This is quite concerning, and respect to DJB for fighting against it. However, I have to wonder...who would this actually compromise that matters to NSA? * Targets with sufficient technical understanding would use hybrids anyway. * Average users and unsophisticated targets can already be monitored through PRISM which makes cryptography moot. So...what's their actual end game here?
Coupled with QUANTUMINSERT, it would enable a https://en.wikipedia.org/wiki/Downgrade_attack even for folks who might otherwise be using stronger encryption methods.
NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
101–110 of 119 posts
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#102DJB has been complaining about this NSA position since 2022 (I guess long before it was an issue at the TLS WG): https://blog.cr.yp.to/20220805-nsa.html I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. If it isn't some sort of gimmick to allow NSA to break these, it's sure showing a huge amount of confidence in relatively recently developed mechanisms. It fe…
Why is that so surprising? Adopting new cryptography by running it in a hybrid mode with the cryptography it's replacing is generally not standard practice and multi-algorithm schemes are pretty niche at best (TrueCrypt/VeraCrypt are the only non-PQ cases that come to mind, although I'm sure there are others). Now you could certainly argue that PQ algorithms are untested and risky in a way that was not true of any other new algorithm and thus a hybrid scheme makes the most sense, but it's not such an obviously correct argument that anyone arguing otherwise must be either stupid or malicious.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#103Earlier quoted context omitted.
Which insinuations do you think are ludicrous? Is it not a matter of public record at this point that the NSA and NIST have lied to weaken cryptography standards?
The entirely unsupported insinuation that the customer Cisco is describing is the NSA. What's even supposed to be the motivation there? The NSA want weak crypto so they're going to buy a big pile of Ciscos that they'll never use but which will make people think it's secure? There are others, but on its own that should already be a red flag.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#104DJB has been complaining about this NSA position since 2022 (I guess long before it was an issue at the TLS WG): https://blog.cr.yp.to/20220805-nsa.html I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. If it isn't some sort of gimmick to allow NSA to break these, it's sure showing a huge amount of confidence in relatively recently developed mechanisms. It fe…
> I'm actually quite surprised that anyone is advocating the non-hybrid PQ key exchange for real applications. Why is that so surprising? Adopting new cryptography by running it in a hybrid mode with the cryptography it's replacing is generally not standard practice and multi-algorithm schemes are pretty niche at best (TrueCrypt/VeraCrypt are the only non-PQ cases that come to mind, although I'm sure there are others…
The cool thing is the dramatic security improvements against certain unknown unknowns for approximately linear additional work and space. Seems like a pretty great advantage for the defender, although seriously arguing that quantitatively requires some way to reason about the unknown unknowns (the reductio ad absurdum being that we would need to use every relevant primitive ever published in every protocol¹).
I see PQC as somehow very discontinuous with existing cryptography, both in terms of the attacks it tries to mitigate and the methods it uses to resist them. This might be wrong. Maybe it's fair to consider it an evolutionary advance in cryptographic primitive design.
The casual argument from ignorance is that lattices are apparently either somewhat harder to understand, or just less-studied overall, than other structures that public-key primitives have been built on, to the extent that we would probably currently not use them at all in practical cryptography if it weren't for the distinctive requirements of resistance to quantum algorithms. I understand that this isn't quantitative or even particularly qualitative (for instance, I don't have any idea of what about lattices is actually harder to understand).
Essentially, in this view, we're being forced into using weird esoteric stuff much earlier than we'd like because it offers some hope of defending against other weird esoteric stuff. Perhaps this is reinforced by, for example, another LWE submission having been called "NewHope", connoting to me that LWE was thought even by many of its advocates to offer urgently-needed "hope", but maybe not "confidence".
I'd like not to have to have that argument only in terms of vibes (and DJB does have some more concrete arguments that the security of SIKE was radically overestimated, while the security of LWE methods was moderately overestimated, so we need to figure out how to model how much of the problem was identified by the competition process and how much may remain to be discovered). I guess I just need to learn more math!
¹ I think I remember someone at CCC saying with respect to the general risk of cryptographic backdoors that we should use hybrids of mechanisms that were created by geopolitical rivals, either to increase the chance that at least one party did honest engineering, or to decrease the chance that any party knows a flaw in the overall system! This is so bizarre and annoying as a pure matter of math or engineering, but it's not like DJB is just imagining the idea that spy agencies sometimes want to sabotage cryptography, or have budgets and staff dedicated to doing so.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#105I skimmed the article, but it doesn't make too much sense. It says: >Surveillance agency NSA and its partner GCHQ are trying to have standards-development organizations endorse weakening ECC+PQ down to just PQ. The NSA spends about half of its resources attempting to hack the FBI and erase its evidence against them in the matter of keeping my wife and me from communicating. The other half of the staff are busy commen…
They are not running out of resources.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#106I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…
You find it offensive now to compare ML-KEM and SIKE because SIKE was so thoroughly broken and demonstrated to be worse than pre-quantum crypto. But ML-KEM may already be broken this thoroughly by NSA and friends, and they’re keeping it secret because shipping bad crypto to billions of people enables SIGINT. The idea that your professional crypto acquaintances might be on the NSA’s payroll clearly disturbs you enough that you dismiss it out of hand.
Bernstein is proposing more transparency because that is what was promised after the Dual-EC debacle. Do you disagree with Bernstein because he advocates for transparency (which could prevent bad crypto shipping), or because of his rhetorical style?
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#107I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…
ML-KEM and SIKE were both candidates in the PQ competition which ML-KEM won. SIKE was considered such a strong contender that it was used in production TLS experiments at scale by Google and Cloudflare. (I guess you didn’t read past the second paragraph?) You find it offensive now to compare ML-KEM and SIKE because SIKE was so thoroughly broken and demonstrated to be worse than pre-quantum crypto. But ML-KEM may alre…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#108Earlier quoted context omitted.
ML-KEM and SIKE were both candidates in the PQ competition which ML-KEM won. SIKE was considered such a strong contender that it was used in production TLS experiments at scale by Google and Cloudflare. (I guess you didn’t read past the second paragraph?) You find it offensive now to compare ML-KEM and SIKE because SIKE was so thoroughly broken and demonstrated to be worse than pre-quantum crypto. But ML-KEM may alre…
I find the comparison risible because SIKE is based on an entirely different and novel problem class, and the vibe I get from Bernstein is that he thinks lattice cryptography is alien enough to people who don't work in this space that they'll miss the fact that cryptosystems based on ring-LWE hardness have been worked on by giants in the field since the mid-1990s.
You’ve admitted you were “loudly wrong” when you announced Dual-EC couldn’t be an NSA cryptography backdoor. Snowden let us all know the NSA spends $250 million every year secretly convincing/bribing the private sector to use bad cryptography. Despite that history, you are still convinced there’s no way ML-KEM is an NSA cryptographic backdoor and that all the bizarre procedural errors in the PQ crypto contest are mere coincidences.
[checks my text messages] Lucy just texted me, Thomas. She’s outside waiting for you to kick her football.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#109Earlier quoted context omitted.
As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…
Matthew Garrett is not a secret NSA propagandist. People can reasonably disagree with the djb position. His blog posts are notoriously divisive, and that doesn't make everyone on the other side a secret NSA influencer. Please assume good faith, or discussions turn into personal attacks and wild accusations.
In 2016, Isis Lovecruft was romantically involved with Jacob Appelbaum. Isis lost a coveted PhD student spot studying under Bernstein to… Jacob Appelbaum. Isis broke up with Jacob and accused him of sexual abuse in a spectacularly public manner.
Isis became romantically involved with Henry de Valence, another Bernstein PhD student. Valence became acquainted with Appelbaum. Later, under Isis’ direction, Valence published a wild screed full of bizarre accusations trying to get Appelbaum expelled and Bernstein fired. When this failed, Isis dumped Valence and publicly accused him of sexual abuse.
Isis Lovecruft is now married to Matthew Garrett. Obviously Matthew is going to work to discredit Bernstein, because if he fails, he knows what the next two steps are.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#110Earlier quoted context omitted.
I find the comparison risible because SIKE is based on an entirely different and novel problem class, and the vibe I get from Bernstein is that he thinks lattice cryptography is alien enough to people who don't work in this space that they'll miss the fact that cryptosystems based on ring-LWE hardness have been worked on by giants in the field since the mid-1990s.
You seem blind to the obvious corollary to that fact, which is if cryptosystems based on ring-LWE hardness have been worked on by giants for 30 years, then those same cryptosystems have been cryptanalyzed for 30 years, and a significant chunk of cryptanalytic research stays in NSA’s Classified Mathematics Library. You’ve admitted you were “loudly wrong” when you announced Dual-EC couldn’t be an NSA cryptography backd…