Live data from Hacker News

NIST announces first PQC algoritms to be standardized

groups.google.com

111–120 of 132 posts

Re: NIST announces first PQC algoritms to be standardized

#111

Something that worries me, if someone cracks our current encryption using quantum computers couldn't they be logging everything we say right now and everything we say right now is actually unsecure to someone 10 years in the future?

Yes. This is why the work is being done now, and there will be an urgency in moving PQC algorithms from academia to commercial use. Everything that has been stolen in data breaches up until then will be broken once QC are viable.

Good news is that we are likely more than 10 years away from QCs being useful enough to do this.

Re: NIST announces first PQC algoritms to be standardized

#112
post #107

Earlier quoted context omitted.

OpenSSH appears to have disregarded NIST, and made their own determination on a pq-kex. Should NIST be disregarded? NTRU-prime is not a finalist, but OpenSSH has decided that the NIST designation is irrelevant. https://www.openssh.com/releasenotes.html ssh(1), sshd(8): use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed t…

I personally think NIST should be disregarded, but you can disregard NIST and still end up with CRYSTALS-KYBER as your default PQC KEM, on its own merits, which can include the fact that NIST's standardization spurs so much implementation of CRYSTALS-KYBER that it becomes a de facto standard in addition to a de jure standard. (Same for signatures, and so on). People with qualms about NIST might also reasonably have q…

I agree with your sentiment. I wish NIST had conducted the proceedings more professionally, and this collapse in confidence is their own fault.

The OpenSSH decision to promote NTRU-prime from an experimental feature to the preferred key exchange was breathtakingly rapid, and final. It is a tacit assertion that NIST is no longer relevant.

DJB was on several teams, and I think that OpenSSH would lend greater credence to him than any other council, deservedly so.

We might end up with SPHINCS+, but I will be surprised if KYBER is adopted.

This moved very fast.

Re: NIST announces first PQC algoritms to be standardized

#113
post #112

Earlier quoted context omitted.

I personally think NIST should be disregarded, but you can disregard NIST and still end up with CRYSTALS-KYBER as your default PQC KEM, on its own merits, which can include the fact that NIST's standardization spurs so much implementation of CRYSTALS-KYBER that it becomes a de facto standard in addition to a de jure standard. (Same for signatures, and so on). People with qualms about NIST might also reasonably have q…

I agree with your sentiment. I wish NIST had conducted the proceedings more professionally, and this collapse in confidence is their own fault. The OpenSSH decision to promote NTRU-prime from an experimental feature to the preferred key exchange was breathtakingly rapid, and final. It is a tacit assertion that NIST is no longer relevant. DJB was on several teams, and I think that OpenSSH would lend greater credence t…

I don't wish NIST had conducted the proceedings more professionally, not because I'm a nihilist about standards but because I don't know enough to critique how they ran this. I've read the whole post upthread (by the way: if you're scratching your head, the trick is to read the red text, across several pages, all the way through, and then come back and pay attention to the rebuttals you think are interesting) and don't feel any more equipped to say anything about it. What I will say is that a significant chunk of all the world's public key encryption expertise got sunk into this event.

One reason KYBER got standardized quickly is that PQC KEMs are time-sensitive if you believe the quantum attack threat is plausibly material within the next 10-15 years. Your adversary in these attacks will almost certainly be state signals intelligence groups, and the expense involved in building attack hardware dwarfs the expense of collecting traffic today to decrypt in 2034. If you're a PQC believer, you want something out the door soon.

I don't understand the special sway you think Bernstein has, versus all the other cryptographers that participate in NISTPQC, with the OpenSSH team. I worry that people believe stuff like this because they know who Bernstein is and what OpenSSH is, and don't off the top of their head know who Tancrède Lepoint is. Note also that the KYBER team includes Peter Schwabe, whose name you should definitely know if you're a Bernstan.

Re: NIST announces first PQC algoritms to be standardized

#114

Earlier quoted context omitted.

A point rendering the choice even more curious: Germany and the Netherlands have recommended the use of encryption not relying on the shortest vector problem [1]. The two suggestions of FrodoKEM (relying on hardness of the learning with errors problem) and Classic McEliece (relying on hardness of decoding random codes?) aren't lattice-based apparently. Perhaps NIST knows something we don't ; ^ ) [1] - https://twitter…

LWE's hardness is based on SVP (ignoring issues of tightness, which isn't unique to FrodoKEM). The difference between FrodoKEM + Kyber/Saber isn't relying on SVP/not (they all essentially do), but is on relying on LWE over structured lattices or not. At a very high level, all of the three rely on an n x n matrix at a certain point. The "structured lattice" schemes (Kyber/Saber) make structural assumptions about this…

Ah, thanks for the clarification!

Re: NIST announces first PQC algoritms to be standardized

#115
post #68
post #7

What's up with this? > In addition, NIST has engaged with third parties that own various patents directed to cryptography, and NIST acknowledges cooperation of ISARA, Philippe Gaborit, Carlos Aguilar Melchor, the laboratory XLIM, the French National Center for Scientific Research (CNRS), the University of Limoges, and Dr. Jintai Ding. NIST and these third parties are finalizing agreements such that the patents owned…

> If the agreements are not executed by the end of 2022, NIST may consider selecting NTRU instead of KYBER. It is especially interesting that NTRU (nor NTRU Prime, a different proposal) is _not_ advancing to the 4th round. Wouldn't you want to encourage more analysis for your (implied) runner-up?

Not only that, NIST says:

> Overall assessment. One important feature of NTRU is that because it has been around for longer, its IP situation is more clearly understood. The original designers put their patents into the public domain [113], in addition to most of them having expired.

> As noted by the submitters, NTRU may not be the fastest or smallest among the lattice KEM finalists, and for most applications and use cases, the performance would not be a problem. Nonetheless, as NIST has selected KYBER for standardization, NTRU will therefore not be considered for standardization in the fourth round.

https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8413.pdf

"NTRU is obviously legal and perfectly suitable, but we're not picking it." I find this to be a baffling position given the as-yet-unsolved patent issues with KYBER.

Re: NIST announces first PQC algoritms to be standardized

#116
post #112

Earlier quoted context omitted.

I agree with your sentiment. I wish NIST had conducted the proceedings more professionally, and this collapse in confidence is their own fault. The OpenSSH decision to promote NTRU-prime from an experimental feature to the preferred key exchange was breathtakingly rapid, and final. It is a tacit assertion that NIST is no longer relevant. DJB was on several teams, and I think that OpenSSH would lend greater credence t…

I don't wish NIST had conducted the proceedings more professionally, not because I'm a nihilist about standards but because I don't know enough to critique how they ran this. I've read the whole post upthread (by the way: if you're scratching your head, the trick is to read the red text, across several pages, all the way through, and then come back and pay attention to the rebuttals you think are interesting) and don…

The major question will be what ends up in TLS.

Aside from adherence to DJB, the question will be what can be trusted?

We have been down this road before.

https://lwn.net/Articles/681616/

Re: NIST announces first PQC algoritms to be standardized

#117
post #116

Earlier quoted context omitted.

I don't wish NIST had conducted the proceedings more professionally, not because I'm a nihilist about standards but because I don't know enough to critique how they ran this. I've read the whole post upthread (by the way: if you're scratching your head, the trick is to read the red text, across several pages, all the way through, and then come back and pay attention to the rebuttals you think are interesting) and don…

The major question will be what ends up in TLS. Aside from adherence to DJB, the question will be what can be trusted? We have been down this road before. https://lwn.net/Articles/681616/

Again, you're not really being asked to trust NIST here, so much as you are the CRYSTALS team. If you think the CRYSTALS team has been subverted by NSA, you're pretty far outside of the mainstream of cryptography thinkers; notably, this isn't a claim Bernstein has made, or is likely ever to make, unless someone dares him to†.

https://news.ycombinator.com/item?id=10376951

Re: NIST announces first PQC algoritms to be standardized

#118
post #68

Earlier quoted context omitted.

> If the agreements are not executed by the end of 2022, NIST may consider selecting NTRU instead of KYBER. It is especially interesting that NTRU (nor NTRU Prime, a different proposal) is _not_ advancing to the 4th round. Wouldn't you want to encourage more analysis for your (implied) runner-up?

Not only that, NIST says: > Overall assessment. One important feature of NTRU is that because it has been around for longer, its IP situation is more clearly understood. The original designers put their patents into the public domain [113], in addition to most of them having expired. > As noted by the submitters, NTRU may not be the fastest or smallest among the lattice KEM finalists, and for most applications and us…

>NTRU may not be the fastest or smallest.

"It's slower and uses more memory" goes a long way in encouraging the evaluation of other options.

Re: NIST announces first PQC algoritms to be standardized

#119
post #43

Earlier quoted context omitted.

To nitpick, afaik, its not that they cannot be proven, its that they have not been, and look very hard to prove, which is slightly different (not my area of expertise, but i assume this would be tied to p vs np)

I it not tied to P vs NP as far as I’m aware. But it is the same sort of situation: number theory assumptions that are completely unproven despite many attempts.

According to Wikipedia, all the proposed PQC schemes are proven to be NP-Hard, so you could say that their security depends on P != NP: https://en.wikipedia.org/wiki/Post-quantum_cryptography#Secu...

Re: NIST announces first PQC algoritms to be standardized

#120
post #20

Earlier quoted context omitted.

What's the "obligatory djb warnings"? Something like "any crypto that's not mine isn't great"? ;)

from skimming it, his main argument is that Kyber relies on many constructions (e.g. cyclotomic polynomials) that are actively under attack - researchers have been successfully chipping away at them and show no signs of stopping. he also alleges that NIST have been moving the goal posts to favor Kyber, and they've been duplicitous in their narrative. he favors NTRU, which iirc isn't his.

NTRU also relies on cyclotomic rings, so if distrust in cyclotomics was a good reason to reject Kyber, it would apply to NTRU too.
Post reply on HN