Earlier quoted context omitted.
> Incorrect. My argument is that they aren't the same entity. Your mind is going to be blown when you learn about proxy organizations and cut-outs.
NIST does a lot of things that have nothing to do with computer security! Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?
NSA and IETF: Fairness
151–160 of 198 posts
Re: NSA and IETF: Fairness
#152Earlier quoted context omitted.
> “People are already doing it, so we might as well rubber-stamp it even if it’s not great” introduces problems of its own: people will perceive that rubber-stamping as validating it, and now they’ll use it even more, where perhaps if you held back, they wouldn’t. The GOST cipher, which is Russia's AES equivalent, is also in an RFC: * https://datatracker.ietf.org/doc/html/rfc9189 * https://en.wikipedia.org/wiki/GOST_…
In fairness, I do think that this situation is somewhat different. As I noted above ( https://news.ycombinator.com/item?id=48812792 ), there are two main routes to an Informational RFC of this kind. * Through the IETF * Through the Independent Stream The GOST documents went through the Independent Stream and therefore do not have IETF imprimateur. These documents are proposed for the IETF Stream and therefore require…
* https://datatracker.ietf.org/doc/html/rfc6296
When I pointed out that the NAT(44) RFC (1631/3022) was 'only' "Informational" I got radio silence:
Re: NSA and IETF: Fairness
#153Earlier quoted context omitted.
To be clear, the Schneier Facts on Dual-EC turned out to be far more accurate than the Ptacek Gut Logic.
Schneier said the same thing I did. I literally got my take from Schneier. You don't even have the Schneier Facts right!
The BSAFE disclosure happened in 2013 with Snowden. In 2015 you published an article still questioning whether Dual-EC was a backdoor, and providing an immense amount of plausible deniability for folks like Hoffman.
https://sockpuppet.org/blog/2015/08/04/is-extended-random-ma...
You don’t even remember the historical Ptacek Gut Logic!
Re: NSA and IETF: Fairness
#154Earlier quoted context omitted.
NIST does a lot of things that have nothing to do with computer security! Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?
The Godfather Part 2 demonstrated overwhelmingly that a good part of Vito Corleone’s ill-gotten gains went to strengthening his community. The Italians in his neighborhood adored him.
That's beyond moving goalposts. Just take the L, dude.
Re: NSA and IETF: Fairness
#155Earlier quoted context omitted.
Schneier said the same thing I did. I literally got my take from Schneier. You don't even have the Schneier Facts right!
To quote you: “ (I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, it was immediately clear what was going on).” The BSAFE disclosure happened in 2013 with Snowden. In 2…
I mean, it's obvious what you did here: you went to my blog hoping to find the "Dual EC is fine" story, misread this one, and then took a random name out of it and tried to cast them as an archvillain.
Re: NSA and IETF: Fairness
#156Earlier quoted context omitted.
In fairness, I do think that this situation is somewhat different. As I noted above ( https://news.ycombinator.com/item?id=48812792 ), there are two main routes to an Informational RFC of this kind. * Through the IETF * Through the Independent Stream The GOST documents went through the Independent Stream and therefore do not have IETF imprimateur. These documents are proposed for the IETF Stream and therefore require…
I have gotten flack for giving ULA+NPTv6 as a possible solution to an IPv6 multi-homing issue because the RFC that describes it was 'only' "Experimental": * https://datatracker.ietf.org/doc/html/rfc6296 When I pointed out that the NAT(44) RFC (1631/3022) was 'only' "Informational" I got radio silence: * https://datatracker.ietf.org/doc/html/rfc1631
WRT IPv4 NAT, I'm not sure how much we can infer from the status. Many people at IETF were (and some still are) very anti-NAT, in part because they felt that IPv6 was the right solution. As a result, the IETF really avoided doing anything that looked like it was endorsing NAT, even though it's obviously just a fact of the Internet.
Re: NSA and IETF: Fairness
#157Earlier quoted context omitted.
1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental weakness that should cause a panic. Note that the non-constant time implementations were caught ~2 years ago, prior to any deployment. So it was a sign of everything going "as exp…
> pure ML-KEM is much more "proven" than people are discussing. The core hardness assumption dates back to 2005, and has been intensely studied (the paper introducing it got a cryptography version of a Nobel prize (Godel prize), as did several follow-up works only achievable using that hardness assumption. The inventor of the lobotomy won a Nobel Prize in Medicine for it.
Re: NSA and IETF: Fairness
#158Earlier quoted context omitted.
I might have expected you'd be once bitten twice shy after having once taking an aggressive position that DUAL-EC would never have backdoored anyone in practice... The optionality of MLKEM by itself is of a similar shape to standardizing a lame DRBG that 'obviously' no one would use and anyone who would use would use the appendix parameter generation scheme that would have rendered it secure (although still slow). Th…
None of this makes any sense once you understand that NSA had no hand in designing MLKEM, or in shaping the LWE research that led to it. NSA designed Dual-EC. MLKEM won an open competition; its entrants are among the most reputable cryptographers in the world.
I'm happy to agree that it affords much less degrees of freedom than original design, but the irrelevance argument depends on no influence rather than a lack of absolute influence.
Re: NSA and IETF: Fairness
#159Earlier quoted context omitted.
To quote you: “ (I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, it was immediately clear what was going on).” The BSAFE disclosure happened in 2013 with Snowden. In 2…
You don't understand the article you just quoted. It is certainly not the case that I published an article in 2015 questioning Dual EC. You might be the only person in the world with an opinion about Paul Hoffman, by the way. I had to look him up. I mean, it's obvious what you did here: you went to my blog hoping to find the "Dual EC is fine" story, misread this one, and then took a random name out of it and tried to…
Yet, your article says “In at least one case, Hoffman even attempted to provide a cryptographic rationale for extra randomness. Of course, naming-and-shaming either of them is pretty silly.” This makes no sense. We have names for criminal equivalents of his behavior: criminal mischief, disturbing the peace, conspiracy, etc. But if you do these things on a standards board, you get a pass? This was a concerted well-funded effort to compromise your security and my security. I think he should be put in a pillory and tarred-and-feathered.
You continue to cover for malicious actors with your “but the NSA didn’t write it!” insistence. The classic anti-Schneier Dual-EC take around 2007 was “but the NSA wouldn’t insert a backdoor, they would destroy their public image!” Your insistence is the equivalent of “but the NSA wouldn’t do that AGAIN!” Fool me once…
Re: NSA and IETF: Fairness
#160Earlier quoted context omitted.
The Godfather Part 2 demonstrated overwhelmingly that a good part of Vito Corleone’s ill-gotten gains went to strengthening his community. The Italians in his neighborhood adored him.
What does a work of fiction have to do with whether two distinct government entities are the same thing or not? That's beyond moving goalposts. Just take the L, dude.