Live data from Hacker News

Debunking NIST's calculation of the Kyber-512 security level

blog.cr.yp.to

141–150 of 219 posts

Re: Debunking NIST's calculation of the Kyber-512 security level

#141
post #34

Earlier quoted context omitted.

> At this point, it feels quite strongly to me that he is trying to interpret every action in the most malicious way possible. Given the long and detailed history of various governments and government agencies purposefully attempting to limit the public from accessing strong cryptography, I tend to agree with the "assume malice by default" approach here. Assuming anything else, to me at least, seems pretty naive.

Eh, it goes both ways. Back in the 1970's and 1980's there was a whole lot of suspicion about changes that the NSA made to DES S-boxes with limited explanation- was it a backdoor in some way? Then in 1989 white hats "discovered" differential cryptography, and realized that the changes that were made to the algorithm actually protected it from a then-unknown (to the general public) cryptographic attack. Differential c…

>So sometimes they strengthen it, sometimes they weaken it, and so I'm not sure it appropriate to presume malice.

If you had a dog that sometimes licked you and sometimes bit you, would you let it sleep with you?

Neither NSA nor NIST can be trusted. They brought this on themselves.

Re: Debunking NIST's calculation of the Kyber-512 security level

#142
post #67

The unfortunate reality of this is that while he may be right , it is difficult to classify the responses (or non-response) from the NIST people as deceptive vs just not wanting to engage with someone coming from such an adversarial position. NIST is staffed by normal people who probably view aggressively worded requests for clarification in the same way that most of us have probably fielded aggressively worded bug r…

> If Kyber-512 is actually this risky, then it deserves to be communicated clearly.

The statement djb seems to be making: It is not known if Kyber-512 is as cryptographically strong as AES-128 by the definitions provided by NIST.

This is an issue because these algorithms will be embedded within hardware soon.

> Besides the fact that nobody is deploying standalone PQ for some time

Now that an implementation has been chosen to be standardized, hardware vendors are likely to start designing blocks that can more efficiently compute the FIPS 203 standard (if they haven't already designed a few to begin with).

Given that the standard's expected publication is in 2024, and the 1-2 year review timeline for NIST CMVP review on FIPS modules, I wouldn't be surprised to see a FIPS 140-3 Hardware Module with ML-KEM (Kyber-etc.) by mid 2026.

> a succinct breakdown of why

The issue seems to be his statement from [1]: "However, NIST didn't give any clear end-to-end statements that Kyber-512 has N bits of security margin in scenario X for clearly specified (N,X)."

djb succinctly outlines the "scenario X" he referred to in [2], in which he only needs a yes or no answer. He is literally asking the people who should know and be able to discuss the matter, who would have the technical background to discuss this matter. He had received no response, which is why he had posted [1].

NIST's reply in [3] is a dismissal of [1] without a discussion of the security itself. The frustrating part for me to read was the second paragraph: "The email you cited (https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...), speaks for itself. NIST continues to be interested in people's opinions on whether or not our current plan to standardize Kyber512 is a good one. While reviewers are free, as a fun exercise, to attempt to "disprove what NIST _appears_ to be claiming about the security margin," the results of this exercise would not be particularly useful to the standardization process. NIST's prior assertions and their interpretation are not relevant to the question of whether people believe that it is a good idea to standardize Kyber512."

If NIST views the reviewers' claims about security to be "not particularly useful to the standardization process," (and remember: the reviewers are themselves cryptographers) then why should the public trust the standard at all?

> a smoking gun or two would be great

There wouldn't be a smoking gun because the lack of clarification is the issue at hand. If they could explain how they calculated the security strength of Kyber-512, then this would be a different issue.

The current 3rd party estimates of Kyber-512's security strength (which is a nebulous term...) puts it below the original requirements, so clarification or justification seems necessary.

[1]: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...

[2]: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...

[3]: https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/4MBu...

Re: Debunking NIST's calculation of the Kyber-512 security level

#143

Earlier quoted context omitted.

> If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. > However, this man is one of the foremost cryptographers in the world […] It's possible to be both (not saying Bernstein is). Plenty of smart folks have 'jumped the shark' intellectually: Ted Kaczynski, the Unabomber, was very talented in mathematics before he went off the deep…

There was a smart guy once who went crazy. We should assume smart people are crazy.

That's not the claim. The claim is "because we know smart people have gone crazy, we know being smart and being crazy are not mutually exclusive, so someone being smart isn't disqualified from also being crazy." Which seems obviously true.

Re: Debunking NIST's calculation of the Kyber-512 security level

#144
post #119
post #99

Related note: Government employees (including military, intel) are just people, and worse, bureaucrats. They aren't magical wizards who can all do amazing things with mathematics and witchcraft. If they were good at what they do, they wouldn't need ever increasing funding and projects to fix things.

Cryptanalysis and encryption are somewhat of an exception to this. There are some extremely smart people who work in these areas for the government, precisely because funding and application is on a different scale.

Very few folks except the gov’t have real existential need for best in breed crypto, frankly.

Re: Debunking NIST's calculation of the Kyber-512 security level

#145
post #136

> Discovering the secret workings of NISTPQC. I filed a FOIA request "NSA, NIST, and post-quantum cryptography" in March 2022. NIST stonewalled, in violation of the law. Civil-rights firm Loevy & Loevy filed a lawsuit on my behalf. As much as I generally loathe djb personally, professionally he will always have my support as he’s been consistently willing to take the federal government to task in court. It brings me…

Why do you dislike him personally?

Re: Debunking NIST's calculation of the Kyber-512 security level

#146

Earlier quoted context omitted.

> If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. > However, this man is one of the foremost cryptographers in the world […] It's possible to be both (not saying Bernstein is). Plenty of smart folks have 'jumped the shark' intellectually: Ted Kaczynski, the Unabomber, was very talented in mathematics before he went off the deep…

> Plenty of smart folks have 'jumped the shark' intellectually: Ted Kaczynski, the Unabomber, was very talented in mathematics before he went off the deep end. Kaczynski dropped out of society to live in a cabin alone at 29. He delivered his first bomb at 35. I'm not sure this is a reasonable comparison to invoke in any way whatsoever. When DJB starts posting about the downfall of modern society from his remote cabin…

While kaczynski was clearly unhinged, and I frankly don’t see how sending mail bombs did anything helpful towards solving the problems he addressed (or that his proposed solution would necessarily be better than ‘the disease’), I dare anyone to read his manifesto and say he was wrong.

If DJB is unhinged but similarly insightful about a crypto algo, I think we’d all be better off. Assuming he lays off the mailbombs anyway.

Re: Debunking NIST's calculation of the Kyber-512 security level

#147

Earlier quoted context omitted.

Blowfish has a continuing existence as the basis for bcrypt.

It works as a password hash for reasons having in part to do with why it isn’t a great general purpose cipher.

Can you expand, or link to an explanation?

Re: Debunking NIST's calculation of the Kyber-512 security level

#148
post #127
post #108

Earlier quoted context omitted.

You mean ANSI/ISO/NIST and Dual_EC_DRBG, that everyone suspected had a backdoor before it was included as one of multiple options? https://en.m.wikipedia.org/wiki/Dual_EC_DRBG#Timeline_of_Dua... Or the s-boxes in DES, that the NSA suggested to IBM + NIST's predecessor, so as to be resistant to then-not-widely-known differential cryptanalysis? https://web.archive.org/web/20120106042939/http://securespee...

[flagged]

He/she means that there have been good things coming out of the NSA/NIST collaborations (another example is SHA0->SHA1, introducing a "mysterious" left shift that made SHA1 much stronger), and the bad ones are caught quickly.

Re: Debunking NIST's calculation of the Kyber-512 security level

#149
post #117

Earlier quoted context omitted.

That is not true. There is no such requirement for a hash function.

Thread is talking about cryptographic hash functions, given the context

Yes, they don’t output random looking things necessarily. For example a hash function could be collision resistant but not pre image resistant, or vice versa. There’s much more nuance in these definitions.

Re: Debunking NIST's calculation of the Kyber-512 security level

#150

Earlier quoted context omitted.

There was a smart guy once who went crazy. We should assume smart people are crazy.

That's not the claim. The claim is "because we know smart people have gone crazy, we know being smart and being crazy are not mutually exclusive, so someone being smart isn't disqualified from also being crazy." Which seems obviously true.

And not useful
Post reply on HN