Live data from Hacker News

Debunking NIST's calculation of the Kyber-512 security level

blog.cr.yp.to

121–130 of 219 posts

Re: Debunking NIST's calculation of the Kyber-512 security level

#121
post #2

Unfortunately, the NSA & NIST most likely is recommending a quantum-proof security that they've developed cryptanalysis against, either through high q-bit proprietary technology or specialized de-latticing algorithms . The NSA is very good at math, so I'm be thoroughly surprised if this analysis was error by mistake rather than error through intent.

> through high q-bit proprietary technology

Somebody would leak or steal that as it would be a GIGANTIC leap forward in our engineering skill at the quantum level.

Getting more than a handful of qubits to stay coherent and not collapse into noise is a huge research problem right now, and progress has been practically non-existent for almost a decade.

Re: Debunking NIST's calculation of the Kyber-512 security level

#122
post #16

That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…

You're making an assumption that the NSA cares about the efficacy of cryptography for other people. Why would they care about that?

it's in the national security interest of the United States to have its industries use high-quality crypto

see: colonial oil pipeline hack

Re: Debunking NIST's calculation of the Kyber-512 security level

#123
post #91
post #45

Earlier quoted context omitted.

Teams of cryptographers submit several proposals (and break each other's proposals). These people are well respected, largely independent, and assumed honest. Some of the mailing lists provided by NIST where cryptographers collaborated to review each other's work are public NIST may or may not consort with your friendly local neighborhood NSA people, who are bright and talented contributors in their own right. That's…

I was under the impression that only fools trust NIST after DUAL_EC_whatsit. Is that not the case?

from the article:

> I filed a FOIA request "NSA, NIST, and post-quantum cryptography" in March 2022. NIST stonewalled, in violation of the law. Civil-rights firm Loevy & Loevy filed a lawsuit on my behalf.

> That lawsuit has been gradually revealing secret NIST documents, shedding some light on what was actually going on behind the scenes, including much heavier NSA involvement than indicated by NIST's public narrative.

even if I had never heard of DUAL_EC_whatsit, there's enough here to make me mistrust NIST.

Re: Debunking NIST's calculation of the Kyber-512 security level

#124
post #67

The unfortunate reality of this is that while he may be right , it is difficult to classify the responses (or non-response) from the NIST people as deceptive vs just not wanting to engage with someone coming from such an adversarial position. NIST is staffed by normal people who probably view aggressively worded requests for clarification in the same way that most of us have probably fielded aggressively worded bug r…

Edit: Just realized the author is djb, Daniel Bernstein, which I guess is semi-ironic for me because I was recently praising him on HN for an old, well-read blog post on ipv6. Thus, I guess I may take back a bit of what I said below, or least perhaps it would be better to say that I can better understand the adversarial tone given djb's history with NIST recommendations (more info at https://en.wikipedia.org/wiki/Dan…

Even worse, I expected to find a part when he reports it and includes the responses/follow-up from that... But this is the first time it's published a far as I understand? Did I miss it in the wall of text? Or is it really a huge initial writeup that may end up with someone responding "oh, we did mess up, didn't we? Let's think how to deal with that."

Re: Debunking NIST's calculation of the Kyber-512 security level

#125

Earlier quoted context omitted.

You're making an assumption that the NSA cares about the efficacy of cryptography for other people. Why would they care about that?

it's in the national security interest of the United States to have its industries use high-quality crypto see: colonial oil pipeline hack

It's in the national security interest of the United States to have its industries use robust security practices.

Industries with secure fences that are regularly patrolled are entirely different to industries with partial coverage by unpatrolled rusty fences and a freestanding door frame that has a titanium unpickable lock.

Passwords get compromised that's a fact.

How the single employee password that got breached was obtained is still (AFAIK) a mystery - but this will always happen ... given many employess, at least one will eventually make a mistake.

After that, the VPN had no multifactor authentication, the network had no internal honey subnets, canary accounts, sanity checks, etc.

High-quality crypto alone does not make for secure systems.

And systems can be secure with lower quality crypto if the systems are robust.

Re: Debunking NIST's calculation of the Kyber-512 security level

#126
post #69
post #65

Earlier quoted context omitted.

You're still not recognizing the difference between corrupting a single academic cryptographer and corrupting a whole bunch of academic cryptographers. This isn't so black and white. For what it's worth, I do think the US government could corrupt academic cryptographers. If I was an academic cryptographer, and someone from the US government told me to do something immoral or else they would, say, kill my family, and…

As long as we're clear that your concern involves spy movie shit, and not mathematics or computer science, I'm pretty comfortable with where we've landed.

Why would you use mathematics or computer science to ascertain whether someone has been corrupted by a government agency?

Re: Debunking NIST's calculation of the Kyber-512 security level

#127
post #108
post #91

Earlier quoted context omitted.

I was under the impression that only fools trust NIST after DUAL_EC_whatsit. Is that not the case?

You mean ANSI/ISO/NIST and Dual_EC_DRBG, that everyone suspected had a backdoor before it was included as one of multiple options? https://en.m.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dua... Or the s-boxes in DES, that the NSA suggested to IBM + NIST's predecessor, so as to be resistant to then-not-widely-known differential cryptanalysis? https://web.archive.org/web/20120106042939/http://securespee...

[flagged]

Re: Debunking NIST's calculation of the Kyber-512 security level

#128
post #34

Notwithstanding DJB's importance to cryptography, and the fact that I'm ignorant of a large number of details here, there was a point where he lost a lot of credibility with me. Specifically, when he gets to the graphs, he says "NIST chose to deemphasize the bandwidth graph by using thinner red bars for it." That is just not proven by his evidence, and there is a very plausible explanation for it. The graph that has…

> At this point, it feels quite strongly to me that he is trying to interpret every action in the most malicious way possible. Given the long and detailed history of various governments and government agencies purposefully attempting to limit the public from accessing strong cryptography, I tend to agree with the "assume malice by default" approach here. Assuming anything else, to me at least, seems pretty naive.

Eh, it goes both ways. Back in the 1970's and 1980's there was a whole lot of suspicion about changes that the NSA made to DES S-boxes with limited explanation- was it a backdoor in some way? Then in 1989 white hats "discovered" differential cryptography, and realized that the changes that were made to the algorithm actually protected it from a then-unknown (to the general public) cryptographic attack. Differential cryptography worked beautifully on some other popular cryptosystems of the era, e.g. the FEAL-4 cipher could be broken with just 8 plaintext examples, while DES offered protection up to 2^47 chosen plaintexts.

The actual way that the NSA had tried to limit DES was to cap its key length at 48 bits, figuring that their advantage in computing power would let them brute force it when no one else could. (NIST compromised between the NSA's desire for 48 and the rest of the world's desire for 64, which was why DES had the always bizarre 56 bit key.) So sometimes they strengthen it, sometimes they weaken it, and so I'm not sure it appropriate to presume malice.

Re: Debunking NIST's calculation of the Kyber-512 security level

#129
post #23
post #16

That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…

> Why would they be willing to risk that here? Certain types of attacks basically make it so you need to have a specific private key to act as a backdoor. That's the current guess on what may be happening with the NIST ECC curves. If so, this can be effectively a US-only backdoor for a long, long time.

No, it’s really not. Ask Neal Koblitz.

Re: Debunking NIST's calculation of the Kyber-512 security level

#130

Earlier quoted context omitted.

Absolutely, but NIST ultimately choose the winners, giving them the option to pick (non-obviously) weak/weaker algorithms. Historically only the winners are adopted. Look at the AES competition - how often do you see Serpent being mentioned, despite it having a larger security margin than Rijndael by most accounts?

Blowfish has a continuing existence as the basis for bcrypt.

It works as a password hash for reasons having in part to do with why it isn’t a great general purpose cipher.
Post reply on HN