Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

181–190 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#181
post #177

Earlier quoted context omitted.

It seems wildly shortsighted as well. I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust t…

Everyone also discounts the other reason NIST (with NSA behind the scenes) might be shifty -- they know of a mathematical or computational exploit class that no one else does. And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it. Without disclosing what "it" is. Everyone's quick to jump to the "NSA is weakening algorithms" explanation, but there's both historical a…

>there's both historical and practical precedent for the strengthening alternative.

I'm aware of the DES S-boxes, are there other examples of this?

Re: Mathematician warns US spies may be weakening next-gen encryption

#182
Dan bernstein wrote Qmail, DJBDNS and Cryptography algorithms

https://en.m.wikipedia.org/wiki/Bernstein_v._United_States

Qmail https://en.m.wikipedia.org/wiki/Qmail

Djbdns https://en.m.wikipedia.org/wiki/Djbdns

https://en.m.wikipedia.org/wiki/Daniel_J._Bernstein

Re: Mathematician warns US spies may be weakening next-gen encryption

#183
post #181
post #177

Earlier quoted context omitted.

Everyone also discounts the other reason NIST (with NSA behind the scenes) might be shifty -- they know of a mathematical or computational exploit class that no one else does. And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it. Without disclosing what "it" is. Everyone's quick to jump to the "NSA is weakening algorithms" explanation, but there's both historical a…

>there's both historical and practical precedent for the strengthening alternative. I'm aware of the DES S-boxes, are there other examples of this?

SHA was withdrawn after publication and replaced with a stronger version[0].

[0] https://en.wikipedia.org/wiki/SHA-1#Development

Re: Mathematician warns US spies may be weakening next-gen encryption

#184
post #30

Earlier quoted context omitted.

Applying this logic, there is literally nothing NIST could have done here other than not run the competition in the first place; if it's not enough that almost every participant in the competition agrees that it was well conducted --- if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything --- then all you're really saying is that there's no way to create a trustworthy sta…

> if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything This is precisely not what I'm saying (and isn't what's happening here). What I'm saying is that given the evidence presented about NIST repeatedly changing evaluation methods, incorrectly calculating the strength of the Kyber, and refusing to clarify any of the above, it really looks like NIST had an outcome that t…

https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...

Re: Mathematician warns US spies may be weakening next-gen encryption

#185

Earlier quoted context omitted.

But how do we prove the cooks aren't talking to each other outside the kitchen?

If there's something wrong with the work they do in the kitchen, it doesn't matter how that came to be. If there is nothing wrong with it, it doesn't matter what else (other than something that would make them do something they shouldn't in the kitchen) they talk about outside of the kitchen. The solution can't possibly be not even knowing the difference between someone putting salt or toe nails into a pan -- but ens…

How do we know the cooks aren't holding out on a better recipe for Alfredo sauce that uses more salt? The recipe they're using seems adequate, but there's a better formula they could be using by adding salt, except they've all gotten together outside of work to conspire against us and say there's nothing wrong with the amount of salt they're using. Who knows who's paying them to say this? We need to follow them everywhere, see who they see, read what they write, audit their bank records. We need proof.

Re: Mathematician warns US spies may be weakening next-gen encryption

#186
post #66

Earlier quoted context omitted.

I did not dig through all the links in that twitter thread, but the first few tweets are pretty misleading. The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far…

> no idea if DJB's argument is insanely paranoid Isn't paranoia an essential job requirement for cryptographers?

It isn’t paranoia when the NSA has been caught with their hand in the cookie jar before. There is no obligation to give known liars the benefit of the doubt.

Re: Mathematician warns US spies may be weakening next-gen encryption

#187
post #174

Earlier quoted context omitted.

That wouldn't explain the intentional destruction of the blackberry phones and the deletion of thousands of emails.

I'd say the haphazard destruction of Blackberries and iPads with hammers is pretty explicit evidence of how bad State Dept IT policy and execution was. Maybe I've worked in large corporations too much, but my first question when I see policy violations is not "How is this person conspiring?" but rather "What made following the official policy difficult? And how can we fix that?" Also, the State Dept seems like exactl…

She must've been unaware of her legal requirements under FOIA, that her husband signed into law, when she ordered the people's emails destroyed.

Re: Mathematician warns US spies may be weakening next-gen encryption

#188
post #100
post #99

Earlier quoted context omitted.

I’ve not followed the PQC competition very closely, but I don’t think djb’s arguments significantly impact whether you should use KYBER-512. From my reading, as someone with a decent amount of crypto knowledge, all the evidence suggests that it is more than secure enough. The rest of the stuff is at the level of “submit an erratum”, not “omg cancel the whole thing”. If anything, this reinforces my belief that KYBER i…

The last part I agree with - clearly KYBER isn't trivially broken if this is the best he can come up with. What doesn't seem clear to me, and I'd appreciate if you could tell me why you think differently, is that KYBER-512 isn't as strong as it was targeted to be. I find djb's argument on this narrow point fairly convincing: KYBER-512 isn't as secure as AES-128 (by the methods used to measure "secure" in this competi…

It’s possible that in the specific sense that NIST defined, KYBER-512 isn’t as strong as AES-128. However, that doesn’t mean that it’s less secure in general. E.g. DJB himself wrote a good article[1] on how even though 128-bit AES and 256-bit elliptic curve crypto are thought of as same “security level”, actually there are attacks against AES that just don’t apply to ECC when you consider multi-target security models (i.e., when you consider a population of users not just one). I wouldn’t be surprised if similar things applied to lattice-based crypto, but I don’t know enough about it. And even if we take the reduced security level given by DJB, it still seems big enough to be out of reach to any realistic attack.

But by all means feel free to go one bigger and pick KYBER-768, and I believe lots of people do recommend this. Obviously, there is a performance penalty (as there is when moving from AES 128 to 256), and for PQ schemes there is also more importantly also a big increase in the size of bytes on the wire when public keys have to be exchanged (e.g. in TLS) - in this case a jump from 800 bytes to 1,184 bytes (a 48% increase). (Compare this to ECC public keys which are typically around 32-65 bytes, depending on encoding).

[1]: https://blog.cr.yp.to/20151120-batchattacks.html

Re: Mathematician warns US spies may be weakening next-gen encryption

#189
post #16
post #11

I believe the push for passkeys is another avenue for this.

No passkeys are based on whatever the best crypto is -- for example in a world where quantum computers are practical then they'll be using a quantum safe algorithm. Spy agencies, law enforcement, and criminals would all much prefer people use easily guessable and/or unsafely stored passwords. Those are both easier to discover, easier to brute force, and easier to intercept (specifically all you need to do is intercep…

Or to grab your phone with a 4 digit pin and unlock every device you've secured with a passkey. At least previously your bad password was probably longer than a 4 digit pin.

Re: Mathematician warns US spies may be weakening next-gen encryption

#190
post #61

Earlier quoted context omitted.

Faster than Blake2/3? Not even close!

> Faster than Blake2/3? Not even close! Blake2 was not created (December 2012) until after the SHA-3 competition, which ended on October 2012 (Keccak being the winner). It was Blake1 that was entered. Blake3 was released in 2020. I'm sure a Keccak2/3 could have also been better than the original Keccak1, but that was not available either.

You never specified timing. You made a blanket statement as if it was still true.
Post reply on HN