DJB has been complaining about this NSA position since 2022 (I guess long before it was an issue at the TLS WG): https://blog.cr.yp.to/20220805-nsa.html I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. If it isn't some sort of gimmick to allow NSA to break these, it's sure showing a huge amount of confidence in relatively recently developed mechanisms. It fe…
NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
21–30 of 119 posts
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#22Earlier quoted context omitted.
For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…
It's really clear why people would want a non-hybrid code point. To me it really isn't. TLS has no need for it. But let's focus the context for some US government organisations that want this for their FIPS maturity level they're aiming for. Why would these organisations want a weaker algorithm for TLS than what is standardised; more importantly how does it benefit deployment except save a tiny bit of computation and…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#23Earlier quoted context omitted.
I feel like if your argument is that the rules weren't followed, you have a pretty strong obligation to follow the rules in submitting your complaint.
Having served on boards, rejections on procedural grounds which fail to address engineering concerns which have been raised stink of a cop-out.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#24This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?
What's quite concerning? Be specific.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#25Earlier quoted context omitted.
Having served on boards, rejections on procedural grounds which fail to address engineering concerns which have been raised stink of a cop-out.
Have you read the complaint? It's not about engineering concerns, it's about whether procedures were followed correctly.
This complaint? https://cr.yp.to/2025/20250812-non-hybrid.pdf
Engineering concerns start in section 2 and continue through section 4.
It seems you haven't read it.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#26Earlier quoted context omitted.
What's quite concerning? Be specific.
It is concerning that the IETF is moving forward with a proposal that weakens security and is of questionable technical merit, with the most reasonable explanation being that this is the result of efforts by government surveillance agencies to enable or potentially enable monitoring of encrypted communications supposedly protected by this standard; additionally, it is concerning that disagreeing with this decision is…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#27DJB has been complaining about this NSA position since 2022 (I guess long before it was an issue at the TLS WG): https://blog.cr.yp.to/20220805-nsa.html I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. If it isn't some sort of gimmick to allow NSA to break these, it's sure showing a huge amount of confidence in relatively recently developed mechanisms. It fe…
Expand on "recently-developed mechanisms".
https://en.wikipedia.org/wiki/Lattice-based_cryptography#His...
2005 (LWE), 2012 (LWE for key exchange), earlier (1990s for lattice math in general), 2017 (Kyber submission), later (competition modifications to Kyber)?
I can see where one could see the mathematics as moderately mature (comparable in age to ECC, but maybe less intensively studied?). As above, I don't know quite how to think about whether the "thing" here is properly "lattices", "LWE", "LWE-KEX", "Kyber", or "the parameters and instantiation of Kyber from the NIST PQ competition". Depending where we focus our attention there, I suppose this gives us some timeframe from the 1980s (published studies of computational complexity of lattice-related algorithms) to "August 2024" (adoptions of NIST PQ FIPS documents).
Edit: The other contextual thing that freaks out DJB, for those who might not be familiar, is that one of the proposed standards NIST was considering, SIKE, made it all the way through to the final (fourth) round of consideration, whereupon it was completely broken by a couple of researchers bringing to bear mathematical insight. Now SIKE had a very different architecture than the other proposals in the fourth round, so it seems like a portion of the debate is whether the undetected mathematical problems in SIKE are symptomatic of "the NIST competition came extraordinarily close to approving something that was totally broken, so maybe it wasn't actually that great at evaluating candidate algorithms, or at least maybe the mathematics community's understanding of post-quantum key exchange algorithms is still immature" or more symptomatic of "SIKE had such a weird and distinctive architecture that it was hard to understand or analyze, or hard to motivate relevant experts to understand or analyze it, unlike other candidate algorithms that were and are much better understood". It seems like DJB is saying the former and you're saying the latter.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#28Earlier quoted context omitted.
It's really clear why people would want a non-hybrid code point. To me it really isn't. TLS has no need for it. But let's focus the context for some US government organisations that want this for their FIPS maturity level they're aiming for. Why would these organisations want a weaker algorithm for TLS than what is standardised; more importantly how does it benefit deployment except save a tiny bit of computation and…
And this gets back to the Dual-EC argument, right? Dual-EC was standardized as this weird government thing that maybe you technically need for FIPS, but obviously if you're seriously designing a cryptosystem you wouldn't choose it. And that seems to be GP's position on non-hybrid PQ as well -- just that the reason for not choosing it is "it introduces risk for very little benefit" instead of "it is obviously a bumbli…
Unless NSA pays you $10 million, as they did to RSA, to make said obviously bumbling attempt the default in their security products.
https://en.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dual_...
https://www.reuters.com/article/us-usa-security-rsa-idUSBRE9...
Or unless the presence of such less secure options in compliant implementations enables a https://en.wikipedia.org/wiki/Downgrade_attack
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#29Earlier quoted context omitted.
It is concerning that the IETF is moving forward with a proposal that weakens security and is of questionable technical merit, with the most reasonable explanation being that this is the result of efforts by government surveillance agencies to enable or potentially enable monitoring of encrypted communications supposedly protected by this standard; additionally, it is concerning that disagreeing with this decision is…
I'm asking how, specifically, it "weakens security" and is of "questionable technical merits". The IETF isn't a government body.
Are you implying that djb blew the matter out of proportion?
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#30Earlier quoted context omitted.
And this gets back to the Dual-EC argument, right? Dual-EC was standardized as this weird government thing that maybe you technically need for FIPS, but obviously if you're seriously designing a cryptosystem you wouldn't choose it. And that seems to be GP's position on non-hybrid PQ as well -- just that the reason for not choosing it is "it introduces risk for very little benefit" instead of "it is obviously a bumbli…
> Dual-EC was standardized as this weird government thing that maybe you technically need for FIPS, but obviously if you're seriously designing a cryptosystem you wouldn't choose it. Unless NSA pays you $10 million, as they did to RSA, to make said obviously bumbling attempt the default in their security products. https://en.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dual_... https://www.reuters.com/article/us-usa-s…