Live data from Hacker News

Debunking NIST's calculation of the Kyber-512 security level

blog.cr.yp.to

191–200 of 219 posts

Re: Debunking NIST's calculation of the Kyber-512 security level

#191
post #114

Earlier quoted context omitted.

Even with a verifiably random key, Dual EC is still unacceptable. First, because its output has unacceptable biases [1,2]. Second, because its presence allows an attacker to create a difficult-to-detect backdoor simply by replacing the key, as apparently happened with Juniper NetScreen devices [3,4]. --- [1] Kristian Gjøsteen, Comments on Dual-EC-DRBG/NIST SP 800-90, draft December 2005. Online: https://web.archive.o…

> Even with a verifiably random key What's a "verifiably random" key?

"Verifiably random" means produced using a process where it isn't possible for you to know the outcome. In this case, saying "the key is [X], which is the SHA-2 hash of [Y]" would allow you to know that they couldn't choose [X] without breaking SHA-2.

Re: Debunking NIST's calculation of the Kyber-512 security level

#192
post #136

> Discovering the secret workings of NISTPQC. I filed a FOIA request "NSA, NIST, and post-quantum cryptography" in March 2022. NIST stonewalled, in violation of the law. Civil-rights firm Loevy & Loevy filed a lawsuit on my behalf. As much as I generally loathe djb personally, professionally he will always have my support as he’s been consistently willing to take the federal government to task in court. It brings me…

Why do you dislike him personally?

https://news.ycombinator.com/item?id=13891900

Re: Debunking NIST's calculation of the Kyber-512 security level

#193

Earlier quoted context omitted.

It's in there. He first raised the issue in April 2022. Then in December 2022 he asked about the evaluation of Kyber's security and they posted this[1], which included a 2^40 multiple that he wasn't sure where it came from; if it came from where he thought it did (bogus math on numbers from a paper DJB himself coauthored), then that was troubling. There was no response, so a few weeks later he posted his assumptions…

> NIST's prior assertions and their interpretation are not relevant [...] That seems to be an extraordinarily strong claim to make, without detailed explanation, which apparently wasn't provided.

There did seem to be some talking past each other. The most kind to NIST explanation is they wanted DJB to say something like "Adopting Kyber-512 is bad because it is likely to be less strong than AES-128, and here's the math" while DJB wanted to rebut the analysis that NIST, (hopefully with the aid of a member of the team developing Kyber) had done.

I think there was also a bit of DJB wanting to engage NIST in a scientific debate (and getting increasingly abrasive when this didn't happen), while NIST wanted none of that, preferring that such debates be between researchers.

However from the point of view advanced in TFA, the best published papers implied that Kyber's security was likely very close to another algorithm (that the author of TFA preferred) that was disqualified for being insufficiently strong.

Re: Debunking NIST's calculation of the Kyber-512 security level

#194
post #47

Earlier quoted context omitted.

Bad systems beat good people. There are a lot of symptoms to distract yourself with. Focus on the game instead. A society full of good people will sort out the rest.

This apathy is an interesting phenomenon, let's not ignore it. The Internet has brought us a wealth of knowledge but it has also shown us how truly chaotic the world really is. And negativity is a profitable way to drive engagement, so damn near everyone can see how problematic our society is. And when the algorithm finds something you care to be sad about, it will show you more, more, and ever more all the way into…

Bad systems beat good people.

Everything you listed is valid (through one lens), but they are symptoms. Distract yourself with symptoms and you'll never solve the problem.

Application Service Providers, as they exist today, are bad systems.

They provide tremendous value, that's why they exist. But they also carry tremendous cost. So far, nobody has solved the cost without compromising the value.

If you want to fix the web, moving us closer to a free and open web, stay hyper focused on solving the cost without compromising the value.

First past the post voting is a bad system.

In the U.S. you don't solve politics by voting for candidates, that's treating symptoms.

If you are a staunch republican, vote republican. If you are a staunch democrat, vote democrat.

Everyone else should be hyper focused on one thing: ballot reform.

If you want to solve the problem, focus on the game and solve it. A society full of good, but currently defeated, people will do the rest.

Re: Debunking NIST's calculation of the Kyber-512 security level

#195
post #140
post #45

Earlier quoted context omitted.

Teams of cryptographers submit several proposals (and break each other's proposals). These people are well respected, largely independent, and assumed honest. Some of the mailing lists provided by NIST where cryptographers collaborated to review each other's work are public NIST may or may not consort with your friendly local neighborhood NSA people, who are bright and talented contributors in their own right. That's…

> NIST may or may not consort with your friendly local neighborhood NSA people It is worth noting that while breaking codes is a big part of the NSA's job, they also have a massive organization (NSA Cybersecurity, but I prefer the old name Information Assurance) that works to protect US and allied systems and cryptographic applications. In the balance, weakening American standards does little to help with foreign col…

> In the balance, weakening American standards does little to help with foreign collection.

Though it can be greatly beneficial for domestic collection. Further, so long as the US remains a dominant player in Tech and Tech-influenced fields like finance, odds are a lot of the world is going to be at least de facto using US standards.

Re: Debunking NIST's calculation of the Kyber-512 security level

#196
post #67

The unfortunate reality of this is that while he may be right , it is difficult to classify the responses (or non-response) from the NIST people as deceptive vs just not wanting to engage with someone coming from such an adversarial position. NIST is staffed by normal people who probably view aggressively worded requests for clarification in the same way that most of us have probably fielded aggressively worded bug r…

If TFA were by a nobody I might agree, but TFA is by DJB and/or Tanja Lange, and they're not nobodies. These things need to be at least somewhat adversarial partly because that's what it takes to do cryptanalysis, and partly because of past shenanigans. It goes with the territory and the politics. It's unavoidable.

Re: Debunking NIST's calculation of the Kyber-512 security level

#197
post #16

That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…

NSA weakened DES from 64-bit keys to 56-bit keys. The idea was that they could be ahead in breaking it, and that by the time 56-bit keys were too weak in general then something else would replace DES. Risky? Yes, but it worked out, for some value of "worked out". So I wouldn't assume something like that wouldn't happen again.

Re: Debunking NIST's calculation of the Kyber-512 security level

#198
post #34

Earlier quoted context omitted.

> At this point, it feels quite strongly to me that he is trying to interpret every action in the most malicious way possible. Given the long and detailed history of various governments and government agencies purposefully attempting to limit the public from accessing strong cryptography, I tend to agree with the "assume malice by default" approach here. Assuming anything else, to me at least, seems pretty naive.

Eh, it goes both ways. Back in the 1970's and 1980's there was a whole lot of suspicion about changes that the NSA made to DES S-boxes with limited explanation- was it a backdoor in some way? Then in 1989 white hats "discovered" differential cryptography, and realized that the changes that were made to the algorithm actually protected it from a then-unknown (to the general public) cryptographic attack. Differential c…

[deleted]

Re: Debunking NIST's calculation of the Kyber-512 security level

#199

Assuming djb is correct and the current process is broken... is trying to expose it and then fix it through FOIA requests really the best approach? If your codebase is hairy enough, and the problem to be solved is fundamentally fairly simple, sometimes it's better to rewrite than refactor. Doubly so if you believe a clever adversary has attempted to insert a subtle backdoor or bugdoor. What would a better crypto sele…

Taking money from the cryptographers offers the exact opposite incentive that you want it to: your NSA black budget slush fund has orders of magnitude more spending power than anybody honest could hope to acquire.

Re: Debunking NIST's calculation of the Kyber-512 security level

#200
post #67

The unfortunate reality of this is that while he may be right , it is difficult to classify the responses (or non-response) from the NIST people as deceptive vs just not wanting to engage with someone coming from such an adversarial position. NIST is staffed by normal people who probably view aggressively worded requests for clarification in the same way that most of us have probably fielded aggressively worded bug r…

If TFA were by a nobody I might agree, but TFA is by DJB and/or Tanja Lange, and they're not nobodies. These things need to be at least somewhat adversarial partly because that's what it takes to do cryptanalysis, and partly because of past shenanigans. It goes with the territory and the politics. It's unavoidable.

One can be combative and adversarial and still write succinctly and persuasively.

This text does DJB no favors. He comes across like a conspiracy theorist, based on the form of the content alone.

Post reply on HN