Earlier quoted context omitted.
You do realize that the NSA spends many millions on employing mathematicians, right? And that they wouldn’t keep doing that if all the mathematicians did was get really shit-hot at Kerbal Space Program? An analysis of the comparative risks of these crypto systems should include “The NSA knows a lot of math they’re not sharing, and if they really really like ML-KEM, that’s concerning even if Ptacek keeps pointing out…
When you make an argument that is actually somehow rooted in cryptographic research, I'll have something to reply to. This is all just Schneier-Facts(tm) logic.
NSA and IETF: Fairness
141–150 of 198 posts
Re: NSA and IETF: Fairness
#142Earlier quoted context omitted.
When you make an argument that is actually somehow rooted in cryptographic research, I'll have something to reply to. This is all just Schneier-Facts(tm) logic.
To be clear, the Schneier Facts on Dual-EC turned out to be far more accurate than the Ptacek Gut Logic.
Re: NSA and IETF: Fairness
#143Earlier quoted context omitted.
You're argument is that I shouldn't think of NIST as a patsy for the NSA, is because the NSA can't possibly be recommending a compromised cipher, because if they were, that would mean this US government org is horribly defective and dysfunctional, where one side didn't know what the other was doing? Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motiv…
> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So you hate pancakes" is happening. > Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motive when there's a history or pattern. Yes you are. You need…
Your mind is going to be blown when you learn about proxy organizations and cut-outs.
Re: NSA and IETF: Fairness
#144Earlier quoted context omitted.
NTRU based schemes are not the most conservative. NTRU is an old design from the 90s, that had some shocking structural attacks against it appear ~2016. These attacks so far are only relevant for moduli q ~ (1/100) n^{2.3...}. This makes them worse than conventional attacks against NTRU-based PKE. But they completely killed roughly half of all NTRU-based fully homomorphic encryption schemes, and are a (major) structu…
The general C.W. I've heard is that if something happened that made MLKEM look theoretically shaky (pretty unlikely, but whatever), you fall back to something like FrodoKEM, which is plain LWE with no affordance for NTT or anything like it; no structure, no performance.
1. algebraic structure: sure use frodoKEM
2. error rates smaller than those required for worst-case to average-case reductions: idk bump error rates
3. some coding theorist ruins everyone's fun and has linear time decoding for p-ary construction A codes: probably drink a lot idk
fortunately there haven't been any "incremental" attacks in any of these directions, so it is really more an academic discussion.
Also note the primary issue with FrodoKEM isn't performance (though that is definitely worse), but size. My impression from the following
https://blog.cloudflare.com/sizing-up-post-quantum-signature...
https://blog.cloudflare.com/making-protocols-post-quantum/
was that TLS w/ FrodoKEM might have some undesirable performance characteristics, though that isn't directly stated in the articles. Iirc TLS w/ FrodoKEM
Re: NSA and IETF: Fairness
#145This post was pretty technical. Let's explain a couple of terms: ML-KEM -- Module-Lattice-Based Key-Encapsulation Mechanism ML-DSA -- Module-Lattice-Based Digital Signature Algorithm solo PQ -- Using post-quantum crypto on its own ECC+PQ -- Using post-quantum crypto as a layer on top of traditional elliptical curve cryptography (ECC) So what's at stake here, is that the PQ crypto is not proven yet, and had recent imp…
1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental weakness that should cause a panic. Note that the non-constant time implementations were caught ~2 years ago, prior to any deployment. So it was a sign of everything going "as exp…
The inventor of the lobotomy won a Nobel Prize in Medicine for it.
Re: NSA and IETF: Fairness
#146Earlier quoted context omitted.
> You're argument is that I shouldn't think of NIST as a patsy for the NSA, Incorrect. My argument is that they aren't the same entity. The thing you said is a whole different argument. "I like waffles" "So you hate pancakes" is happening. > Incentives are basically all I consider when trying to establish true motive. But you're not required to consider motive when there's a history or pattern. Yes you are. You need…
> Incorrect. My argument is that they aren't the same entity. Your mind is going to be blown when you learn about proxy organizations and cut-outs.
Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?
Re: NSA and IETF: Fairness
#147> Secret NSA documents showed that NSA pushed DES in the 1970s to "drive out competitors" while knowing that DES was "weak enough" to break; meanwhile NSA publicly claimed that it would use DES Is this true? The NSA pushed for weaker cryptography it could break versus stronger cryptography our adversaries couldn't?
Re: NSA and IETF: Fairness
#148Earlier quoted context omitted.
I might have expected you'd be once bitten twice shy after having once taking an aggressive position that DUAL-EC would never have backdoored anyone in practice... The optionality of MLKEM by itself is of a similar shape to standardizing a lame DRBG that 'obviously' no one would use and anyone who would use would use the appendix parameter generation scheme that would have rendered it secure (although still slow). Th…
None of this makes any sense once you understand that NSA had no hand in designing MLKEM, or in shaping the LWE research that led to it. NSA designed Dual-EC. MLKEM won an open competition; its entrants are among the most reputable cryptographers in the world.
All 3 (roughly) took the approach of
1. take the obvious best design, and
2. tweak various internal design knobs you have access to, and
3. that's pretty much it.
So they differ in the internal design knobs they chose. But the fact that 3 independent teams all created something substantially similar to ML-KEM should be an indication of how much harder it would be for the NSA to be behind it.
Re: NSA and IETF: Fairness
#149Earlier quoted context omitted.
1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental weakness that should cause a panic. Note that the non-constant time implementations were caught ~2 years ago, prior to any deployment. So it was a sign of everything going "as exp…
> pure ML-KEM is much more "proven" than people are discussing. The core hardness assumption dates back to 2005, and has been intensely studied (the paper introducing it got a cryptography version of a Nobel prize (Godel prize), as did several follow-up works only achievable using that hardness assumption. The inventor of the lobotomy won a Nobel Prize in Medicine for it.
Re: NSA and IETF: Fairness
#150Earlier quoted context omitted.
using pure ML-KEM is not a footgun. Some people may have doubts about lattice-based cryptography, despite being securely deployed in Chrome nearly a decade ago. Some people have doubts about many things. The fact that people have doubts does not make the scheme a "footgun".
It is if literally the only thing you've ever read about the technical details of LWE cryptography is Daniel Bernstein.