Earlier quoted context omitted.
These are arguments, but I don't really understand what they're arguments for. At issue here is whether or not the IETF should document usage of pure-MLKEM TLS. There are environments where people are going to use pure-MLKEM TLS, whether Bernstein likes it or not. His argument is that the IETF should pretend that isn't happening, and throw up weird procedural obstacles to it.
If it's documented it will be implemented by many more libraries and applications, that's the argument
NSA and IETF: Fairness
41–50 of 198 posts
Re: NSA and IETF: Fairness
#42Earlier quoted context omitted.
No, it's not an absurd claim. Lattice key establishment goes back into the mid-1990s, and was at one point a serious contender for the alternative-to-RSA/FFDH algorithm that ECC became. Modern LWE lattice KEM is approximately at the same point in its lifecycle (say, compared to original NTRU) as Curve25519 was to ECDH.
the McEliece cryptosystem goes back to the 70s, doesn't mean it's as well studied as RSA. obviously people study popular cryptographic primitives more. having said that, I would trust McEliece more than Kyber.
Re: NSA and IETF: Fairness
#43Earlier quoted context omitted.
He's a cryptographer. You're describing cryptographers. You get that other cryptographers designed Kyber/MLKEM, and still more implemented it, right? There are cryptographers besides Daniel J. Bernstein.
"two timing leaks, KyberSlash1 and KyberSlash2, in every official reference Kyber implementation from 2017 through late 2023" Cryptographers can be good, bad, be more or less knowledgeable about applied cryptography, and possibly have agendas.
Re: NSA and IETF: Fairness
#44Earlier quoted context omitted.
He's a cryptographer. You're describing cryptographers. You get that other cryptographers designed Kyber/MLKEM, and still more implemented it, right? There are cryptographers besides Daniel J. Bernstein.
I do think it's fair to make an argument that DJB's expertise in practical cryptography (both in e.g. engineering against side channel attacks as well as in publishing his own libraries) gives him a reality-minded perspective/attitude. That said, personally speaking, his behavior as a software publisher (packaging & whatnot) is something I'd call… let's go with "subpar" and leave it at that. So while I do believe it'…
Re: NSA and IETF: Fairness
#45Earlier quoted context omitted.
From the way DJB talks about IETF processes, it's quite clear to me though that he has little trust/belief in the IETF consensus process. I thought he said as much somewhere but can't find that right now. (It's particularly obvious in https://blog.cr.yp.to/20260405-votes.html ) Which is why I'm noting the alienation of "IETF believers", which I should maybe clarify I count myself as. The IETF is a lot of people doing…
He famously doesn't support the IETF. In the long-long-long ago, back when I had a "home page" with my username and a tilde in it, I used to have a quote from him on it about the IETF and "ego standards". He's been picking fights like this with different IETF working groups for basically his entire career. This isn't even the first time he's picked a huge fight with IETF cryptography groups; he managed to get Kenny P…
I've met him in person, once, at a CCC event about a decade ago, and as someone clueless about cryptography all I can say to that is that he certainly had (has?) a my-way-or-the-highway personality.
> I, too, don't support the IETF
Out of curiosity, how would you maintain e.g. TLS? Something more academic? Raw "throw it all out there, best-wins"? Another SDO (e.g. ITU)? Other more formal international processes?
Re: NSA and IETF: Fairness
#46Earlier quoted context omitted.
If it's documented it will be implemented by many more libraries and applications, that's the argument
It already exists. In fact, there are environments where it has to exist. So the argument he's making is that the IETF should pretend it doesn't exist.
Re: NSA and IETF: Fairness
#47DJB has orchestrated a vote rigging campaign against this WGLC, encouraging users to join the list and vote/express their opinion and providing the exact subject header to use. Have any other sides been saying, essentially, just join the group and say you’re for/against? He’s been moderated during the last call because of his email disclaimer/footnote, and apparently refuses to respond on list during this time. Seems…
Informational RFCs still need to pass through the IETF consensus process, changing the intended status isn't a procedural bypass. However, the authors can just publish it elsewhere, it makes no difference at all for the codepoint allocations. Only distinction is that it doesn't get the somewhat intangible (but existent) "RFC sheen".
Re: NSA and IETF: Fairness
#48Earlier quoted context omitted.
He famously doesn't support the IETF. In the long-long-long ago, back when I had a "home page" with my username and a tilde in it, I used to have a quote from him on it about the IETF and "ego standards". He's been picking fights like this with different IETF working groups for basically his entire career. This isn't even the first time he's picked a huge fight with IETF cryptography groups; he managed to get Kenny P…
> whether he realizes it or not, he's operating in supremely bad faith this time. I've met him in person, once, at a CCC event about a decade ago, and as someone clueless about cryptography all I can say to that is that he certainly had (has?) a my-way-or-the-highway personality. > I, too, don't support the IETF Out of curiosity, how would you maintain e.g. TLS? Something more academic? Raw "throw it all out there, b…
I would maintain TLS the same way WireGuard and OpenSSH are maintained. Both have superior track records. I'm generally an opponent of all security and (especially) cryptographic standards bodies.
Re: NSA and IETF: Fairness
#49Earlier quoted context omitted.
"two timing leaks, KyberSlash1 and KyberSlash2, in every official reference Kyber implementation from 2017 through late 2023" Cryptographers can be good, bad, be more or less knowledgeable about applied cryptography, and possibly have agendas.
Huh, seen through that light, it's much clearer why we should all have ECC in our cryptosystems, because nothing has ever gone wrong with an ECC implementation.
Re: NSA and IETF: Fairness
#50This post was pretty technical. Let's explain a couple of terms: ML-KEM -- Module-Lattice-Based Key-Encapsulation Mechanism ML-DSA -- Module-Lattice-Based Digital Signature Algorithm solo PQ -- Using post-quantum crypto on its own ECC+PQ -- Using post-quantum crypto as a layer on top of traditional elliptical curve cryptography (ECC) So what's at stake here, is that the PQ crypto is not proven yet, and had recent imp…
Perhaps