Live data from Hacker News

NSA and IETF, part 3: Dodging the issues at hand

blog.cr.yp.to

241–249 of 249 posts

Re: NSA and IETF, part 3: Dodging the issues at hand

#241

Earlier quoted context omitted.

I don't make a habit of googling things for people when they could do it just as quickly themselves. There is only one paper proposing the OpenSSL heartbeat feature. So I have not been unclear, nor can there be any confusion about which it is. Perhaps we'll learn someday what tptacek expects to find or not to find in it, but he'll have to spend 30 seconds with Google. As I did. Informing one's self is a pretty low ba…

Your argument that heart bleed was intentional is very weak

Means, motive, and opportunity. Seems to check all the boxes.

There's no conclusive evidence that it wasn't purposeful. And plenty of evidence of past plausibly deniable attempts. So you can believe whatever lets you sleep better at night.

Re: NSA and IETF, part 3: Dodging the issues at hand

#242

Earlier quoted context omitted.

At least in terms of the Bada55 paper, I think he writes in a fairly jocular style that sounds unprofessional unless you read his citations as well. You seem to object to his occasional jocularity and take it as prima facie evidence of him being “batshit”. Given that you are well known for a jocular writing style, perhaps you should extend some grace. The slides seem like a pretty nice summary of the 2015-era SafeCur…

No, what I'm saying has only to do with the substance of his claims , which I now think you don't understand, because I laid them out straightforwardly (I might have been wrong, but I definitely wasn't making a tone argument) and you came back with this. People actually do work in this field. You can't just bluster your way through it. This is a "challenge" with discussing Bernstein claims on Hacker News and places l…

I’m not sure why you’re hung up on SNTRUP, since DJB didn’t submit it past round 2 of NISTPQC. In round 3, DJB put his full weight behind Classic McEliece.

You’ve previously argued that “cryptosystems based on ring-LWE hardness have been worked on by giants in the field since the mid-1990s” and suggested this is a point in Kyber’s favor. Well, news flash, McEliece has been worked on by giants in the field for 45 years. It shows up in NSA’s declassified internal history book, though their insights into the crypto system are still classified to this day.

Re: NSA and IETF, part 3: Dodging the issues at hand

#243

Earlier quoted context omitted.

No, what I'm saying has only to do with the substance of his claims , which I now think you don't understand, because I laid them out straightforwardly (I might have been wrong, but I definitely wasn't making a tone argument) and you came back with this. People actually do work in this field. You can't just bluster your way through it. This is a "challenge" with discussing Bernstein claims on Hacker News and places l…

I’m not sure why you’re hung up on SNTRUP, since DJB didn’t submit it past round 2 of NISTPQC. In round 3, DJB put his full weight behind Classic McEliece. You’ve previously argued that “cryptosystems based on ring-LWE hardness have been worked on by giants in the field since the mid-1990s” and suggested this is a point in Kyber’s favor. Well, news flash, McEliece has been worked on by giants in the field for 45 year…

How long do you think people have been working on lattice cryptography?

Re: NSA and IETF, part 3: Dodging the issues at hand

#244

Earlier quoted context omitted.

Very very incorrect. EDIT: Adding more to my post here because it would be hypocritical for you to complain: 1. I feel like given how I can make accurate predictions about Henry’s sphere of influence, that might gain me a little credibility: https://news.ycombinator.com/item?id=45495180 2. The reason I insulted you is because I know for a fact that when the mob came and demanded you shun and persecute someone, you ca…

de Valence accuses Bernstein of specific academic misconduct and you come back with this Encyclopedia Dramatica stuff? Why bother commenting at all? I don't think "I insulted you because" is ever a good way to start an HN comment, for what it's worth, but thanks for laying your cards on the table.

Because Bernstein addresses this:

>>> There is a committee at TU/e charged by law with ensuring proper grading, and I have recently learned that claims by Mr. de Valence related to this topic have been formally investigated and rejected by that committee. Now that Mr. de Valence has issued public accusations, it would seem that a public resolution will be necessary, starting with Mr. de Valence making clear what exactly his accusations are.

He also points out that de Valence is himself likely guilty of academic misconduct based on his own admissions.

We have two people making contradictory statements. The only ways to resolve it are facts (which were presumably reviewed by the committee) and credibility. You clearly think de Valence is more credible because he’s one of your feline friends, and because your other feline friends accused Appelbaum of sexual crimes, and you hate that Bernstein worked with Appelbaum because in your mind a sexual abuse accusation is as good as guilt of sexual abuse.

de Valence chose the same credibility-destroying path as Lovecruft, Honeywell, et al. did: make serious accusations in the public sphere instead of letting our public institutions charged with addressing these type of accusations do their job. Wise people realize that you can’t be criminally charged for publishing a smear campaign online, but you can be criminally charged for filing a police report, and evaluate accordingly.

Re: NSA and IETF, part 3: Dodging the issues at hand

#245

Earlier quoted context omitted.

I’m not sure why you’re hung up on SNTRUP, since DJB didn’t submit it past round 2 of NISTPQC. In round 3, DJB put his full weight behind Classic McEliece. You’ve previously argued that “cryptosystems based on ring-LWE hardness have been worked on by giants in the field since the mid-1990s” and suggested this is a point in Kyber’s favor. Well, news flash, McEliece has been worked on by giants in the field for 45 year…

How long do you think people have been working on lattice cryptography?

Lattices themselves have been analyzed since the days of Gauss. Lattice cryptography is only a couple decades old (in the unclassified literature).

The first proposed lattice-based cryptosystem was completely broken within 2 years of its announcement, which is an lovely harbinger of Kyber’s fate.

Re: NSA and IETF, part 3: Dodging the issues at hand

#246

Earlier quoted context omitted.

de Valence accuses Bernstein of specific academic misconduct and you come back with this Encyclopedia Dramatica stuff? Why bother commenting at all? I don't think "I insulted you because" is ever a good way to start an HN comment, for what it's worth, but thanks for laying your cards on the table.

Because Bernstein addresses this: >>> There is a committee at TU/e charged by law with ensuring proper grading, and I have recently learned that claims by Mr. de Valence related to this topic have been formally investigated and rejected by that committee. Now that Mr. de Valence has issued public accusations, it would seem that a public resolution will be necessary, starting with Mr. de Valence making clear what exac…

The same credibility-destroying path of questioning the conduct of your hero, I do get what you're saying, we don't have to belabor this. If you had a real argument you'd have presented it by now.

Re: NSA and IETF, part 3: Dodging the issues at hand

#247

Earlier quoted context omitted.

How long do you think people have been working on lattice cryptography?

Lattices themselves have been analyzed since the days of Gauss. Lattice cryptography is only a couple decades old (in the unclassified literature). The first proposed lattice-based cryptosystem was completely broken within 2 years of its announcement, which is an lovely harbinger of Kyber’s fate.

That's a funny claim given NTRU goes back to 1996 and was a PQC finalist. I barely know what I'm talking about here and even I think you're bluffing your way through this. At this point you're making arguments Bernstein would presumably himself reject!

Re: NSA and IETF, part 3: Dodging the issues at hand

#248

Earlier quoted context omitted.

Lattices themselves have been analyzed since the days of Gauss. Lattice cryptography is only a couple decades old (in the unclassified literature). The first proposed lattice-based cryptosystem was completely broken within 2 years of its announcement, which is an lovely harbinger of Kyber’s fate.

That's a funny claim given NTRU goes back to 1996 and was a PQC finalist. I barely know what I'm talking about here and even I think you're bluffing your way through this. At this point you're making arguments Bernstein would presumably himself reject!

Since you've been very strident throughout this thread I'm wondering if you're going to have a response to this. Similarly, I'm curious, as a scholar of Bernstein's cryptography writing --- did the MOV attack (prominently featured on Safecurves) serve as a lovely harbinger of the failure of elliptic curve cryptography?

Re: NSA and IETF, part 3: Dodging the issues at hand

#249

Dear some seasoned cryptographer, Please ELI5: what is the argument for including the option for the non-hybrid option in this standard? Is it a good argument in your expert opinion? My pea brain: implementers plus options equals bad, newfangled minus entrenched equals bad, alice only trust option 1 but bob only have option 2 = my pea brain hurt!

The strongest arugument made is that hybrid is more complex, more work and therefore more risky.

As someone who has been implementing such systems for 20 years, I don't buy this. In my mind, it's equivalent to saying "Seatbelts add complexity to the safety system, and it's more work. So let's get rid of it."

In this argument, the benefits of hybrid/seatbelts are not factored in adequately.

Post reply on HN