Live data from Hacker News

Debunking NIST's calculation of the Kyber-512 security level (2023)

blog.cr.yp.to

21–22 of 22 posts

Re: Debunking NIST's calculation of the Kyber-512 security level (2023)

#21
post #10

Earlier quoted context omitted.

Historically the NSA has sabotaged public cryptography standards so that it could crack them, while adversaries hopefully couldn't. It pays its employees to do this. It seems plausible that that's what's going on here, but even if so, whether that's because they know of a fatal weakness in NTRU they fear adversaries will exploit, or know of one in Kyber that they hope to exploit themselves, is anybody's guess.

NSA makes public their own policy for national security systems. https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA... If the U.S. Government is willing to bet the SECRET-and-above farm on particular cryptography standards and implementations, it’s probably safe for you to use them too.

FWIW, the US government actively develops and maintains a suite of classified cryptography algorithms[0] which are completely separate from the suite of algorithms they publish publicly. The reason for the existence of Suite A algorithms has never really been explained. I’ve heard rumors that it contains capabilities not known in public cryptographic algorithms, but that’s speculation.

[0] https://en.wikipedia.org/wiki/NSA_Suite_A_Cryptography

Re: Debunking NIST's calculation of the Kyber-512 security level (2023)

#22

Earlier quoted context omitted.

NSA makes public their own policy for national security systems. https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA... If the U.S. Government is willing to bet the SECRET-and-above farm on particular cryptography standards and implementations, it’s probably safe for you to use them too.

FWIW, the US government actively develops and maintains a suite of classified cryptography algorithms[0] which are completely separate from the suite of algorithms they publish publicly. The reason for the existence of Suite A algorithms has never really been explained. I’ve heard rumors that it contains capabilities not known in public cryptographic algorithms, but that’s speculation. [0] https://en.wikipedia.org/wi…

They do, and there are a lot of situations in which those algorithms are not usable, such as on mobile devices, hence the introduction of Suite B and now CNSA.
Post reply on HN