Live data from Hacker News

Debunking NIST's calculation of the Kyber-512 security level

blog.cr.yp.to

21–30 of 219 posts

Re: Debunking NIST's calculation of the Kyber-512 security level

#21
post #15

If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. However, this man is one of the foremost cryptographers in the world, he has basically single-handedly killed US government crypto export restrictions back in the days, and (not least of all because of Snowden) we know that the NSA really is trying to sabotage cryptography. Also, h…

An interesting set of comments (by tptacek) from a thread in 2022 (I wonder if they still hold the same opinion in light of this latest post on NIST-PQC by djb): > The point isn't that NIST is trustworthy. The point is that the PQC finalist teams are comprised of academic cryptographers from around the world with unimpeachable reputations, and it's ludicrous to suggest that NSA could have compromised them. The whole…

I hope he finds all sorts of crazy documents from his FOIA thing. FOIA lawsuits are a very normal part of the process (I've had the same lawyers pry loose stuff from my local municipality). I would bet real money against the prospect of him finding anything that shakes the confidence of practicing cryptography engineers in these standards. Many of the CRYSTALS team members are quite well regarded.

Re: Debunking NIST's calculation of the Kyber-512 security level

#22
post #2

Unfortunately, the NSA & NIST most likely is recommending a quantum-proof security that they've developed cryptanalysis against, either through high q-bit proprietary technology or specialized de-latticing algorithms . The NSA is very good at math, so I'm be thoroughly surprised if this analysis was error by mistake rather than error through intent.

The NSA also has a mission-based interest in _breaking_ other people's crypto though, which is generally known. Which is generally known, so I'm surprised by your argument. Even if the NSA knows more than they are telling us, this doesn't result in most of us feeling less worried, as their ends may not be strengthening the public's cryptography!

Yes: https://en.wikipedia.org/wiki/Dual_EC_DRBG

Also, we still to this day do not know where the seed for P256 and P384 came from. And we're using that everywhere. There is a non-zero chance that the NSA basically has a backdoor for all NIST ECC curves, and no one actually seems to care.

Re: Debunking NIST's calculation of the Kyber-512 security level

#23
post #16

That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…

> Why would they be willing to risk that here?

Certain types of attacks basically make it so you need to have a specific private key to act as a backdoor. That's the current guess on what may be happening with the NIST ECC curves.

If so, this can be effectively a US-only backdoor for a long, long time.

Re: Debunking NIST's calculation of the Kyber-512 security level

#24

Notwithstanding DJB's importance to cryptography, and the fact that I'm ignorant of a large number of details here, there was a point where he lost a lot of credibility with me. Specifically, when he gets to the graphs, he says "NIST chose to deemphasize the bandwidth graph by using thinner red bars for it." That is just not proven by his evidence, and there is a very plausible explanation for it. The graph that has…

> Knowing that DJB was involved in NTRU, it's a little hard to shake the feeling that a lot of this is DJB just being salty about losing the competition.

There isn't a lot of people in the world with the technical know-how for cryptography. It's clear that competitors in this space are going to be reviewing eachothers work.

Re: Debunking NIST's calculation of the Kyber-512 security level

#25
post #2

Unfortunately, the NSA & NIST most likely is recommending a quantum-proof security that they've developed cryptanalysis against, either through high q-bit proprietary technology or specialized de-latticing algorithms . The NSA is very good at math, so I'm be thoroughly surprised if this analysis was error by mistake rather than error through intent.

"Specialized de-latticing algorithms"?

Re: Debunking NIST's calculation of the Kyber-512 security level

#26
post #24

Notwithstanding DJB's importance to cryptography, and the fact that I'm ignorant of a large number of details here, there was a point where he lost a lot of credibility with me. Specifically, when he gets to the graphs, he says "NIST chose to deemphasize the bandwidth graph by using thinner red bars for it." That is just not proven by his evidence, and there is a very plausible explanation for it. The graph that has…

> Knowing that DJB was involved in NTRU, it's a little hard to shake the feeling that a lot of this is DJB just being salty about losing the competition. There isn't a lot of people in the world with the technical know-how for cryptography. It's clear that competitors in this space are going to be reviewing eachothers work.

Yes, that was the premise of the competition, and was in fact what happened.

Re: Debunking NIST's calculation of the Kyber-512 security level

#27
post #15

If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us. However, this man is one of the foremost cryptographers in the world, he has basically single-handedly killed US government crypto export restrictions back in the days, and (not least of all because of Snowden) we know that the NSA really is trying to sabotage cryptography. Also, h…

>If you have never heard of Bernstein, this may look like mad ramblings of a proto-Unabomber railing against THE MAN trying to oppress us.

Can I point out that Ted Kaczynski was also actually a mathematical prodigy, having been accepted into Harvard on a scholarship at 16?

Re: Debunking NIST's calculation of the Kyber-512 security level

#28

Love the narrative style of this writing second-guessing the erroneous thought processes. Are they deceptive? Who knows. What worries me is that it's neither malice nor incompetence, but that a new darker force has entered our world even at those tables with the highest stakes.... dispassion and indifference. It's hard to get good people these days. A lot of people stopped caring. Even amongst the young and eager. Wh…

Bad systems beat good people.

There are a lot of symptoms to distract yourself with. Focus on the game instead.

A society full of good people will sort out the rest.

Re: Debunking NIST's calculation of the Kyber-512 security level

#29
post #23
post #16

That's more of a diary than an article -- jargony, disorganized, running in circles, very hard to follow. But the information might be important regardless. There's a strong implication that NIST with help of the NSA intentionally standardized on a weak algorithm. We all know that's possible. But can someone who follows some of this stuff more closely explain what the play would be? I always assumed that weakening pu…

> Why would they be willing to risk that here? Certain types of attacks basically make it so you need to have a specific private key to act as a backdoor. That's the current guess on what may be happening with the NIST ECC curves. If so, this can be effectively a US-only backdoor for a long, long time.

I don't believe that is anybody's guess on what may be happening with the NIST ECC curves. Ordinarily, when people on HN say things like this, they're confusing Dual EC, a public key random number generator, known to be backdoored, with the NIST curve standards.

Re: Debunking NIST's calculation of the Kyber-512 security level

#30
post #29
post #23

Earlier quoted context omitted.

> Why would they be willing to risk that here? Certain types of attacks basically make it so you need to have a specific private key to act as a backdoor. That's the current guess on what may be happening with the NIST ECC curves. If so, this can be effectively a US-only backdoor for a long, long time.

I don't believe that is anybody's guess on what may be happening with the NIST ECC curves. Ordinarily, when people on HN say things like this, they're confusing Dual EC, a public key random number generator, known to be backdoored, with the NIST curve standards.

Yeah I've noticed people mixing them up. They happened around the same time, so I can excuse it a bit.

The problem with the NIST ECC curves are that we still do not know where the heck that seed came from and why that seed specifically.

Post reply on HN