Live data from Hacker News

NSA and IETF, part 3: Dodging the issues at hand

blog.cr.yp.to

41–50 of 249 posts

Re: NSA and IETF, part 3: Dodging the issues at hand

#43
post #29

[flagged]

> This is why djb is in the Cypherpunks Hall of Fame! [1] This is a list made by you 2 weeks ago? EDIT: Okay lol. I actually browsed the list and found multiple dubious entries, along with Trump! Hilarious list. 10/10.

what do you expect, when the tagline at the end of the page says "In crypto we trust."?

Honestly, it's a bit sad. There are many great people on that list, but some seem a bit random and some are just straight up cryptobros, which makes the whole thing a joke, unfortunately

Re: NSA and IETF, part 3: Dodging the issues at hand

#44
post #14

20+2 (conditional support) versus 7. 22/29 = 76% in some form of "yea" That feels like "rough consensus"

The standard used in the C and C++ committees is essentially a 2-to-1 majority in favor. I'm not aware of any committee where a 3-to-1 majority is insufficient to get an item to pass. DJB's argument that this isn't good enough would, by itself, be enough for me to route his objections to /dev/null; it's so tedious and snipey that it sours the quality of his other arguments by mere association. And overall, it gives t…

We're talking about a landmine in a crypto spec and you're bikeshedding about consensus ratios.

We should talk about the NSA designed landmine.

Re: NSA and IETF, part 3: Dodging the issues at hand

#45
post #24

In context, this particular issue is that DJB disagrees with the IETF publishing an ML-KEM only standard for key exchange. Here's the thing. The existence of a standard does not mean we need to use it for most of the internet. There will also be hybrid standards, and most of the rest of us can simply ignore the existence of ML-KEM -only. However, NSA's CNSA 2.0 (commercial cryptography you can sell to the US Federal…

The standard will be used, as it was the previous time the IETF allowed the NSA to standardize a known weak algorithm.

Sorry that someone calling out a math error makes the NIST team feel stupid. Instead of dogpiling the person for not stroking their ego, maybe they should correct the error. Last I checked, a quantum computer wasn't needed to handle exponents, a whiteboard will do.

Re: NSA and IETF, part 3: Dodging the issues at hand

#46

Earlier quoted context omitted.

Why, if I might respectfully ask?

Sure! First, while I’m in no position to judge cryptographic algorithms, the success of cha-cha and 25519 speak for themselves. More prosaically, patriecia/critbit trees and his other tools are the right thing, and foresighted. He’s not just smart, but also prolific. However, he’s left a wake of combative controversy his entire career, of the “crackpot” type the parent comment notes, and at some point it’d be worth h…

I do not understand your last paragraph. :/

Re: NSA and IETF, part 3: Dodging the issues at hand

#49
post #14

20+2 (conditional support) versus 7. 22/29 = 76% in some form of "yea" That feels like "rough consensus"

The standard used in the C and C++ committees is essentially a 2-to-1 majority in favor. I'm not aware of any committee where a 3-to-1 majority is insufficient to get an item to pass. DJB's argument that this isn't good enough would, by itself, be enough for me to route his objections to /dev/null; it's so tedious and snipey that it sours the quality of his other arguments by mere association. And overall, it gives t…

You are turning “consensus” into “majority” and those it not the same.
Post reply on HN