Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

1–10 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#3
post #2

It's a touch odd to make a big deal of the fact that you've filed a complaint and fail to mention that it was formally rejected three days before you published the post: https://datatracker.ietf.org/group/iesg/appeals/artifact/146

Lots of respect to both you and the author, but the rejection gives no real response to any of the issues I see raised in the document.

It failed to raise my confidence at all.

> The IESG has concluded that there were no process failures by the SEC ADs. The IESG declines to directly address the complaint on the TLS WG document adoption matter. Instead, the appellant should refile their complaint with the SEC ADs in a manner which conforms to specified process.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#4
DJB has been complaining about this NSA position since 2022 (I guess long before it was an issue at the TLS WG):

https://blog.cr.yp.to/20220805-nsa.html

I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. If it isn't some sort of gimmick to allow NSA to break these, it's sure showing a huge amount of confidence in relatively recently developed mechanisms.

It feels kind of like saying "oh, now that we can detect viruses in sewage, hospitals should stop bothering to report possible epidemic outbreaks, because that's redundant with the sewage monitoring capability". (Except worse, because it involves some people who may secretly be pursuing goals that are the opposite of everyone else's.)

Edit: DJB said in that 2022 post

  > Publicly, NSA justifies this by
  > 
  > . pointing to a fringe case where a careless effort to add an extra security layer damaged security, and
  > . expressing "confidence in the NIST PQC process".

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#5
This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA?

* Targets with sufficient technical understanding would use hybrids anyway.

* Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot.

So...what's their actual end game here?

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#6
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

I think the point is... even if you can't get everyone to adopt your backdoored technology, you are much better off if 30% of the market adopts it than if >1%...

Intelligence is a numbers game, they never get everything, but if your net is wide enough and you don't give up, you'll catch a lot of fish over time

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#8
post #2

It's a touch odd to make a big deal of the fact that you've filed a complaint and fail to mention that it was formally rejected three days before you published the post: https://datatracker.ietf.org/group/iesg/appeals/artifact/146

It's still nice that it was put up for completeness. And as we know this stuff has a long sordid history of people who are proponents of weakening encryption not giving up easily.
Post reply on HN