place; if it's not enough that almost every participant in the competition agrees that it was well conducted --- if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything --- then all you're really saying is that there's no way to create a trustworthy sta…

> if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything

This is precisely not what I'm saying (and isn't what's happening here). What I'm saying is that given the evidence presented about NIST repeatedly changing evaluation methods, incorrectly calculating the strength of the Kyber, and refusing to clarify any of the above, it really looks like NIST had an outcome that they wanted to reach and took the actions necessary to reach that outcome. It's also really weird to say "it's not enough that almost every participant in the competition agrees that it was well conducted" in response to the lead designers of one of the two primary algorithms saying that the competition wasn't well conducted. With a competition like this, you do expect some people to think that the decision criteria weren't quite the right ones or something like that, but here there's a very clear accusation that NIST either just lied about the security of Kyber or messed it up and refused to correct it when it was pointed out to them.

Re: Mathematician warns US spies may be weakening next-gen encryption

#166
post #3

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

Because your options are Beijing or DC. We like to pretend the age of empires is past but realistically we still live in a time of where there are two major world powers and everyone gets to decide which side of the line they want to fall on, accept American hegemony or submit to Chinese control.

> Because your options are Beijing or DC

What kind of mental contortions do you have to go through to think like this? It comes off like gung-ho ignorance at best, and reeks of some of the most obvious american military propaganda I've ever read.

Re: Mathematician warns US spies may be weakening next-gen encryption

#167
post #22

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

NIST refereed a competition among the best-regarded academic cryptographers in the world. It didn't design any of these constructions, and practically all of the inputs into the competition, including the critiques of the submissions, came from academics (many of them not American). One of the annoying things about how Bernstein is communicating about this is that he is counting on his audience not knowing this.

This is all nice and well, but it doesn't actually address the inherent untrustworthiness of a state-associated (and known to be penetrated) organization.

Re: Mathematician warns US spies may be weakening next-gen encryption

#168

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

NIST promotes open competitions with many non-US based participants, e.g. AES was designed by Belgian researchers. These is somewhat better than not having such a system at all. If nothing else, you get to benefit from public analysis and pick another of the algorithms that get proposed in the competition, even if it's not the NIST-blessed one.

The issue is not AES of course, it's the NIST being associated with a government that can't be trusted when it comes to developing reliable and trustworthy encryption schemes. They've clearly demonstrated this time and time again.

Re: Mathematician warns US spies may be weakening next-gen encryption

#169
post #29

Why does anyone take a US-based seriously as a standards authority? It seems like a transparent conflict of interest.

Where else are you going to go? The EU, UK and Australia are all bad for this in various ways, having key-disclosure laws or trying to ban e2e or whatever else. I don’t know about you but I don’t consider China or Russia to be valid places to look for un-backdoored crypto either. It seems (to this non-American) like one of the least-worst options. Maybe we could trust a Scandinavian country or Switzerland? (Yes, I ha…

> Where else are you going to go?

I don't know, but I'd start with getting buy-in from any interested country with an emphasis on not too much from any one. Where it's physically located is irrelevant, the issue is the clear commitment to the interests of the american state.

Re: Mathematician warns US spies may be weakening next-gen encryption

#170
post #18

Earlier quoted context omitted.

>Because your options are Beijing or DC. We have plenty of standards in Europe too :-) However, with cryptography historically the best crypto has been invented in the US and it made much more sense for allies to just use ready made solutions than to roll their own. Do countries on the US crypto exports ban lists have their own incompatible crypto? I dont know, they might, but they for sure don't share it as freely a…

> historically the best crypto has been invented in the US ENIGMA?

The Enigma machine was probably the weakest of its kind of machines. It had a critical security flaw in that it could never encipher a letter to itself, and most of its security came from the IV settings, which were communicated in such poor fashion that the Poles cracked it long before WW2 even started.

By contrast, the US and British rotor machines were never cracked by the Axis powers in WW2, and the other two German rotor ciphers were less thoroughly cracked by the Allies.

Post reply on HN