Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

11–20 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#11
There is so much here to debate about. A) Never trust the cyber feds. B) The NSA is not the place anyone thinks, it’s a Wild West in the most bizarre of places, trust me from experience. C) Cryptology concerns more of than security and exchanging messages or packets, sometimes you don’t even know what kind of thing (living) can and has been decrypted. D) The NSA plays very, very, very dirty. It is like a digital CIA, they are in everything (i.e. cyber spies in various roles at tech/telecom/manufacturer company xyz). E) NEVER LISTEN TO THE DAMN NSA / DRIVEN BY A CULTURE OF EXPLOITATION

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#12
I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It's really sad.

Dual EC wasn't a shockingly clever, CS-boundary-pushing hack (and NSA has apparently deployed at least one of those in the last 20 years). It was an RNG (not a key agreement protocol) based on asymmetric public key cryptography, a system where you could look at it and just ask "where's the private key?" There wasn't a ton of academic research trying to pick apart flaws in Dual EC because why would there be? Who would ever use it?

(It turns out: a big chunk of the industry, which all ran on ultra-closed source code and was much less cryptographically literate that most people thought. I was loudly wrong about this at the time!)

MLKEM is a standard realization of CRYSTALS-Kyber, an algorithm submitted to the NIST PQ contest by a team of some of the biggest names in academic PQ cryptography, including Peter Schwabe, a prior collaborator of Bernstein. Nobody is looking at MLKEM and wondering "huh, where's the private key?".

MLKEM is based on cryptographic ideas that go back to the 1990s, and were intensively studied in the 2000s. It's not oddball weird cryptography. It is to the lineage of lattice cryptography roughly what Ed25519 was to elliptic curve cryptography at the time of Ed25519's adoption.

Utterly unlike SIKE, which isn't a lattice algorithm at all, but rather a supersingular isogeny algorithm, a cryptographic primitive based on an entirely new problem class, and an extremely abstruse one at that. The field had been studying lattice cryptography intensively for decades by the time MLKEM came to pass. That's not remotely true of isogeny cryptography. Isogenies were taken seriously not because of confidence in the hardness of isogenies, but because of ergonomics: they were a drop-in replacement for Diffie Hellman in a way MLKEM isn't.

These are all things Bernstein is counting on you not knowing when you read this piece.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#13
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

What's quite concerning? Be specific.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#14
post #3
post #2

It's a touch odd to make a big deal of the fact that you've filed a complaint and fail to mention that it was formally rejected three days before you published the post: https://datatracker.ietf.org/group/iesg/appeals/artifact/146

Lots of respect to both you and the author, but the rejection gives no real response to any of the issues I see raised in the document. It failed to raise my confidence at all. > The IESG has concluded that there were no process failures by the SEC ADs. The IESG declines to directly address the complaint on the TLS WG document adoption matter. Instead, the appellant should refile their complaint with the SEC ADs in a…

I feel like if your argument is that the rules weren't followed, you have a pretty strong obligation to follow the rules in submitting your complaint.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#15
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#16
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.

For the same reason your Toyota Camry doesn't have a roll cage.

I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for.

But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point.

Let me just say this once as clearly as I can: I sort of don't give a shit about any of this. A pox on all their houses. I think official cryptographic standards are a force for evil. More good is going to be done for the world by systems that implement well enough to become de facto standards. More WireGuards, fewer RFCs. Certainly, I can't possibly give even a millifuck about what NIST wants.

But I also can't be chill about these blog posts Bernstein writes where it's super clear his audience is not his colleagues in cryptography research, but rather a lay audience that just assumes anything he writes must be true and important. It's gross, because you can see the wires he's using to hold these arguments together (yes, even I can see them), and I don't like it when people insult their audiences this way.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#17
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

Coupled with QUANTUMINSERT, it would enable a https://en.wikipedia.org/wiki/Downgrade_attack even for folks who might otherwise be using stronger encryption methods.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#18
post #14
post #3

Earlier quoted context omitted.

Lots of respect to both you and the author, but the rejection gives no real response to any of the issues I see raised in the document. It failed to raise my confidence at all. > The IESG has concluded that there were no process failures by the SEC ADs. The IESG declines to directly address the complaint on the TLS WG document adoption matter. Instead, the appellant should refile their complaint with the SEC ADs in a…

I feel like if your argument is that the rules weren't followed, you have a pretty strong obligation to follow the rules in submitting your complaint.

Having served on boards, rejections on procedural grounds which fail to address engineering concerns which have been raised stink of a cop-out.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#19
post #16

Earlier quoted context omitted.

To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.

For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…

> For the same reason your Toyota Camry doesn't have a roll cage.

It does though. It's just been engineered integral to the unibody. And there are crumple zones, airbags, seat belts, ABS, emergency braking systems, collision sensors, and more layered defenses in addition.

No sane engineer would argue that removing these layers of defense would make the car safer.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#20
post #16

Earlier quoted context omitted.

To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.

For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…

It's really clear why people would want a non-hybrid code point.

To me it really isn't. TLS has no need for it. But let's focus the context for some US government organisations that want this for their FIPS maturity level they're aiming for. Why would these organisations want a weaker algorithm for TLS than what is standardised; more importantly how does it benefit deployment except save a tiny bit of computation and eliminate some ECC code. I'm not going to jump the shark and say it is nefarious, but I will throw in my 2 cents and say it doesn't help security and is unnecessary.

Post reply on HN