Live data from Hacker News

NSA and IETF: Fairness

blog.cr.yp.to

141–150 of 198 posts

Re: NSA and IETF: Fairness

#141

Earlier quoted context omitted.

You do realize that the NSA spends many millions on employing mathematicians, right? And that they wouldn’t keep doing that if all the mathematicians did was get really shit-hot at Kerbal Space Program? An analysis of the comparative risks of these crypto systems should include “The NSA knows a lot of math they’re not sharing, and if they really really like ML-KEM, that’s concerning even if Ptacek keeps pointing out…

When you make an argument that is actually somehow rooted in cryptographic research, I'll have something to reply to. This is all just Schneier-Facts(tm) logic.

To be clear, the Schneier Facts on Dual-EC turned out to be far more accurate than the Ptacek Gut Logic.

Re: NSA and IETF: Fairness

#142

Earlier quoted context omitted.

When you make an argument that is actually somehow rooted in cryptographic research, I'll have something to reply to. This is all just Schneier-Facts(tm) logic.

To be clear, the Schneier Facts on Dual-EC turned out to be far more accurate than the Ptacek Gut Logic.

Schneier said the same thing I did. I literally got my take from Schneier. You don't even have the Schneier Facts right!

Re: NSA and IETF: Fairness

#143

Earlier quoted context omitted.

You're argument is that I shouldn't think of NIST as a patsy for the NSA, is because the NSA can't possibly be recommending a compromised cipher, because if they were, that would mean this US government org is horribly defective and dysfunctional, where one side didn't know what the other was doing? Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motiv…

> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So you hate pancakes" is happening. > Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motive when there's a history or pattern. Yes you are. You need…

> Incorrect. My argument is that they aren't the same entity.

Your mind is going to be blown when you learn about proxy organizations and cut-outs.

Re: NSA and IETF: Fairness

#144
post #111

Earlier quoted context omitted.

NTRU based schemes are not the most conservative. NTRU is an old design from the 90s, that had some shocking structural attacks against it appear ~2016. These attacks so far are only relevant for moduli q ~ (1/100) n^{2.3...}. This makes them worse than conventional attacks against NTRU-based PKE. But they completely killed roughly half of all NTRU-based fully homomorphic encryption schemes, and are a (major) structu…

The general C.W. I've heard is that if something happened that made MLKEM look theoretically shaky (pretty unlikely, but whatever), you fall back to something like FrodoKEM, which is plain LWE with no affordance for NTT or anything like it; no structure, no performance.

It really depends on what the precise details of the attack look like.

1. algebraic structure: sure use frodoKEM

2. error rates smaller than those required for worst-case to average-case reductions: idk bump error rates

3. some coding theorist ruins everyone's fun and has linear time decoding for p-ary construction A codes: probably drink a lot idk

fortunately there haven't been any "incremental" attacks in any of these directions, so it is really more an academic discussion.

Also note the primary issue with FrodoKEM isn't performance (though that is definitely worse), but size. My impression from the following

https://blog.cloudflare.com/sizing-up-post-quantum-signature...

https://blog.cloudflare.com/making-protocols-post-quantum/

was that TLS w/ FrodoKEM might have some undesirable performance characteristics, though that isn't directly stated in the articles. Iirc TLS w/ FrodoKEM

Re: NSA and IETF: Fairness

#145
post #134
post #5

This post was pretty technical. Let's explain a couple of terms: ML-KEM -- Module-Lattice-Based Key-Encapsulation Mechanism ML-DSA -- Module-Lattice-Based Digital Signature Algorithm solo PQ -- Using post-quantum crypto on its own ECC+PQ -- Using post-quantum crypto as a layer on top of traditional elliptical curve cryptography (ECC) So what's at stake here, is that the PQ crypto is not proven yet, and had recent imp…

1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental weakness that should cause a panic. Note that the non-constant time implementations were caught ~2 years ago, prior to any deployment. So it was a sign of everything going "as exp…

> pure ML-KEM is much more "proven" than people are discussing. The core hardness assumption dates back to 2005, and has been intensely studied (the paper introducing it got a cryptography version of a Nobel prize (Godel prize), as did several follow-up works only achievable using that hardness assumption.

The inventor of the lobotomy won a Nobel Prize in Medicine for it.

Re: NSA and IETF: Fairness

#146

Earlier quoted context omitted.

> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So you hate pancakes" is happening. > Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motive when there's a history or pattern. Yes you are. You need…

> Incorrect. My argument is that they aren't the same entity. Your mind is going to be blown when you learn about proxy organizations and cut-outs.

NIST does a lot of things that have nothing to do with computer security!

Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?

Re: NSA and IETF: Fairness

#147

> Secret NSA documents showed that NSA pushed DES in the 1970s to "drive out competitors" while knowing that DES was "weak enough" to break; meanwhile NSA publicly claimed that it would use DES Is this true? The NSA pushed for weaker cryptography it could break versus stronger cryptography our adversaries couldn't?

DJB wrote a short history of NSA’s malicious meddling in the cryptography we all use, based on a declassified internal history of the NSA.

https://blog.cr.yp.to/20220805-nsa.html

Re: NSA and IETF: Fairness

#148
post #80

Earlier quoted context omitted.

I might have expected you'd be once bitten twice shy after having once taking an aggressive position that DUAL-EC would never have backdoored anyone in practice... The optionality of MLKEM by itself is of a similar shape to standardizing a lame DRBG that 'obviously' no one would use and anyone who would use would use the appendix parameter generation scheme that would have rendered it secure (although still slow). Th…

None of this makes any sense once you understand that NSA had no hand in designing MLKEM, or in shaping the LWE research that led to it. NSA designed Dual-EC. MLKEM won an open competition; its entrants are among the most reputable cryptographers in the world.

it's worth clarifying that its entrants were all qualified, and 2 other essentially identical schemes, namely New Hope and Saber, made it very deep into the NIST competition.

All 3 (roughly) took the approach of

1. take the obvious best design, and

2. tweak various internal design knobs you have access to, and

3. that's pretty much it.

So they differ in the internal design knobs they chose. But the fact that 3 independent teams all created something substantially similar to ML-KEM should be an indication of how much harder it would be for the NSA to be behind it.

Re: NSA and IETF: Fairness

#149
post #134

Earlier quoted context omitted.

1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental weakness that should cause a panic. Note that the non-constant time implementations were caught ~2 years ago, prior to any deployment. So it was a sign of everything going "as exp…

> pure ML-KEM is much more "proven" than people are discussing. The core hardness assumption dates back to 2005, and has been intensely studied (the paper introducing it got a cryptography version of a Nobel prize (Godel prize), as did several follow-up works only achievable using that hardness assumption. The inventor of the lobotomy won a Nobel Prize in Medicine for it.

huh. I really wouldn't want the Nobel Prize committee in medicine doing cryptographic work then. good thing your comment has nothing to do with cryptography then :)

Re: NSA and IETF: Fairness

#150
post #110

Earlier quoted context omitted.

using pure ML-KEM is not a footgun. Some people may have doubts about lattice-based cryptography, despite being securely deployed in Chrome nearly a decade ago. Some people have doubts about many things. The fact that people have doubts does not make the scheme a "footgun".

It is if literally the only thing you've ever read about the technical details of LWE cryptography is Daniel Bernstein.

you'd probably call it "Product NTRU" then, and be a minimum a decade out of date. So you'd probably have to do all that weird shit with co-different ideals Peikert was trying to get us all to do (I know it was "right" but sometimes you need to put a muzzle on the math guys for all of our sakes).
Post reply on HN