Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

1–10 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#2
The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too!

http://bits.blogs.nytimes.com/2013/09/10/government-announce...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#3

The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too! http://bits.blogs.nytimes.com/2013/09/10/government-announce...

The original NYT article was submitted, but barely upvoted.

http://news.ycombinator.com/item?id=6364340

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#4

The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too! http://bits.blogs.nytimes.com/2013/09/10/government-announce...

now the original link was changes to NYTimes anyway

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#5

The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too! http://bits.blogs.nytimes.com/2013/09/10/government-announce...

Mike Masnick calls it a complete non-response from NIST, regarding the real issue/accusation:

http://www.techdirt.com/articles/20130910/12371124473/nists-...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#6
When I saw 'new details' (edit: this was referring to an old title), I was hoping that the backdoor in Dual_EC_DRBG was either confirmed or denied ... in reality, there's not much new here. The NYT confirmed that their previous article was talking about Dual_EC_DRBG, but that's what everyone (edit: in the cryptography community) expected anyway [1].

We still don't know the exact story behind Dual_EC_DRBG. Maybe the NSA carefully crafted the DRBG to contain a backdoor that they knew from the outset. Maybe they didn't notice the backdoor until later (perhaps after cryptographers pointed it out) but ended up discovering the 'key' that allows you to predict the stream, completely breaking the DRBG (this is very unlikely, however). Or maybe they're no better off than the general public.

Annoyingly, there are no concrete details. Internal memos "appear to confirm that the fatal weakness, discovered by two Microsoft cryptographers in 2007, was engineered by the agency". In the latest NYT article, the internal memos "suggest that the N.S.A. generated one of the random number generators used in a 2006 N.I.S.T. standard". (What "generated" really means here is beyond me; obviously the constants were generated somehow. The question is whether or not they were generated with malicious intent. Is the 'generated' part quoted/paraphrased from the memos?)

Now I'm not saying that the NSA didn't have some malicious intent with Dual_EC_DRBG. But we have a stunning lack of any evidence. Internal memos 'appear to confirm' and 'suggest', but the bits provided from them are... lacking. Things certainly seem fishy, but we don't even know the context of the quotes.

I don't know. It certainly wouldn't surprise me if Dual_EC_DRBG was engineered to have a backdoor, but all of the articles I've read seem to carefully use weasel words when talking about it.

[1] http://crypto.stackexchange.com/a/10258/2454

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#9
post #8

Golf clap, anyone? Anyone? This is a huge confidence builder. Huge.

Too little, too late.

This is like a criminal promising he won't do it again, but only AFTER been caught and having the entire town surround him with pitchforks.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#10
post #6

When I saw 'new details' (edit: this was referring to an old title), I was hoping that the backdoor in Dual_EC_DRBG was either confirmed or denied ... in reality, there's not much new here. The NYT confirmed that their previous article was talking about Dual_EC_DRBG, but that's what everyone (edit: in the cryptography community) expected anyway [1]. We still don't know the exact story behind Dual_EC_DRBG. Maybe the N…

> that's what everyone expected anyway

This one sentence is a _remarkably easy way_ to kill a story for the 99.9% of the world who this is news for.

"Everyone" indeed.

Post reply on HN