Live data from Hacker News

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

nist.gov

11–20 of 60 posts

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#11
post #2

CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars and star trek FYI to those who didn't know.

Kyber is a fictional thing, so I understand that it's a Star Wars reference. But Dilithium is a real thing, so not sure why that would be a Star Trek reference? Couldn't it just be a reference to the real thing somehow?

Dilithium is a real molecule, but dilithium crystals are a fictional Star Trek thing. https://en.wikipedia.org/wiki/Dilithium_(Star_Trek)

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#12

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

There's a recent paper on this topic if you're looking for a very in-depth discussion: https://harvardnsj.org/wp-content/uploads/sites/13/2022/06/V...

The conclusion is no, there is no alternative right now.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#13

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

> Is there any alternative organizations like NIST but not-NIST?

Not especially if you're in the US and want to work with government systems or be a sub-contractor to a company that does. Otherwise pick an algorithm and have at it:

* https://xkcd.com/927/

> That NIST worked together with NSA […]

Did they? Or did the NSA lie to NIST?

* https://www.schneier.com/blog/archives/2022/06/on-the-subver...

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#14

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith?

And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out?

So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#15
post #8

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

I can't imagine with the added scrutiny the internet has gotten since then, especially from foreign governments, that NIST will be able to get away with anything like that again. But then again I may be completely ignorant as to the scope of NSA meddling.

> […] that NIST will be able to get away with anything like that again.

You say this like NIST was an accomplice (and not also a victim).

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#16

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

There's no need for one.

How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to.

However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public competition. They basically asked everyone to submit proposals and then asked everyone to find flaws in theses proposals.

These competitions have a very good reputation in the cryptographic community. An algorithm like Dual EC where the issues were quite obvious would've never survived such a process.

The thing you should look at is the process, not the organization.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#17
post #16

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST.

EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent an algorithm which stands up to scrutiny, but which has some extremely hard to notice flaw which only they know about. They could then make those cryptographers submit the algorithm to NIST, and, in a seemingly fair way, pick the subtly broken algorithm as the winner. I can't know whether this happened of course, and it probably didn't, but we fundamentally have to trust that NIST wouldn't do something like that... and we do know that they would do, and indeed have done, something like that.

Maybe the process is such that this attack, and any other kind of attack, is impossible. If that's the case, please do cite something which goes into detail on that.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#18
post #17
post #16

Earlier quoted context omitted.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…

What if those trustworthy organizations were to tell you: "We trust this NIST competition result, and so should you"?

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#20
post #17
post #16

Earlier quoted context omitted.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…

Who do you trust as an authority?
Post reply on HN