It would be interesting to see Signal Sciences response to this Bernstein’s post
Debunking NIST's calculation of the Kyber-512 security level
131–140 of 219 posts
Re: Debunking NIST's calculation of the Kyber-512 security level
#132Earlier quoted context omitted.
While I agree with a lot of what you have said, > Still, the idea that he's "the only one who can produce the good algorithms" The parent post did not, at all, make the claim that Bernstein is the only one .
No, true, the post did not explicitly state this. However the post did suggest that NIST is specifically out to get him and take a swipe at the other candidates: > Is NIST trying to derail his work by standardizing crappy algorithms with the help of the NSA? Who knows. But to me it does smell like that. "Crappy" algorithms that were designed by well-regarded cryptographers, none of whom work for NIST or the NSA, many…
Re: Debunking NIST's calculation of the Kyber-512 security level
#133If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. However, this man is one of the foremost cryptographers in the world, he has basically single-handedly killed US government crypto export restrictions back in the days, and (not least of all because of Snowden) we know that the NSA really is trying to sabotage cryptography. Also, h…
> If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. > However, this man is one of the foremost cryptographers in the world […] It's possible to be both (not saying Bernstein is). Plenty of smart folks have 'jumped the shark' intellectually: Ted Kaczynski, the Unabomber, was very talented in mathematics before he went off the deep…
Re: Debunking NIST's calculation of the Kyber-512 security level
#134Earlier quoted context omitted.
I don't think the "these finalist teams are trustworthy" argument is completely watertight. If the US wanted to make the world completely trust and embrace subtly-broken cryptography, a pretty solid way to do that would be to make competition where a whole bunch of great, independent teams of cryptography researchers can submit their algorithms, then have a team of excellent NSA cryptographers analyze them and pick a…
If the NSA has back-pocketed exploits on the LWE submission from the CRYSTALS authors, it's not likely that a purely academic competition would have fared better. The CRYSTALS authors are extraordinarily well-regarded. This is quite a bank-shot theory of OPSEC from NSA.
Re: Debunking NIST's calculation of the Kyber-512 security level
#135Earlier quoted context omitted.
You're making an assumption that the NSA cares about the efficacy of cryptography for other people. Why would they care about that?
it's in the national security interest of the United States to have its industries use high-quality crypto see: colonial oil pipeline hack
It's not entirely known how every step of that attack went down, but "breaking low quality crypto" hasn't factored into any incident write up I've ever seen.
However, nearly all ransomware uses rsa. Therefore in this particular case, high quality crypto caused harm.
(To state the obvious, I'm not advocating for bad crypto, just discussing this case).
Re: Debunking NIST's calculation of the Kyber-512 security level
#136As much as I generally loathe djb personally, professionally he will always have my support as he’s been consistently willing to take the federal government to task in court. It brings me great joy to see he’s still at it.
Re: Debunking NIST's calculation of the Kyber-512 security level
#137Earlier quoted context omitted.
If the NSA has back-pocketed exploits on the LWE submission from the CRYSTALS authors, it's not likely that a purely academic competition would have fared better. The CRYSTALS authors are extraordinarily well-regarded. This is quite a bank-shot theory of OPSEC from NSA.
This of course means we should ignore reasonable criticism of the contestants in this contest.
Re: Debunking NIST's calculation of the Kyber-512 security level
#138Earlier quoted context omitted.
I was under the impression that only fools trust NIST after DUAL_EC_whatsit. Is that not the case?
You mean ANSI/ISO/NIST and Dual_EC_DRBG, that everyone suspected had a backdoor before it was included as one of multiple options? https://en.m.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dua... Or the s-boxes in DES, that the NSA suggested to IBM + NIST's predecessor, so as to be resistant to then-not-widely-known differential cryptanalysis? https://web.archive.org/web/20120106042939/http://securespee...
There is a widely held belief that the US IC changed fundamentally in terms of their regard for their own raison d’etre that day.
Re: Debunking NIST's calculation of the Kyber-512 security level
#139Earlier quoted context omitted.
Correct me if I'm wrong, everything is also being done out in the open for everyone to see. The NIST aren't using some secret analysis to make any recommendations.
My rule of thumb in these situations is always: if they could, they would. I've seen enough blatant disregard for humanity to assume any kind of honesty in the powers that were.
No one can say they pushed some useless or overtly backdoored encryption. That's rarely how Intel agencies work. It's also not how they need to work to maintain their effectiveness indefinitely.
When the CIA is trying to recruit for HUMINT if they can get claws into anything whether it's a business conference that has a 0.1% chance they'll meet some pliable young but likely future industry insider that may or may not turn into a valuable source then they'll show up to every single year to that conference. It's a matter of working every angle you can get.
They aren't short of people, time, or money. And in security tiny holes in a dam turn into torrents of water all the time.
The fact NIST is having non public backroom meetings with NSA, concealing NSA employee paper authors, generating a long series of coincidental situations preferencing one system, and stonewalling FIOAs from reputable individuals. IDK, if was a counter intelligence officer in charge of detecting foreign IC work I'd be super suspicious of anything sold as safe and open from that org.
Re: Debunking NIST's calculation of the Kyber-512 security level
#140Earlier quoted context omitted.
Correct me if I'm wrong, everything is also being done out in the open for everyone to see. The NIST aren't using some secret analysis to make any recommendations.
Teams of cryptographers submit several proposals (and break each other's proposals). These people are well respected, largely independent, and assumed honest. Some of the mailing lists provided by NIST where cryptographers collaborated to review each other's work are public NIST may or may not consort with your friendly local neighborhood NSA people, who are bright and talented contributors in their own right. That's…
It is worth noting that while breaking codes is a big part of the NSA's job, they also have a massive organization (NSA Cybersecurity, but I prefer the old name Information Assurance) that works to protect US and allied systems and cryptographic applications.
In the balance, weakening American standards does little to help with foreign collection. Their efforts would be much better spent injecting into the GOST process (Russia and friends) or State Cryptography Administration (China and friends).