Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

211–218 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#211
post #155
post #113

Earlier quoted context omitted.

Hm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected enough to warrant better responses. If he's turned so crank-y that his peers simply no longer engage with him beyond the strictly necessary, then this all looks a bit different. I'd still love to see some of his specific criticisms addressed,…

It actually doesn't, because NIST needs to speak to and be trusted by more than just a tiny clique. Djb crypto is widely known and used which means they have to deal with him whether they like it or not.

It does for me, because his criticism (since shown to be wrong) never included the claim that KYBER was broken, just that it wasn't perfect and that he was unfairly treated.

Cranks and assholes occasionally are unfairly treated, but generally are fairly ignored - the effort of dealing with their claims aren't worth it.

As an outsider, "respected cryptographer makes a narrow technical claim and is brushed off by NIST" and "sore loser that no-one talks to complains that people aren't entertaining his latest complaint about the ref" are very different situations, from which I will take very different actions.

This is looking more and more like the latter!

Re: Mathematician warns US spies may be weakening next-gen encryption

#213

"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that without being inside NIST" says Moody. There's our problem - right there! If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding an…

It seems wildly shortsighted as well. I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust t…

>I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor.

That's an incredibly charitable version of their point of view. How's this for their POV: They're angry that they can't see every single piece of communications, and they think they can get away with weakening encryption because nobody can stop them legally (because the proof is classified), and nobody's going to stop them by any other avenue either.

Re: Mathematician warns US spies may be weakening next-gen encryption

#214
post #177

Earlier quoted context omitted.

It seems wildly shortsighted as well. I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust t…

Everyone also discounts the other reason NIST (with NSA behind the scenes) might be shifty -- they know of a mathematical or computational exploit class that no one else does. And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it. Without disclosing what "it" is. Everyone's quick to jump to the "NSA is weakening algorithms" explanation, but there's both historical a…

> And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it.

Or, more likely, to exploit it.

Re: Mathematician warns US spies may be weakening next-gen encryption

#215
post #194

Earlier quoted context omitted.

She must've been unaware of her legal requirements under FOIA, that her husband signed into law, when she ordered the people's emails destroyed.

Or, she didn't even think about records retention or device security, in the same way that most politicians/executives don't, assuming it was handled by someone. And it was in fact not, because there was no functioning policy enforcement at State.

> there was no functioning policy enforcement at State

I agree, the laws were not enforced in this case.

Re: Mathematician warns US spies may be weakening next-gen encryption

#216

Earlier quoted context omitted.

> Blake3 is the most interesting […] Not really? SHA-2 was released in 2001: * https://en.wikipedia.org/wiki/SHA-2 Blake3 was released 2020. I'm sure if the folks that created SHA-2 did a hash in 2020 they could do something better/faster as well.

First, each Blake version was written by a totally different authors AFAICT so while each version is faster, making a faster construction was a totally different team. I don't see why you're putting so much confidence that the original SHA-2 team could come up with a faster hash function. FWIW, SHA-3 is slower than SHA-2 although of course SHA-3 is a totally different construction from SHA-2 by design.

[deleted]

Re: Mathematician warns US spies may be weakening next-gen encryption

#217

The open-source community will continue adopting "next-gen" "encryption" even though it has back doors, just like they didn't question elliptic curve encryption even after the NSA got caught putting out a compromised algorithm.

> The open-source community will continue adopting "next-gen" "encryption" even though it has back doors, just like they didn't question elliptic curve encryption even after the NSA got caught putting out a compromised algorithm.

The NSA put out a known compromised elliptic curve encryption algorithm? Or are you referring to Dual_EC_DRBG, a probably compromised random number generator?

Re: Mathematician warns US spies may be weakening next-gen encryption

#218
post #211
post #155

Earlier quoted context omitted.

It actually doesn't, because NIST needs to speak to and be trusted by more than just a tiny clique. Djb crypto is widely known and used which means they have to deal with him whether they like it or not.

It does for me, because his criticism (since shown to be wrong) never included the claim that KYBER was broken, just that it wasn't perfect and that he was unfairly treated. Cranks and assholes occasionally are unfairly treated, but generally are fairly ignored - the effort of dealing with their claims aren't worth it. As an outsider, "respected cryptographer makes a narrow technical claim and is brushed off by NIST"…

You're making decisions based on trivial social factors instead of the only salient point, which is that NIST had proven itself to be corrupted in the past when it comes to setting cryptographic standards.
Post reply on HN