Live data from Hacker News

Mathematician warns US spies may be weakening next-gen encryption

newscientist.com

111–120 of 218 posts

Re: Mathematician warns US spies may be weakening next-gen encryption

#111

Earlier quoted context omitted.

So 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

[deleted]

Re: Mathematician warns US spies may be weakening next-gen encryption

#112

Earlier quoted context omitted.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

The people are still human beings. The process is still open to FOIA. It’s not perfect, but it’s the right solution.

Sorry, what is the right solution? Total surveillance? The current approach? Some middling thing?

Re: Mathematician warns US spies may be weakening next-gen encryption

#113
post #96

Earlier quoted context omitted.

There is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not fro…

FWIW, I don't believe Bernstein is evil. I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.

Hm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected enough to warrant better responses.

If he's turned so crank-y that his peers simply no longer engage with him beyond the strictly necessary, then this all looks a bit different.

I'd still love to see some of his specific criticisms addressed, but that becomes a minor point...

Re: Mathematician warns US spies may be weakening next-gen encryption

#114
This is a question I've asked before, but I'm wondering if there's an updated perspective. Given the human brain is unencryptable, it seems like keeping secrets is going to be impossible.

I guess maybe with the advent of AI, you just have device to device communication with no man in the middle in the future?

Re: Mathematician warns US spies may be weakening next-gen encryption

#115
post #18
post #3

Earlier quoted context omitted.

Because your options are Beijing or DC. We like to pretend the age of empires is past but realistically we still live in a time of where there are two major world powers and everyone gets to decide which side of the line they want to fall on, accept American hegemony or submit to Chinese control.

>Because your options are Beijing or DC. We have plenty of standards in Europe too :-) However, with cryptography historically the best crypto has been invented in the US and it made much more sense for allies to just use ready made solutions than to roll their own. Do countries on the US crypto exports ban lists have their own incompatible crypto? I dont know, they might, but they for sure don't share it as freely a…

> but they for sure don't share it as freely available standards.

https://www.rfc-editor.org/rfc/rfc8891 (GOST Magma) is a russian standard block cipher.

https://www.gsma.com/aboutus/wp-content/uploads/2014/12/eea3... is a Chinese stream cipher.

https://datatracker.ietf.org/doc/html/draft-ribose-cfrg-sm4-... Chinese block cipher.

https://datatracker.ietf.org/doc/html/draft-oscca-cfrg-sm3-0... Chinese hash function.

https://datatracker.ietf.org/doc/html/rfc4269 (SEED) is from South Korea (aligned, but still worth a mention)

Re: Mathematician warns US spies may be weakening next-gen encryption

#116

Earlier quoted context omitted.

Why not? Have you ever worked in an open kitchen? If you can't do your work for the public under public scrutiny, you shouldn't.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

Does mandating to record any work related communication really invade privacy of people working there?

Re: Mathematician warns US spies may be weakening next-gen encryption

#117

Earlier quoted context omitted.

I believe the Solokey meets your definition. The hardware schematics are open, as is the software running on it. The Precursor is also open hardware and software. If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet . And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall…

You'd have to choose your FPGA judiciously. The truly paranoid see the attack surface area of 100 GB of black box libraries needed to synthesize designs and appreciate the possibility of gateware trojans.

While I think choosing an open source stack is important, can you imagine how difficult it would be to inject a remote exploit into ARBITRARY hardware your code didn't know in advance?

Re: Mathematician warns US spies may be weakening next-gen encryption

#118

Earlier quoted context omitted.

Except that in one I can say "my president is an idiot. We need a leadership change" without wiping my credit score or being detained.

Half seriously, what's the difference between your career ruined via social credit being wiped by government or your career ruined via social credit being wiped on Twitter?

One's a repressive government and one's some number of people choosing not to like you very much anymore?

Re: Mathematician warns US spies may be weakening next-gen encryption

#119

Earlier quoted context omitted.

How is that in any way like working in an open kitchen? Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.

Does mandating to record any work related communication really invade privacy of people working there?

As it would be based on distrust, you'd have to record everything everywhere to avoid people not evading it.

Even innocently, if, for example, two employees meet at home for dinner with their respective families and there is talk about work - needs to be recorded in that view. Or people car sharing on the way to work - recorded. Any work related communication is very very broad.

And everything recorded open to the public, too.

Re: Mathematician warns US spies may be weakening next-gen encryption

#120
post #96

Earlier quoted context omitted.

There is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not fro…

FWIW, I don't believe Bernstein is evil. I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.

On the other hand he’s been a great force against NSA’s shenanigans.
Post reply on HN