Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

51–60 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#51
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

The vast majority of organisations just use whatever default security settings their Cisco router or web browser comes with.

The NSA starts by requiring some insecure protocols be supported, and then when support is widespread they start requiring it be made a default by requiring compliance testing be done with default config.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#52
post #7

The mere idea that that they want to do this makes me want a 3rd layer of encryption on top of the other 2.

Encryption layers are actually pretty cheap for the vast majority of ciphers and applications. Seems dumb not to have like 10.

Nothing is as cheap (and secure at the same time) as hardware-accelerated AES. Thats why its often the only encryption-layer used.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#53
post #39

Earlier quoted context omitted.

> you're free to read the mailing list archives and observe that every issue Dan raised was discussed at the time As was https://en.wikipedia.org/wiki/Dual_EC_DRBG which was ratified over similar objections. That made it no less of a backdoor. > it's not their job As I said about excuses.

They're adhering to their charter. If you show up to my manager demanding to know why I made a specific engineering decision, he's not going to tell you - that's not the process, that's not his job, he's going to trust me to make good decisions unless presented with evidence I've misbehaved. But as has been pointed out elsewhere, the distinction between the Dual EC DRBG objections and here are massive. The former had…

> If you show up to my manager demanding to know why I made a specific engineering decision, he's not going to tell you

Well if your working in a standards development organisation then your manager probably should.

It looks like (in the US at least) standards development organisations have to have (and follow) very robust transparency processes to not be default-liable for individual decisions.

(Unlike most organisations, such as where where you and your manager from your scenario come from)

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#54
post #11

There is so much here to debate about. A) Never trust the cyber feds. B) The NSA is not the place anyone thinks, it’s a Wild West in the most bizarre of places, trust me from experience. C) Cryptology concerns more of than security and exchanging messages or packets, sometimes you don’t even know what kind of thing (living) can and has been decrypted. D) The NSA plays very, very, very dirty. It is like a digital CIA,…

>sometimes you don’t even know what kind of thing (living) can and has been decrypted.

?

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#56
post #11

There is so much here to debate about. A) Never trust the cyber feds. B) The NSA is not the place anyone thinks, it’s a Wild West in the most bizarre of places, trust me from experience. C) Cryptology concerns more of than security and exchanging messages or packets, sometimes you don’t even know what kind of thing (living) can and has been decrypted. D) The NSA plays very, very, very dirty. It is like a digital CIA,…

Ok, aside from not trusting the NSA, could you expand on why someone should trust you?

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#57
post #16

Earlier quoted context omitted.

To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.

For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…

You're arguing against deliberate cooperation.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#58
post #56
post #11

There is so much here to debate about. A) Never trust the cyber feds. B) The NSA is not the place anyone thinks, it’s a Wild West in the most bizarre of places, trust me from experience. C) Cryptology concerns more of than security and exchanging messages or packets, sometimes you don’t even know what kind of thing (living) can and has been decrypted. D) The NSA plays very, very, very dirty. It is like a digital CIA,…

Ok, aside from not trusting the NSA, could you expand on why someone should trust you ?

> expand on why someone should trust you

The point is to trust no one and no thing that we cannot examine freely, closely, and transparently. And to maintain healthy skepticism of any entity that claims to have a virtuous process to do its business.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#59
post #7

The mere idea that that they want to do this makes me want a 3rd layer of encryption on top of the other 2.

Encryption layers are actually pretty cheap for the vast majority of ciphers and applications. Seems dumb not to have like 10.

Make sure you absolutely have fresh entropy for all ten of your encryption layers. Re-using secrets and randomness between different encryption algorithms can leak a lot of data!

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#60
post #56

Earlier quoted context omitted.

Ok, aside from not trusting the NSA, could you expand on why someone should trust you ?

> expand on why someone should trust you The point is to trust no one and no thing that we cannot examine freely, closely, and transparently. And to maintain healthy skepticism of any entity that claims to have a virtuous process to do its business .

GGP stated:

  > trust me from experience.
Post reply on HN