Live data from Hacker News

Government Announces Steps to Restore Confidence on Encryption Standards

bits.blogs.nytimes.com

81–90 of 132 posts

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#81
post #56

Earlier quoted context omitted.

Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough. But it's probably best to just forget about NIST and start from scratch with a new standards body with zero influence from the government - any government(how it should be).

Almost by definition, a standards organization would have some form of government (lowercase g) running it. What would you suggest as an alternative? Wikistandards? Even a wiki has government.

I don't see the utility in using "government" to mean something other than "the state". We have other words that can work just as well without introducing confusion about the intent of the speaker.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#82
post #70

Earlier quoted context omitted.

OpenSSL supports these Russian GOST standards: * md_gost94 message digest algorithm * gost89 symmetric encryption algorithm with 256 bit key * gost94 public key algorithm with 1024 bit public key * gost94cp public key algorithm with 1024 bit public key (CP mode1) * gost2001 public key algorithm based on elliptic curves with 512 bit public key * gost2001cp public key algorithm based on elliptic curves with 512 bit pub…

Should I make a simple script to use gnutls to encrypt a file with AES then openssl using gost89, then 3des ?

Why not? Seems like fun.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#83
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.

Iran should be able to do that.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#84
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.

Oh god, not again with the "war on terror".

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#85
post #42
post #28

Want to know how to get a secure encryption standard? Do not develop it with the government involved, especially not the US government.

That doesn't ensure a lack of foul play. Even none government-employed developers could be turned into "agents" to insert code. Whether they're bought off or even just have strong patriotic motivations to begin with, you still need a stricter review process to ensure that no one country nor organisation has significant input nor control over the code.

That's true. But if you've not got a player on the table you're obliged to listen to because their vote overrides everybody elses, they can't shoot down things they don't like as easily.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#86
post #35

Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…

I wonder what % of posts in threads covering these topics are astroturf.

https://en.wikipedia.org/wiki/Astroturfing

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#87
post #26

This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…

True, but Russia, China and the US all have a shared interest in working (together?) against Islamic rebels/separatists/militants/terrorists, so they may well cooperate more than you might at first suspect. If you could get some Islamic militants to (develop?) contribute a cryptosystem, then you would be more convincing.

It's arguable that their interest is to fight against "Islamic rebels/separatists/militants/terrorists".

One might say that they instead have a political and economical agenda disguised as war against terror.

If so, they would certainly have conflicts of interest, at least at some point.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#88
post #53

Earlier quoted context omitted.

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.

Nitpicking but why understatement? Feeling betrayed sounds more serious that just pissed off.

Just semantics- 'feeling betrayed' is passive; 'are pissed off' is active. Probable reality- the betrayal has pissed them off.

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#89

This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…

Yes, Prof. Green posted a critical post about the NSA, and then JHU asked him to remove the post from their servers[1]. I'm stunned; academic freedom is evidently an illusion in some parts of the US.

How deeply have our academic institutions been co-opted by the intelligence community?

1. JHU then had a dean apologize, but it was almost certainly only a reaction to the negative publicity that ensued: https://twitter.com/matthew_d_green/status/37712085467858534

and

https://twitter.com/matthew_d_green/status/37749174387029196...

Re: Government Announces Steps to Restore Confidence on Encryption Standards

#90
post #56
post #53

Earlier quoted context omitted.

“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. That's the understatement of the century. NIST is pissed off. Many of these guys move fluidly back and forth from NSA, and clearly they were kept in the dark.

Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough. But it's probably best to just forget about NIST and start from scratch with a new standards body with zero influence from the government - any government(how it should be).

They can't fix it. As the article noted, they are required by law to consult with the NSA. While the NSA is an expert on cryptography, they are obviously (and were, obviously, at the time that law was written) conflicted. That the law says that NIST has to consult with the NSA means that the law-writers, our government, want NIST to allow NSA to weaken cryptography standards. This is not conspiracy-thinking, anyone who thought through the consequences of this law would see that this is what the NSA would try to do.

Why would the cryptography community ever again cooperate with NIST while the requirement to consult with the NSA is in place? It's not a question of feeling betrayed, it's simply irrational to try to create a strong cryptography standard when the NSA is in the room. They can do that work outside of NIST.

Post reply on HN