Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

71–80 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#71
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

Thanks, I'll use Bernstein's recommendations. His article is not rambling: Mailing list discussions are just tedious to recap.

I wonder what your strategy here is. Muddying the waters and depict Bernstein as a renegade? You have made too many big-state and big-money apologist posts for that to work.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#72
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

The vast majority of organisations just use whatever default security settings their Cisco router or web browser comes with. The NSA starts by requiring some insecure protocols be supported , and then when support is widespread they start requiring it be made a default by requiring compliance testing be done with default config.

They also historically have extremely deep access to networks, and even if a given corp doesn't allow them to put a box inside the corp's own network, they control / have access to many or all of the links between most corps' datacenters.

From this privileged network position, if both sides support weaker crypto that NSA lobbied for, they can MitM the initial connection and omit the hybrid methods from the client's TLS ClientHello, and then client/server proceed to negotiate into a cipher that NSA prefers.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#73

Earlier quoted context omitted.

> expand on why someone should trust you The point is to trust no one and no thing that we cannot examine freely, closely, and transparently. And to maintain healthy skepticism of any entity that claims to have a virtuous process to do its business .

GGP stated: > trust me from experience.

And the point is “trust me: trust no one, but especially not them” is the meaning you are ignoring.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#74
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

The SIKE comparison is not particularly inconsistent since Bernstein has been banging the drum that structured lattices may not be as secure as thought for years now.

Currently the best attacks on NTRU, Kyber, etc, are essentially the same generic attacks that work for something like Frodo, which works on unstructured lattices. And while the resistance of unstructured attacks is pretty well studied at this point, it is not unreasonable to suspect that the algebraic structure in the more efficient lattice schemes can lead to more efficient attacks. How efficient? Who knows.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#75
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

Bernstein wasn't the only objector. There were 7 objectors and 20 proponents.

Dual EC isn't the only comparison he's making. He's also making a comparison to DES, which had an obvious weakness: 53 bit limitation, similar to the obvious weakness of non-hybrid. In neither case is there a secret backdoor. At the time of DES, the NSA publicly said they used it, to make others confident in it. Similarly, the NSA is saying "we do not anticipate supporting hybrid in NSS", which will make people confident in non-hybrid. But in the background, NSA actually uses something more secure (using 2 layers of encryption themselves).

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#76
I skimmed the article, but it doesn't make too much sense. It says:

>Surveillance agency NSA and its partner GCHQ are trying to have standards-development organizations endorse weakening ECC+PQ down to just PQ.

The NSA spends about half of its resources attempting to hack the FBI and erase its evidence against them in the matter of keeping my wife and me from communicating. The other half of the staff are busy commenting online about how unfair this is, and attempting to get justice.

There are no NSA resources left for actions like the one I quoted. I don't think NSA is involved in it.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#77
post #34

Earlier quoted context omitted.

It's hard to answer your question without repeating the arguments made in the post itself. Are you implying that djb blew the matter out of proportion?

Poor quality analogy: should ed25519 only have been incorporated into protocols in conjunction with another cryptographic primitive? Surely requiring a hybrid with ecdsa would be more secure? Why did djb not argue for everyone using ed25519 to use a hybrid? Was he trying to reduce security? The reason this is a poor quality analogy is that fundamentally ecdsa and ed25519 are sufficiently similar that people had a hig…

> seem to feel that the security benefits of a hybrid approach don't justify the drawbacks.

The problem with this statement to me is that we know of at least 1/4 finalists in the post quantum cryptography challenge is broken, so it's very hard to assign a high probability that the rest of the algorithms will be secure from another decade of advancement (this is not helped by the fact that since the beginning of the contest, the lattice based methods have lost a signficant number of bits as better attacks have been discovered).

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#78
post #5

This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?

99% of global TLS traffic?

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#79
It sounds like there is probably some ongoing drama here, but aside from that: this post has convinced me that standards this important need to be decided on by organizations that aren't a government.

I wonder who else could reasonably host a standardization process? Maybe the Linux Foundation? All the cryptography talent seems to be working on ZK proofs at the moment in the Ethereum ecosysetem; I think if Vitalik organized a contest like NIST people would pay attention.

The most important thing is to incentivize attackers to break the cryptography on dummy examples instead of in the wild. Ideally: before the algorithm is standardized. The Ethereum folks are well setup to offer bounties for this. If a cryptographer can make FU money through responsible disclosure, then there is less incentive to sell the exploit to dishonest parties.

Post reply on HN