Live data from Hacker News

Breaking rainbow takes a weekend on a laptop

eprint.iacr.org

51–60 of 66 posts

Re: Breaking rainbow takes a weekend on a laptop

#51
post #48

Earlier quoted context omitted.

I respectfully disagree. It certainly isn’t intended as an insult! One looks like astroturfing performed without a valid basis against cited examples shared in good faith, the other appears to be a mistake in analysis which I am pointing out in good faith. It’s probably an honest mistake, the history here is intentionally obscured by large-scale adversaries. I do believe that the second is just a mistake and I do not…

You don't have to agree but you can't call people NSA shills and you can't tell people they don't know what they're talking about. That's just how this forum works - don't put that kind of thing in your comments. It's not a high or difficult bar to meet.

I did not intend, nor do I think I called the parent an NSA shill. If it comes across as that, I apologize.

The parent clearly says that it is hard to get a bead on what he is arguing. I tried to explain what people may hear or see and I do believe that some people might not be able to see the latter but only the former, fair or not, but I only endorsed the latter.

I guess I should make clear that I think the parent is simply mistaken and that I don’t think he is a shill. It’s not intended as an insult to say there is a mistake of analysis, as I said the topic is very difficult and also often very contentious.

Re: Breaking rainbow takes a weekend on a laptop

#52
post #33

Earlier quoted context omitted.

The NSA hoped noone would notice.

They authors acknowledged on the list that they didn’t think of the attack, and have appropriately scaled the parameters. Cryptography is hard - there have been numerous NTRU optimizations that withstood years of analysis before someone worked how to break them. Not everything is an NSA conspiracy. The dual-EC bullshit was even confusing to other cryptographers at the time, but at that time good faith was still being…

At the time some cryptographers said it looked like a backdoor and they were largely dismissed by the public until Snowden related evidence came to light. Further reporting exposed the $10m bribe to RSA. To wax poetic: It was not a note in isolation but a note in a much larger song.

It is important to remember that NSA is continuing to do this kind of thing and they try from every angle. It is literally their job. Consider that the Dragonfly issues at the IETF are after Dual EC.

There are backdoored systems which are deployed and have not yet been revealed.

We must be on the lookout for them, and we must consider that NSA supposedly employs the most mathematicians in the world.

Ward’s work is amazing. Wouldn’t it be amazing if NSA actually tried to help? Do we suppose NSA didn’t also have a break on it? If not, we should really hope Ward keeps working in public. If NSA actually wanted to help and did help by breaking the remaining systems, it might win some points in public and especially if they advance the state of the art in cryptanalysis.

Re: Breaking rainbow takes a weekend on a laptop

#53
post #49

Earlier quoted context omitted.

> very aware of how NSA backdoors work and you’re misleading people Hard to coerce that into a "good faith". Accusations of astroturfing are not allowed here.

I’m saying this in response to the parents claim of it being hard to get a bead on what he is arguing. I’m answering that as two possible ways to read it and I emphasize the latter. I did not accuse, I tried to explain what I think people take from his argumentation.

Your words were “misleading people”.

Just stop.

Re: Breaking rainbow takes a weekend on a laptop

#54
post #36

Earlier quoted context omitted.

It's tricky to get a bead on what it is people think I'm arguing here. My argument is simple and narrow: if it's an attack discovered independently that can break a cryptosystem with realistic parameters over a weekend on a laptop, it's not an NSA backdoor. NSA backdoors are trivially exploitable by NSA, but not trivially exploitable by anyone with the relevant mathematics background.

On what basis do you make that claim? It appears that you’re saying that PX-1000cr isn’t an example NSA backdoor or that the article breaking the cipher in the PX1000cr is incorrect? It seems like you’re either very aware of how NSA backdoors work and you’re misleading people for some reason or you don’t know what you’re talking about, you’re being hopeful and you are ignoring the evidence that NSA inserts backdoors…

I'm having trouble even following what you're saying here. A cryptographically-relevant quantum computer breaks all conventional elliptic curve cryptography, not just NSA's backdoor. Everything we're talking about is irrelevant if NSA can break curves with quantum computers.

Re: Breaking rainbow takes a weekend on a laptop

#55
post #35

Earlier quoted context omitted.

I don't think you're following the actual dispute on this subthread.

I followed it and was trying to point out that your question was imprecise.

Respectfully, I think you're a little lost here.

Re: Breaking rainbow takes a weekend on a laptop

#56
post #54

Earlier quoted context omitted.

On what basis do you make that claim? It appears that you’re saying that PX-1000cr isn’t an example NSA backdoor or that the article breaking the cipher in the PX1000cr is incorrect? It seems like you’re either very aware of how NSA backdoors work and you’re misleading people for some reason or you don’t know what you’re talking about, you’re being hopeful and you are ignoring the evidence that NSA inserts backdoors…

I'm having trouble even following what you're saying here. A cryptographically-relevant quantum computer breaks all conventional elliptic curve cryptography, not just NSA's backdoor. Everything we're talking about is irrelevant if NSA can break curves with quantum computers.

The point is that if the RNG didn’t artificially add elliptic curves in the form of a back door, even a CRQC wouldn’t be able to break the RNG. Grover can be assumed to reduce the security by roughly ~N/2. A design with a sufficiently large N isn’t going to fall to a CRQC generally. The design of Dual EC which includes a backdoor is strictly worse than a design without a low hanging Q to attack.

NSA expects and is pushing the idea that there will be a CRQC. NSA does not say they will be the only people with a CRQC, and so their hold on a monopoly to exploit Dual EC isn’t forever and will someday be in the domain of a person with a laptop (and access to a CRQC).

Re: Breaking rainbow takes a weekend on a laptop

#57
post #54

Earlier quoted context omitted.

I'm having trouble even following what you're saying here. A cryptographically-relevant quantum computer breaks all conventional elliptic curve cryptography, not just NSA's backdoor. Everything we're talking about is irrelevant if NSA can break curves with quantum computers.

The point is that if the RNG didn’t artificially add elliptic curves in the form of a back door, even a CRQC wouldn’t be able to break the RNG. Grover can be assumed to reduce the security by roughly ~N/2. A design with a sufficiently large N isn’t going to fall to a CRQC generally. The design of Dual EC which includes a backdoor is strictly worse than a design without a low hanging Q to attack. NSA expects and is pu…

I think your entire argument boils down to "there's no such thing as a NOBUS backdoor because practical quantum computing breaks Dual EC". OK. Super interesting point.

Re: Breaking rainbow takes a weekend on a laptop

#58
post #53

Earlier quoted context omitted.

I’m saying this in response to the parents claim of it being hard to get a bead on what he is arguing. I’m answering that as two possible ways to read it and I emphasize the latter. I did not accuse, I tried to explain what I think people take from his argumentation.

Your words were “misleading people”. Just stop.

My words included two options, one of which includes those words — and I disowned the first option. Please read it again and then read his comment again. Selective quoting won’t change that I was providing a reflection of two possible reads of his comments, and I endorsed the latter in good faith. If you think my first option is unreasonable as a characterization to write down, I’m not sure how I can more clearly express that this is a reading that someone can fairly arrive at - I just think it’s wrong. I provided these two options because he could rephrase his comments to avoid the first one entirely to sharpen his argument. If the parent hadn’t expressed that it was “hard to get a bead” I wouldn’t have provided the first option as feedback to try to express the possible “beads” in question.

If you don’t think there are people who are actively misleading people on this topic or that a comment can’t be read that way, I think we should agree to disagree. People will read a lot of things in this area in bad faith and they are also often wrong because there is intentional obfuscation by large-scale adversaries.

Re: Breaking rainbow takes a weekend on a laptop

#59
post #33

Earlier quoted context omitted.

They authors acknowledged on the list that they didn’t think of the attack, and have appropriately scaled the parameters. Cryptography is hard - there have been numerous NTRU optimizations that withstood years of analysis before someone worked how to break them. Not everything is an NSA conspiracy. The dual-EC bullshit was even confusing to other cryptographers at the time, but at that time good faith was still being…

At the time some cryptographers said it looked like a backdoor and they were largely dismissed by the public until Snowden related evidence came to light. Further reporting exposed the $10m bribe to RSA. To wax poetic: It was not a note in isolation but a note in a much larger song. It is important to remember that NSA is continuing to do this kind of thing and they try from every angle. It is literally their job. Co…

They were largely dismissed by "the public" --- and dismissive themselves --- because nobody believed anybody would actually use an expensive, janky PKRNG when far simpler, more performant CSPRNGs were already universally available in operating systems and standard C libraries. The revelation in the BULLRUN leaks wasn't that Dual EC was suspicious --- it had always been suspicious --- but rather that companies were actually using it, because NSA suborned RSA Security into making BSAFE use it.

(Prior to BULLRUN, I'd have been equally dismissive of the idea that people were still using BSAFE, either, but, no, as it turns out, the industry is a whole lot dumber than any of us expected it is).

NSA does actually try to help; it's ostensibly half of their mission (nobody seriously believes the IAD mission gets anything close to 50% of the resources).

Re: Breaking rainbow takes a weekend on a laptop

#60
post #53

Earlier quoted context omitted.

Your words were “misleading people”. Just stop.

My words included two options, one of which includes those words — and I disowned the first option. Please read it again and then read his comment again. Selective quoting won’t change that I was providing a reflection of two possible reads of his comments, and I endorsed the latter in good faith. If you think my first option is unreasonable as a characterization to write down, I’m not sure how I can more clearly exp…

Look, dude, I don't care about this NSA shill stuff, and you're not doing your arguments any favors trying to super-duper-duper explain what you really meant by dropping innuendo into the thread. Just stop talking about it and move on. Now you know that HN is super picky about "shillage" arguments. We can be done talking about it.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Post reply on HN