Live data from Hacker News

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

nist.gov

31–40 of 60 posts

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#31
post #16

Earlier quoted context omitted.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

> The thing you should look at is the process, not the organization. Then there shouldn't be a problem with another organization hosting the contest than NIST? Since I'm probably not alone in not being able to trust them anymore.

There isn't a problem, except that nobody will take the other organization's contest especially seriously, or write its name into contracts.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#32

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN.

The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will trust this contest for similar reasons. If you could get this cast of cryptographers not to submit to NIST contests, and instead submit to some other contest, we'd have something productive to talk about. But you can't, and so, when we talk about contest-based cryptography standards, you're going to end up back at NIST.

I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.

Meanwhile: pull up the authorship team on CRYSTALS-KYBER. Approximately 0% of credible cryptographers believe that NIST was somehow able to exert improper influence over this design.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#33

Earlier quoted context omitted.

Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out? So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence

> Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? Not sure if that's better or worse than them collaborating directly. Edit: from a paper linked in another comment: > Researchers raised concerns to NIST about both possible bias in the bits and a possible backdoor in Dual_EC_DRBG. NIST examined the issue. NSA dismissed NIST'…

> It wouldn't surprise me that if NSA found something, they would withhold any findings if they could benefit from being the only ones knowing about any holes. Although we all know how that ends.

I think you would be correct and do you know that ends?

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#34

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

Well, you could always look for when the Russians or Chinese come out with their own and hope the NSA doesn't know those backdoors.

Russia didn't develop Kuznyechik for nothing

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#35
post #32

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.

Sorry if you think I'm trying to convince people of anything. I'm simply asking for alternatives to NIST itself, for my own personal and selfish reasons. I'm not arguing against other people trusting NIST, their competitions or anything like that. Just asking a question regarding alternatives.

I'm glad you and others answered. Someone even gave a proper alternative based in Germany, and for that I'm very happy. I'm sorry you feel like people are "relitigating the same points over and over again", I cannot steer the conversation any more than you can and I personally haven't seen any conversations on HN about alternatives to NIST, then obviously I wouldn't ask for it, if I already knew the answer.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#36
post #32

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

They didn't say anything about NIST competitions.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#37
post #17
post #16

Earlier quoted context omitted.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

I don't understand cryptography enough to vet algorithms. I need to trust an authority to tell me which algorithms to use. I do not trust NIST as an authority. That's why it would be nice to have an actually trustworthy authority which does similar work to NIST. EDIT: To more specifically address the process: If NIST wanted to get people to trust a shady algorithm, they could have some amazing cryptographers invent a…

NIST wouldn't get away with choosing an algorithm that has been shown to have vulnerabilities, which is the only thing it could do is come up with an algorithm with a subtle unnoticed flaw. And that algorithm has to have performance at least as good as the other algorithms in the contest.

But if it can come up with a competitive algorithm with a subtle unnoticed flaw, than that attack would work almost as well in a contest hosted by some other organization. They wouldn't be able to guarantee the win, but they would still have a good shot at it.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#38
post #21

Earlier quoted context omitted.

Who do you trust as an authority?

I don't know, but organizations which haven't duped people into using broken crypto before would be a good start.

Like if you dont like the US NIST standards there is the Japanese CRYPTREC, and European NESSIE. Alot the same algos as NIST though.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#39
post #32

Earlier quoted context omitted.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again. Sorry if you think I'm trying to convince people of anything. I'm simply asking fo…

You said "NIST worked together with NSA to allow/insert backdoors into cryptography". It's been pointed out a couple times now that neither NIST nor NSA designed these schemes; they were submitted by the highest-profile academic cryptography research teams in the world. You aren't being asked to trust NIST in any meaningful way.

The closest analog to NIST I can think of is ECRYPT and the eSTREAM contest. It produced interesting work and you could follow it in much the same way people followed these last two NIST competitions. But for PQ KEMs, it's likely that NIST's will be the "competition of record".

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#40
post #16

Earlier quoted context omitted.

There's no need for one. How NIST chose algorithms in the past was done in quite diverse ways. Sometimes they merely said "this is a standard" and people could comment and the comments were ignored. This is basically what happened with Dual EC DRBG, whcih is the likely example you're referring to. However the way this standardization worked - and several others before, like AES and SHA-3 - is that NIST made a public…

> The thing you should look at is the process, not the organization. Then there shouldn't be a problem with another organization hosting the contest than NIST? Since I'm probably not alone in not being able to trust them anymore.

Nobody trusted Dual_EC_DRBG despite its NIST accreditation. It was always obviously weird to experts, and it wasn't simple and performant enough for non-experts.

The reason it was enabled in some systems is 1. libraries (like openssl and ffmpeg) used to implement and ship every algorithm on Earth for pride reasons 2. NSA bribed RSA BSafe to make it the default.

You don't have a solution for #2.

Post reply on HN