Earlier quoted context omitted.
Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough. But it's probably best to just forget about NIST and start from scratch with a new standards body with zero influence from the government - any government(how it should be).
Almost by definition, a standards organization would have some form of government (lowercase g) running it. What would you suggest as an alternative? Wikistandards? Even a wiki has government.
Government Announces Steps to Restore Confidence on Encryption Standards
81–90 of 132 posts
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#82Earlier quoted context omitted.
OpenSSL supports these Russian GOST standards: * md_gost94 message digest algorithm * gost89 symmetric encryption algorithm with 256 bit key * gost94 public key algorithm with 1024 bit public key * gost94cp public key algorithm with 1024 bit public key (CP mode1) * gost2001 public key algorithm based on elliptic curves with 512 bit public key * gost2001cp public key algorithm based on elliptic curves with 512 bit pub…
Should I make a simple script to use gnutls to encrypt a file with AES then openssl using gost89, then 3des ?
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#83This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…
True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#84This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…
True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#85Want to know how to get a secure encryption standard? Do not develop it with the government involved, especially not the US government.
That doesn't ensure a lack of foul play. Even none government-employed developers could be turned into "agents" to insert code. Whether they're bought off or even just have strong patriotic motivations to begin with, you still need a stricter review process to ensure that no one country nor organisation has significant input nor control over the code.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#86Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#87This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…
True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.
One might say that they instead have a political and economical agenda disguised as war against terror.
If so, they would certainly have conflicts of interest, at least at some point.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#88Earlier quoted context omitted.
“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.
Nitpicking but why understatement? Feeling betrayed sounds more serious that just pissed off.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#89This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…
How deeply have our academic institutions been co-opted by the intelligence community?
1. JHU then had a dean apologize, but it was almost certainly only a reaction to the negative publicity that ensued: https://twitter.com/matthew_d_green/status/37712085467858534
and
https://twitter.com/matthew_d_green/status/37749174387029196...
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#90Earlier quoted context omitted.
“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.
Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough. But it's probably best to just forget about NIST and start from scratch with a new standards body with zero influence from the government - any government(how it should be).
Why would the cryptography community ever again cooperate with NIST while the requirement to consult with the NSA is in place? It's not a question of feeling betrayed, it's simply irrational to try to create a strong cryptography standard when the NSA is in the room. They can do that work outside of NIST.