Earlier quoted context omitted.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
> The thing you should look at is the process, not the organization. Then there shouldn't be a problem with another organization hosting the contest than NIST? Since I'm probably not alone in not being able to trust them anymore.
NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
31–40 of 60 posts
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#32Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will trust this contest for similar reasons. If you could get this cast of cryptographers not to submit to NIST contests, and instead submit to some other contest, we'd have something productive to talk about. But you can't, and so, when we talk about contest-based cryptography standards, you're going to end up back at NIST.
I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.
Meanwhile: pull up the authorship team on CRYSTALS-KYBER. Approximately 0% of credible cryptographers believe that NIST was somehow able to exert improper influence over this design.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#33Earlier quoted context omitted.
Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out? So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence
> Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? Not sure if that's better or worse than them collaborating directly. Edit: from a paper linked in another comment: > Researchers raised concerns to NIST about both possible bias in the bits and a possible backdoor in Dual_EC_DRBG. NIST examined the issue. NSA dismissed NIST'…
I think you would be correct and do you know that ends?
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#34Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
Russia didn't develop Kuznyechik for nothing
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#35Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…
Sorry if you think I'm trying to convince people of anything. I'm simply asking for alternatives to NIST itself, for my own personal and selfish reasons. I'm not arguing against other people trusting NIST, their competitions or anything like that. Just asking a question regarding alternatives.
I'm glad you and others answered. Someone even gave a proper alternative based in Germany, and for that I'm very happy. I'm sorry you feel like people are "relitigating the same points over and over again", I cannot steer the conversation any more than you can and I personally haven't seen any conversations on HN about alternatives to NIST, then obviously I wouldn't ask for it, if I already knew the answer.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#36Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.
This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#37Earlier quoted context omitted.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…
But if it can come up with a competitive algorithm with a subtle unnoticed flaw, than that attack would work almost as well in a contest hosted by some other organization. They wouldn't be able to guarantee the win, but they would still have a good shot at it.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#38Earlier quoted context omitted.
Who do you trust as an authority?
I don't know, but organizations which haven't duped people into using broken crypto before would be a good start.
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#39Earlier quoted context omitted.
This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…
> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again. Sorry if you think I'm trying to convince people of anything. I'm simply asking fo…
The closest analog to NIST I can think of is ECRYPT and the eSTREAM contest. It produced interesting work and you could follow it in much the same way people followed these last two NIST competitions. But for PQ KEMs, it's likely that NIST's will be the "competition of record".
Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
#40Earlier quoted context omitted.
There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…
> The thing you should look at is the process, not the organization. Then there shouldn't be a problem with another organization hosting the contest than NIST? Since I'm probably not alone in not being able to trust them anymore.
The reason it was enabled in some systems is 1. libraries (like openssl and ffmpeg) used to implement and ship every algorithm on Earth for pride reasons 2. NSA bribed RSA BSafe to make it the default.
You don't have a solution for #2.