Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

171–180 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#171
post #137

Earlier quoted context omitted.

OTOH, ensuring our representatives are 100% beholden to us also means screaming in the next primary about every bipartisan deal made. Which has the net effect of decreasing the ability to reach nobody-is-happy compromises. Which is something else people say they want. I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well.

> I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well. I hear that, and there's a case for it. Diplomacy, maneuvering and negotiation require secrets and enclaves. So to allow for that you need a few things; - Strict official records of affairs - Strong penalties for fraud, malinfluence, intimidation - Whistleblower protection The last of the…

Billions (the tv show), of all places, made a somewhat similar argument in favor of post-hoc investigations, in the last episode.

Record and share everything immediately = no room for deals

Record nothing = too much room for corruption

So we land at... record everything + only review with just cause + strict whistleblower protections.

Which seems a nice splitting of the matter, but requires a strong, independent third party (e.g. judicial branch) to arbitrate access requests. With tremendous pressure and incentives to breach that limit.

Re: Mathematician warns US spies may be weakening next-gen encryption

#173

Earlier quoted context omitted.

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

But how do we prove the cooks aren't talking to each other outside the kitchen?

If there's something wrong with the work they do in the kitchen, it doesn't matter how that came to be. If there is nothing wrong with it, it doesn't matter what else (other than something that would make them do something they shouldn't in the kitchen) they talk about outside of the kitchen.

The solution can't possibly be not even knowing the difference between someone putting salt or toe nails into a pan -- but ensuring cooks don't talk to each other, so even though we have no clue what they're doing or should be doing, we magically know nothing bad is going on.

Re: Mathematician warns US spies may be weakening next-gen encryption

#174
post #133

Earlier quoted context omitted.

From what I hear, it's also an example of how ineptly run the State Dept's IT systems were. Complex tasks like "set up a new computer" had months of lead time.

That wouldn't explain the intentional destruction of the blackberry phones and the deletion of thousands of emails.

I'd say the haphazard destruction of Blackberries and iPads with hammers is pretty explicit evidence of how bad State Dept IT policy and execution was.

Maybe I've worked in large corporations too much, but my first question when I see policy violations is not "How is this person conspiring?" but rather "What made following the official policy difficult? And how can we fix that?"

Also, the State Dept seems like exactly the sort of place policy violations become culturally routine: non-technical experts, doing work that is arguably "more important", with IT seen as a cost rather than profit center.

Perfect storm for policy-in-name-only.

Re: Mathematician warns US spies may be weakening next-gen encryption

#175

Earlier quoted context omitted.

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

How is it any different?

You don't have privacy in what you do at work when it comes to your employer. That's why it's called privacy, it relates to private and personal things. Your work for someone else is, by definition, not private.

You don't get to push stuff into production and play coy about what you're pushing, do you? Why would that change when the employer is the public?

Re: Mathematician warns US spies may be weakening next-gen encryption

#176

Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…

Strong agree. I've heard Bernstein described before now has having "all the subtlety of The Incredible Hulk". Quite possibly there's some things he can get away with only because he's a brilliant cryptographer. Designing curve25519 was, in terms of practical impact, an achievement I'd put in the same category as inventing RSA or Diffie-Hellman. Not because the ideas were new, but because they came together in a way t…

> I haven't yet heard a rational explanation for just how badly ECDSA mangles the Schnorr protocol in exactly the way that means a lot of implementations end up with horrible security holes.

I thought schnorr was under patent for a bit, so an open alternative was needed? Also ECDSA does allow for recovery of the public key from the signature, which can be useful.

Re: Mathematician warns US spies may be weakening next-gen encryption

#177

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

It seems wildly shortsighted as well. I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust t…

Everyone also discounts the other reason NIST (with NSA behind the scenes) might be shifty -- they know of a mathematical or computational exploit class that no one else does.

And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it.

Without disclosing what "it" is.

Everyone's quick to jump to the "NSA is weakening algorithms" explanation, but there's both historical and practical precedent for the strengthening alternative.

After all, if the US government and military use a NIST-standardized algorithm too... how is using one with known flaws good for the NSA? They have a dual mission.

Re: Mathematician warns US spies may be weakening next-gen encryption

#178

Earlier quoted context omitted.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

How is it any different? You don't have privacy in what you do at work when it comes to your employer. That's why it's called privacy, it relates to private and personal things. Your work for someone else is, by definition, not private. You don't get to push stuff into production and play coy about what you're pushing, do you? Why would that change when the employer is the public?

Putting aside finer points on privacy at work (depending on jurisdiction not so black and white), recording and making publicly available all work related communication goes way beyond usual surveillance at work places even in regulated communication settings. I have at least never worked in any place that would insist on recording any work related conversations with a co-worker during the morning commute (and to have that publicly available).

Re: Mathematician warns US spies may be weakening next-gen encryption

#179
post #59

Ironically, the style and substance of DJB's engagement with his peers and with NIST is likely to sour both against his claims[0], credible though they(might) be. DJB's impression of NIST "stonewalling" could very well be their reluctance in engaging with an adversarial and increasingly deranged private citizen. > We disagree with his analysis,” says Dustin Moody at NIST. “It’s a question for which there isn’t scient…

> It’s a question for which there isn’t scientific certainty and intelligent people can have different views.

WTF is that? No, it's not a question where intelligent people can have different views. DJB is literally claiming the NSA is claiming something similar to "3 + 3 = 9". That claim is either correct or not.

There's a paywall in front of the article that I have no intention to deal with after seeing what's on the comments. But a phrase like (and I could find it before the paywall rits) this is absolutely dishonest.

Re: Mathematician warns US spies may be weakening next-gen encryption

#180

Earlier quoted context omitted.

And SHA-1 is faster than SHA-2, with MD5 faster than both. But speed isn't the only reason to choose an algorithm.

SHA-2 is has more reliable HW acceleration from what I’ve seen. SHA-1 SW according to smhasher is 350mib/s as is MD5, so never use MD5 as SHA-1 is always stronger (sha2 supposedly is 150mib/s). Hw accelerated SHA-1 and SHA-2 are both ~1.5 Gib/s and on x86 HW acceleration is always available. Blake3 is the most interesting because it’s competitive with SHA2 even without HW acceleration. I wonder how it would fare with…

> Blake3 is the most interesting […]

Not really? SHA-2 was released in 2001:

* https://en.wikipedia.org/wiki/SHA-2

Blake3 was released 2020. I'm sure if the folks that created SHA-2 did a hash in 2020 they could do something better/faster as well.

Post reply on HN