Live data from Hacker News

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

nist.gov

21–30 of 60 posts

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#21
post #17

Earlier quoted context omitted.

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…

Who do you trust as an authority?

I don't know, but organizations which haven't duped people into using broken crypto before would be a good start.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#22
post #18
post #17

Earlier quoted context omitted.

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…

What if those trustworthy organizations were to tell you: "We trust this NIST competition result, and so should you"?

Maybe, if their reasoning for trusting the NIST competition result holds up to scrutiny. Do you have any links to trustworthy organizations which wholly endorse the results, with a detailed write-up as to why?

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#23
post #16

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

> The thing you should look at is the process, not the organization.

Then there shouldn't be a problem with another organization hosting the contest than NIST? Since I'm probably not alone in not being able to trust them anymore.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#24
post #2

CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars and star trek FYI to those who didn't know.

Kyber is lead by Crypto Jedi: https://cryptojedi.org/peter/ :)

Who also created another PQC algorithm (that didn't make it past 2nd round) — NewHope https://newhopecrypto.org/

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#25

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

You could look at the German BSI Federal Office for Information Security's documents, but you can't implement anything just by reading them, and they won't teach you about various attacks or other basic cryptographic principles.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#26

Does 'quantum-resistant' also imply 'P=NP' resistant?

No. Public key cryptography is impossible if P=NP. What we are left with is shared one-time-pads that can be arranged using quantum key distribution.

I am not an expert so I will simply link the Wikipedia article on Computational Complexity Theory as my "source".

https://en.m.wikipedia.org/wiki/Computational_complexity_the...

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#27
post #22
post #18

Earlier quoted context omitted.

What if those trustworthy organizations were to tell you: "We trust this NIST competition result, and so should you"?

Maybe, if their reasoning for trusting the NIST competition result holds up to scrutiny. Do you have any links to trustworthy organizations which wholly endorse the results, with a detailed write-up as to why?

I think we can revisit OP:

> However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public competition. They basically asked everyone to submit proposals and then asked everyone to find flaws in theses proposals.

> These competitions have a very good reputation in the cryptographic community.

A very brief google search provided citations to the proposals and counter-attacks for your perusal.

https://en.wikipedia.org/wiki/NIST_Post-Quantum_Cryptography...

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#28

Does 'quantum-resistant' also imply 'P=NP' resistant?

No. Public key cryptography is impossible if P=NP. What we are left with is shared one-time-pads that can be arranged using quantum key distribution. I am not an expert so I will simply link the Wikipedia article on Computational Complexity Theory as my "source". https://en.m.wikipedia.org/wiki/Computational_complexity_the...

If there is an n^(100^100) algorithm that solves an NP-complete problem, then P=NP, but public-key cryptography is still safe because for any practical n it's still too hard to break. There are also public-key systems that are based on NP-complete problems that are easily broken, because n is chosen too small.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#29

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out? So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence

> Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith?

Not sure if that's better or worse than them collaborating directly.

Edit: from a paper linked in another comment:

> Researchers raised concerns to NIST about both possible bias in the bits and a possible backdoor in Dual_EC_DRBG. NIST examined the issue. NSA dismissed NIST's concerns, responding that implementers could choose their own parameters to handle concerns about possible backdoors. NSA pressed NIST to standardize the algorithm, claiming that it needed FIPS validation of agency devices running Dual_EC_DRBG, and thus NIST approved Dual_EC_DRBG as one of four possible standardized random-bit generators. Dual_EC_DRBG remained a FIPS until shortly after the 2013 revelation of an NSA backdoor in a cryptographic algorithm.

https://harvardnsj.org/wp-content/uploads/sites/13/2022/06/V...

So seems NIST and others were aware of the shortcomings of Dual_EC_DRBG but was pressured by NSA to end up as a FIPS anyway.

Either way, hard to start trusting NIST again after a fiasco like that.

> And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out?

AFAIK, NSA didn't submit anything for this competition, but bunch of mathematicians from NSA have worked on helping NIST with the overall process of the competition, including reviewing the entries.

It wouldn't surprise me that if NSA found something, they would withhold any findings if they could benefit from being the only ones knowing about any holes. Although we all know how that ends.

> And the international counterparts can compare & perform their own due diligence

Yes, this is exactly what I'm asking for, the purpose of my initial comment. Who are these international counterparts that I can look to instead of NIST?

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#30
post #8

Earlier quoted context omitted.

I can't imagine with the added scrutiny the internet has gotten since then, especially from foreign governments, that NIST will be able to get away with anything like that again. But then again I may be completely ignorant as to the scope of NSA meddling.

> […] that NIST will be able to get away with anything like that again. You say this like NIST was an accomplice (and not also a victim).

If someone pressures (with just words and no threats) you into shooting another person, do you not at least partly hold some of the blame yourself?

Not sure what consequences NSA told NIST would happen if they said no, when they pressured them, but from the look of things (https://harvardnsj.org/wp-content/uploads/sites/13/2022/06/V...) it seems that NSA just asked NIST nicely to make Dual_EC_DRBG a FIPS even as it was weak, and NIST accepted that.

Post reply on HN