Earlier quoted context omitted.
It's "cipher". But we're not talking about ciphers; we're talking about key establishment algorithms.
It's cypher in British English.
NSA and IETF: Fairness
191–198 of 198 posts
Re: NSA and IETF: Fairness
#192Earlier quoted context omitted.
Did you really need me to specify rhetorically speaking? You weren't able to work out that on your own?
Nobody is even rhetorically asking you to trust NIST.
> you don't have to trust the server
oh, sorry I should have realized this wasn't a conversation anymore
Re: NSA and IETF: Fairness
#193Earlier quoted context omitted.
Nobody is even rhetorically asking you to trust NIST.
If you run a server using TLS, and that server select Kyber, does the security of the connection depend on Kyber being sound? If I need to trust the security of the connection. I have to trust the server, because the server trusts Kyber, that means I have to trust Kyber, because I have to trust the server. > you don't have to trust the server oh, sorry I should have realized this wasn't a conversation anymore
Re: NSA and IETF: Fairness
#194Earlier quoted context omitted.
If you run a server using TLS, and that server select Kyber, does the security of the connection depend on Kyber being sound? If I need to trust the security of the connection. I have to trust the server, because the server trusts Kyber, that means I have to trust Kyber, because I have to trust the server. > you don't have to trust the server oh, sorry I should have realized this wasn't a conversation anymore
I don't even know who you're replying to anymore; who are you quoting? You get that you and I are the only people reading this, right? You're not going to convince me; you already opened this conversation up by acknowledging you're totally unfamiliar with the field you're commenting on.
Good luck buddy :)
Re: NSA and IETF: Fairness
#195Earlier quoted context omitted.
It's cypher in British English.
Exercise for the reader (out of genuine interest): find the most important cryptographic paper published in the last 15 years that uses the British spelling.
Besides, I don't doubt the US spelling has taken over, that has happened a lot in a wide range of fields, but it doesn't invalidate the British spelling, even if it isn't as widely used in recent published papers.
It's like claiming that the element is sulfur not sulphur, because papers are increasingly written for an international audience. In British English, the element is Sulphur, regardless of whether you can find an "important paper" using the spelling.
Re: NSA and IETF: Fairness
#196Earlier quoted context omitted.
Exercise for the reader (out of genuine interest): find the most important cryptographic paper published in the last 15 years that uses the British spelling.
Why the 15 year cut-off? Besides, I don't doubt the US spelling has taken over, that has happened a lot in a wide range of fields, but it doesn't invalidate the British spelling, even if it isn't as widely used in recent published papers. It's like claiming that the element is sulfur not sulphur, because papers are increasingly written for an international audience. In British English, the element is Sulphur, regardl…
Re: NSA and IETF: Fairness
#197Earlier quoted context omitted.
In the past NSA has weakened encryption standards, for example NSA madified DES standard. The NSA pushed backdoored design of Dual_EC_DRBG was standardized in NIST SP 800-90A. "Weaknesses in the cryptographic security of the algorithm were known and publicly criticised well before the algorithm became part of a formal standard endorsed by the ANSI, ISO, and formerly by the National Institute of Standards and Technolo…
> In the past NSA has weakened encryption standards, for example NSA madified DES standard. They made DES more secure against differential cryptanalysis (a method that was classified at the time DES was being designed). Sure, the whole "make the keys 56-bit instead of 64-bit" is a weakening, but differential cryptanalysis would have broken the entire fucking cipher if they didn't prevent it by selecting a secure S-bo…
"
Michael Hayden, a former NSA Director, has since acknowledged the concept of NOBUS:
You look at a vulnerability through a different lens if even with the vulnerability it requires substantial computational power or substantial other attributes and you have to make the judgment who else can do this? If there's a vulnerability here that weakens encryption but you still need four acres of Cray computers in the basement in order to work it you kind of think "NOBUS" and that's a vulnerability we are not ethically or legally compelled to try to patch – it's one that ethically and legally we could try to exploit in order to keep Americans safe from others."
https://en.wikipedia.org/wiki/NOBUSIn general we can asume that NOBUS applies to everything NSA publishes or supports. If not in direct algorithmic weakness, then in weakened parameters or in selection of algorithms that are hard to implement in secure way without specialized hardware support (side channel attacks of AES, sensitivity of DSA to quality of random number generator, hard to correctly implement NIST curves - generated by NSA).
Re: NSA and IETF: Fairness
#198Earlier quoted context omitted.
Probably not. It's been ~13 years when Snowden said what the NSA is doing is going around the encryption by hacking endpoints. Post quantum cryptography doesn't change any of that. You can still lift TLS keys with exploits for transparent MITM. I'd imagine it's much better ROI to look for vulnerabilities with Mythos, than to attack the algorithms.
> is going around the encryption by hacking endpoints Because they weren't (supposedly) able to break the encryption > than to attack the algorithms You have an opportunity to introduce new, broken, algorithms; they exploited it with DES, tried to exploit it with ECC, why wouldn't they try it with post-quantum (which they've kind of been pushing)?