Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

41–50 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#41
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

As I read it, the point of mentioning Dual EC is to show a previous case where NSA have acted in a way that reduces security for hand-wavy reasons, in addition to the DES case where they did the same.

And now, in a world where QR + pre-QR algos are typically being introduced in a layered fashion, they're saying "let's add another option, to reduce the number of options" which at least looks very suspicious

Practical quantum computers are probably not very close, but you can certainly use the fear of them as a chance to introduce a new back-door. If you did, you'd have to behave exactly as the NSA is doing right now.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#42
post #39

Earlier quoted context omitted.

They're adhering to their charter. If you show up to my manager demanding to know why I made a specific engineering decision, he's not going to tell you - that's not the process, that's not his job, he's going to trust me to make good decisions unless presented with evidence I've misbehaved. But as has been pointed out elsewhere, the distinction between the Dual EC DRBG objections and here are massive. The former had…

> unless presented with evidence The complaint seems well referenced with evidence of poor engineering decisions to me. > Dual EC DRBG ... had an obvious technical weakness that provided a clear mechanism for a back door Removing an entire layer of well tested encryption qualifies as an obvious technical weakness to me. And as I've mentioned elsewhere in these comments, opens users up to a https://en.wikipedia.org/wi…

Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for PQC? This isn't actually an engineering hill I'd die on, if more people I trust made clear arguments for why this is dangerous I'd take it very seriously, but right now we basically have djb against the entire world writing a blogpost that makes ludicrous insinuations and fails to actually engage with any of the counterarguments, and look just no.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#43
post #42

Earlier quoted context omitted.

> unless presented with evidence The complaint seems well referenced with evidence of poor engineering decisions to me. > Dual EC DRBG ... had an obvious technical weakness that provided a clear mechanism for a back door Removing an entire layer of well tested encryption qualifies as an obvious technical weakness to me. And as I've mentioned elsewhere in these comments, opens users up to a https://en.wikipedia.org/wi…

Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…

> Why don't we hybridise all crypto?

So you've constructed a strawman. Another indication of ceding the argument.

> and the answer we have from a whole bunch of people who are qualified

The ultimate job of a manager or a board is to take responsibility for the decisions of the organization. All of your comments in this thread center around abdicating that responsibility to others.

> This isn't actually an engineering hill I'd die on

Could have fooled me.

> we basically have djb against the entire world

Many of your comments indicate to me that clashing personalities may be interfering with making the right engineering decision.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#44
post #42

Earlier quoted context omitted.

Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…

> Why don't we hybridise all crypto? So you've constructed a strawman. Another indication of ceding the argument. > and the answer we have from a whole bunch of people who are qualified The ultimate job of a manager or a board is to take responsibility for the decisions of the organization. All of your comments in this thread center around abdicating that responsibility to others. > This isn't actually an engineering…

If the argument is "Why adopt a protocol that may rely on a weak algorithm without any additional protection" then I think it's up to you to demonstrate why that argument doesn't apply to any other scenario as well.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#45
post #44

Earlier quoted context omitted.

> Why don't we hybridise all crypto? So you've constructed a strawman. Another indication of ceding the argument. > and the answer we have from a whole bunch of people who are qualified The ultimate job of a manager or a board is to take responsibility for the decisions of the organization. All of your comments in this thread center around abdicating that responsibility to others. > This isn't actually an engineering…

If the argument is "Why adopt a protocol that may rely on a weak algorithm without any additional protection" then I think it's up to you to demonstrate why that argument doesn't apply to any other scenario as well.

Again with the strawmen.

"Why adopt a protocol that may rely on a weak algorithm without any additional protection"

Does not accurately represent the situation at hand. And that seems intentional.

"Why weaken an existing protocol in ways we know may be exploitable?" is a more accurate representation. And I believe the burden of evidence lies on those arguing to do so.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#46
post #42

Earlier quoted context omitted.

> unless presented with evidence The complaint seems well referenced with evidence of poor engineering decisions to me. > Dual EC DRBG ... had an obvious technical weakness that provided a clear mechanism for a back door Removing an entire layer of well tested encryption qualifies as an obvious technical weakness to me. And as I've mentioned elsewhere in these comments, opens users up to a https://en.wikipedia.org/wi…

Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…

FWIW, https://blog.cr.yp.to/20240102-hybrid.html reads to me like a more direct attempt to engage with the counterarguments.

I am curious what the costs are seen to be here. djb seems to make a decent argument that the code complexity and resource usage costs are less of an issue here, because PQ algorithms are already much more expensive/hard to implement then elliptic curve crypto. (So instead of the question being "why don't we triple our costs to implement three algorithms based on pretty much the same ideas", it's "why don't we take a 10% efficiency hit to supplement the new shiny algorithm with an established well-understood one".)

On the other hand, it seems pretty bad if personal or career cost was a factor here. The US government is, for better or worse, a pretty major stakeholder in a lot of companies. Like realistically most of the people qualified to opine on this have a fed in their reporting chain and/or are working at a company that cares about getting federal contracts. For whatever reason the US government is strongly anti-hybrid, so the cost of going against the grain on this might not feel worth it to them.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#47
post #44

Earlier quoted context omitted.

If the argument is "Why adopt a protocol that may rely on a weak algorithm without any additional protection" then I think it's up to you to demonstrate why that argument doesn't apply to any other scenario as well.

Again with the strawmen. "Why adopt a protocol that may rely on a weak algorithm without any additional protection" Does not accurately represent the situation at hand. And that seems intentional. "Why weaken an existing protocol in ways we know may be exploitable?" is a more accurate representation. And I believe the burden of evidence lies on those arguing to do so.

Kyber is not known to be weaker than any other well used algorithm.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#48
post #47

Earlier quoted context omitted.

Again with the strawmen. "Why adopt a protocol that may rely on a weak algorithm without any additional protection" Does not accurately represent the situation at hand. And that seems intentional. "Why weaken an existing protocol in ways we know may be exploitable?" is a more accurate representation. And I believe the burden of evidence lies on those arguing to do so.

Kyber is not known to be weaker than any other well used algorithm.

Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful.

It really seems like you're trying not to hear what's been said.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#49
post #42

Earlier quoted context omitted.

> unless presented with evidence The complaint seems well referenced with evidence of poor engineering decisions to me. > Dual EC DRBG ... had an obvious technical weakness that provided a clear mechanism for a back door Removing an entire layer of well tested encryption qualifies as an obvious technical weakness to me. And as I've mentioned elsewhere in these comments, opens users up to a https://en.wikipedia.org/wi…

Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…

>So why is it fundamentally and obviously true for PQC? This isn't actually an engineering hill I'd die on, if more people I trust made clear arguments for why this is dangerous I'd take it very seriously, but right now we basically have djb against the entire world writing a blogpost that makes ludicrous insinuations and fails to actually engage with any of the counterarguments, and look just no.

As a response to this only, while djb's recent blog posts have adopted a slightly crackpotish writing style, PQC hybridization is not a fringe idea, and is not deployed because of djb's rants.

Over in Europe, German BSI and French ANSSI both strongly recommend hybrid schemes. As noted in the blog, previous Google and Cloudflare experiments have deployed hybrids. This was at an earlier stage in the process, but the long history of lattices that is sometimes being used as a (reasonable) argument against hybrids applied equally when those experiments were deployed, so here I'm arguing that the choice made at the time is still reasonably today, since the history hasn't changed.

Yes, there is also a more general "lots of PQC fell quite dramatically" sentiment at play that doesn't attempt to separate SIKE and MLKEM. That part I'm happy to see criticized, but I think the broader point stands. Hybrids are a reasonable position, actually. It's fine.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#50
post #7

The mere idea that that they want to do this makes me want a 3rd layer of encryption on top of the other 2.

Encryption layers are actually pretty cheap for the vast majority of ciphers and applications.

Seems dumb not to have like 10.

Post reply on HN