I suspect that NIST is just another government organization trying to do their jobs, and I don't think it's fair that their name got dragged through the mud. The truth is that the NSA practically co-opted NIST's decision-making strategy. I have confidence in NIST. Sadly, I don't have confidence in the NSA to not muddy up the process.
I'm not sure you can separate those. If NIST is being systematically interfered with by the NSA, how can you have confidence in them?
Government Announces Steps to Restore Confidence on Encryption Standards
31–40 of 132 posts
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#32Re: Government Announces Steps to Restore Confidence on Encryption Standards
#33“I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday.
Thats pretty strong sentiment. Seems to echo the bitterness of Rogaway: http://www.cs.ucdavis.edu/~rogaway/politics/surveillance.pdf
This is an important question of our times, and the cryptography experts should speak up like this. They have the credibility, and the ear of the people and media.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#34This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…
I guess we could get the same effect by encrypting using 3DES, then AES, then blowfish, twofish and then RC4.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#35How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this.
Such a situation is fine for "us", and great for government, in that it means they them selves can communicate with confidence. But to expect government to accept a situation where there is zero way they can snoop or investigate is asking a lot. Its a huge risk to government. So, I think we have to forget that idea completely, as attractive as it is to the likes of me.
As others have said, its procedural or legal, not technical. What is needed is a rock solid frame work and set of rules that properly limit how the snooping is done. What is needed is a universal bill of online or electronic rights. Not just for the USA, but something that can apply to any country and government. I'd suggest it should be developed by an international group, UN backed, and made part of being a member. Or could it be something that has to be agreed to as part of acquiring IP addresses or domain names. Dunno, but tie it in some how.
Ok, I'm not sure that works totally as I have set it out, Im no lawyer, and others may well want to modify it, but we need something international as the internet is international. We all need protection, not just Americans. We need a base level to work from. Something we can all accept as reasonable, workable and enforceable. Most of all, we need confidence in using communications and those regulating it.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#36The weird bit is the NYT did it on their own website instead of Ars. It's also super classy of Ars to cite a second report by the NYT then link to their own summary of that article too! http://bits.blogs.nytimes.com/2013/09/10/government-announce...
Mike Masnick calls it a complete non-response from NIST, regarding the real issue/accusation: http://www.techdirt.com/articles/20130910/12371124473/nists-...
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#37Committees rulings are a lie. (http://www.textbookleague.org/103feyn.htm)
Even the most seemingly reasonable regulations are a lie. (http://www.amazon.com/The-Truth-About-Drug-Companies/dp/0375...)
The sooner people realize there's no other option other than a direct democracy since governments and companies are untrustworthy, the better.
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#38This got my heart beating. There is actual rebellion among academics, and a movement to restore trust in both people and tech. This is the NY Times quoting Matt Green of John Hopkins in the article: “I know from firsthand communications that a number of people at N.I.S.T. feel betrayed by their colleagues at the N.S.A.,” Mr. Green said in an interview Tuesday. Thats pretty strong sentiment. Seems to echo the bitterne…
I guess a route that US agencies took is to "we will recommend good standards for you, because you know we also need security, but you shouldnt know all those standards and implementations will be compromised so we still retain the ability to spy on you while you wont be able to spy on us and if you do then you're a traitor".
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#39This is a procedural, not technical problem. It almost seems like the standardisation process open to everyone just enables everyone to insert their own backdoors into the standard. One interesting way to solve the problem would be to allow differenct mutually hostile entities to define their own standards (US, Russia, China, FSF, Pirate Bay, whoever) and then encrypt using all of them. That way, even if there is bac…
Re: Government Announces Steps to Restore Confidence on Encryption Standards
#40Before reading this, bear in mind, you wont find many more critical of government than me....That said I have to ask the following: How can any government accept a situation where communications are so secure that none of their agencies can break it? Essentially law enforcement do need to investigate crime. That has to be right and good for all. Even this anarchist accepts this. Such a situation is fine for "us", and…