Earlier quoted context omitted.
I've read the emails on that list in which DJB is accused of unprofessional behavior. Dave's concerns are not only relevant and well considered, he's taken an extraordinary amount of time to outline them and the discussion around them (both pros and cons) which you can see here: https://blog.cr.yp.to/20260221-structure.html He's also responded directly to criticisms: https://nsa.2026.action.cr.yp.to/guide.html By com…
Like, who is "Dave"?
NSA tries to weaken mlkem standardisation?
91–100 of 100 posts
Re: NSA tries to weaken mlkem standardisation?
#92Earlier quoted context omitted.
This post makes a bad argument. Saying that there's no "Nobody but us backdoor" to prove there's *no* backdoor of *any kind* is clearly naive at best, dishonest at worst. As an example - if there's a weakness that affects 50% of keys (replace with whatever hypothetical number), NSA can make sure it doesn't use those affected keys but still retain the ability to decrypt 50% of everyone else's communications. And using…
A NOBUS backdoor in an asymmetric primitive that looks like "X% of all keys is weak" would not explain "let's move the entire fucking federal governnent to this algorithm including implementations sourced by the private sector that don't do our secret sauxe". Dual_EC_DRBG is the shape of backdoor that would need to apply here: even if you knew the structure of it, you would need an additional private number to attack…
That’s not a NOBUS backdoor. It’s a different type of backdoor and I’m pointing out that proving there is no NOBUS backdoor doesn’t mean there’s no other backdoor.
It’s a counterexample that I came up with in 5 minutes, not a proof that it’s useful to a state actor.
Re: NSA tries to weaken mlkem standardisation?
#93Earlier quoted context omitted.
A NOBUS backdoor in an asymmetric primitive that looks like "X% of all keys is weak" would not explain "let's move the entire fucking federal governnent to this algorithm including implementations sourced by the private sector that don't do our secret sauxe". Dual_EC_DRBG is the shape of backdoor that would need to apply here: even if you knew the structure of it, you would need an additional private number to attack…
> A NOBUS backdoor in an asymmetric primitive that looks like "X% of all keys is weak" That’s not a NOBUS backdoor. It’s a different type of backdoor and I’m pointing out that proving there is no NOBUS backdoor doesn’t mean there’s no other backdoor. It’s a counterexample that I came up with in 5 minutes, not a proof that it’s useful to a state actor.
And why would they still be migrating top secret communications towards the algorithm they (NOBUS or not) have a backdoor in?
That doesn't sound very COMINT to me.
Re: NSA tries to weaken mlkem standardisation?
#94This is not an unbiased article about the situation unfolding on the TLS Working Group mailing list; this is a call to action to join one specific side of the argument that has been ongoing for over a year now. It's an appeal to authority, an attempt to garner support for one side of the debate simply because DJB says so, as part of his effort to flood the zone with messages in opposition. This tactic is explicitly c…
djb has always been as outlandishly activist and combative as he is intelligent and competent. Anyone who attributes public motives or activity or blame to "the NSA" automatically gets dropped into the "conspiracy theorist" bin, as far as I'm concerned.
He maintained that it was the most secure option available, which was technically true until the technology around mail transfer started improving with things like SPF records. qmail didn't support them and wouldn't support them, patches weren't accepted, and the only way to use things like SPF (to reduce spam) was through unofficial community patches that could never be upstreamed.
qmail was far better than sendmail at the tiume, and honestly it probably still is to a large degree, but, like forcing users to change their password every week, it was a case of security being so tight that users had to break it in order to make the system functional.
All this to say that, while DJB is undoubtedly insightful and intelligent, I'm wary of any of his claims of 'this isn't secure enough' because of his past history of making things so secure as to be inflexibly unmanagable.
Re: NSA tries to weaken mlkem standardisation?
#95Earlier quoted context omitted.
djb has always been as outlandishly activist and combative as he is intelligent and competent. Anyone who attributes public motives or activity or blame to "the NSA" automatically gets dropped into the "conspiracy theorist" bin, as far as I'm concerned.
Funny thing about conspiracy "theory" is that a lot of the time the theory turns out to be true. In my view, the impulse to dismiss any suggestion of clandestine group activity (except if it's China's government, or Russia's, or Iran's, or...) as a "theory" is most likely the result of a psychological operation. The Dale Gribbles of the world are not a particularly common character to meet in real life but that's the…
I would love to see any sources on this claim.
A lot of "conspiracy theories" end up being true in some vague way; "the NSA is spying on all of us", yeah, that was true. The NSA is using satellites to read our thoughts? Not so much. Still, people will point to things like the Snowdon leaks to prove that the US government cannot be trusted (which is true) and therefore all the other claims that people make are also true.
The reality is that most conspiracy theories are impossible, either from a technical sense or a logistical one. The extreme examples, like "the earth is flat and the governments are hiding it" or "COVID isn't real and the vaccine is going to kill everyone but every government and doctor on earth is secretly in on it" get shrugged off as "well, not THOSE ones obviously", but most of the rest I've ever seen are also completely unbelievable.
Here's the thing: anyone can come up with a theory and stitch together the most circumstantial "evidence" to "prove" it, combining misinformation, misunderstanding, and misrepresentation to produce something that feels like it could be true on its face if people don't do any real digging, and most don't. I've yet to see a "conspiracy theory" backed by any actual hard evidence; they seem to entirely spring from an overactive imagination and are then "justified" and "proven" by finding other facts to fit the narrative retroactively.
Is there clandestine activity? Absolutely. Are there groups of people trying to manipulate situations and lie to the public for their own gain? Almost certainly. Do people with unsourced, unproven conspiracy theories make it easier for governments to get away with whatever they want because the rampant proliferation of crackpot theories allows for a convenient smokescreen whenever the truth starts to come out? Also yes.
Even if only 10% of conspiracy theories are true, which they are not, the people repeating them do more harm than good by doing so in a way that discredits themselves and others.
Re: NSA tries to weaken mlkem standardisation?
#96Earlier quoted context omitted.
Funny thing about conspiracy "theory" is that a lot of the time the theory turns out to be true. In my view, the impulse to dismiss any suggestion of clandestine group activity (except if it's China's government, or Russia's, or Iran's, or...) as a "theory" is most likely the result of a psychological operation. The Dale Gribbles of the world are not a particularly common character to meet in real life but that's the…
> Funny thing about conspiracy "theory" is that a lot of the time the theory turns out to be true. I would love to see any sources on this claim. A lot of "conspiracy theories" end up being true in some vague way; "the NSA is spying on all of us", yeah, that was true. The NSA is using satellites to read our thoughts? Not so much. Still, people will point to things like the Snowdon leaks to prove that the US governmen…
Re: NSA tries to weaken mlkem standardisation?
#97The NSA is not trying to weaken ML-KEM. The IETF TLS working group is simply trying to publish a pure ML-KEM specification. It does not impact the hybrid ietf-tls-ecdhe-mlkem specification at all. The context of this is that D.J Bernstein has been moderated 7 times from the mailing list for repeated unprofessional and disruptive behavior: https://mailarchive.ietf.org/arch/msg/tls/lON9lKptnJ6ccq2-I1...
Re: NSA tries to weaken mlkem standardisation?
#98Earlier quoted context omitted.
the IETF TLS working group has limited time/energy. He has been (very successfully) taking up a good deal of this with very annoying procedural techniques (and his most recent move, spreading falsehoods regarding an RFC then asking people to brigade a vote on the RFC). Explicitly, this slows down standards, which delays the PQ transition. Again explicitly, this is not the main RFC for PQ TLS, which details a hybrid c…
if no one should implement it, why standardize it?
Re: NSA tries to weaken mlkem standardisation?
#99This is not an unbiased article about the situation unfolding on the TLS Working Group mailing list; this is a call to action to join one specific side of the argument that has been ongoing for over a year now. It's an appeal to authority, an attempt to garner support for one side of the debate simply because DJB says so, as part of his effort to flood the zone with messages in opposition. This tactic is explicitly c…
This (also not unbiased) comment doesn't provide any substantive arguments other than a character attack on DJB. You'd also be hard-pressed to find an appeal to authority in this article. Lastly, I'm pretty sure the comment I'm replying to is at least partially LLM-generated. Ironically, it's the incredibly weak pro-standardization arguments that appear to be the most convincing evidence that the proposed standard is…
Re: NSA tries to weaken mlkem standardisation?
#100This is not an unbiased article about the situation unfolding on the TLS Working Group mailing list; this is a call to action to join one specific side of the argument that has been ongoing for over a year now. It's an appeal to authority, an attempt to garner support for one side of the debate simply because DJB says so, as part of his effort to flood the zone with messages in opposition. This tactic is explicitly c…
Your comment being top of thread, and you seemingly being conversant in the details of the issue, would be exceptionally well-placed to make an argument on the merits of the subject matter. Character portraits are sometimes useful, but technical detail is often conclusive. What's the steelman of djb's position and why does it fail scrutiny? To the uninitiated, it sounds like his preference for the hybrid classical/BQ…
The kindest reading of DJB's position is simple: pure ML-KEM is strong against fewer potential future scenarios than hybrid algorithms are, so people should use hybrid algorithms instead.
And in fact, I agree with this statement! The marginal cost of hybrid algorithms is very small, and the extra safety provided by being hybrid is (in my opinion) slightly larger than that cost. My cost/benefit analysis says that hybrid is the way to go for most people.
However, there are two major flaws with DJB's actual argument:
1. He's making the jump from "most people shouldn't use pure ML-KEM by default" to "the ability to use pure ML-KEM shouldn't be standardized at all". He's making overblown assertions about the power and meaning of an Informational IETF document, and using those to attempt to prevent simple interoperability standardization. Just because I think hybrids are the safer default in general doesn't mean that pure ML-KEM should be verboten; people deserve options, and the role of this document is to provide interoperability instructions for that option.
2. He's resorting to character attacks to imply that ML-KEM simply isn't safe at all. He frequently points to support from NSA and GHCQ as evidence that ML-KEM has been suborned in the same way as DUAL_EC_DRBG, despite widespread agreement in the cryptography community that the ML-KEM parameter space simply doesn't allow such attacks. He frequently points to support from cryptographers at Google and Cisco in the same breath, implying that they too are in the pay of the NSA. He's refusing to acknowledge that his implications that ML-KEM is unsafe imply that he should also oppose standardization of ML-KEM hybrids.
So while there's a kernel of truth to DJB's argument, I strongly believe that he has both taken the conclusion too far, and taken his argumentation tactics too far. It has lowered my respect for him as a person even further than it already was by his defense of Jacob Applebaum.