Live data from Hacker News

NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

nist.gov

51–60 of 60 posts

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#51
post #32

Earlier quoted context omitted.

This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN. The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will…

BULLRUN was done to NIST, not by them. It’s think it’s also an example of why NIST is so important. The subversion of the standard is a problem, but the real exploit using that subversion was the laziness and lack of skill that downstream practitioners demonstrated. People clicked next and installed that RSA BSAFE package without any configuration or reading of the manual. Without NIST, you’d have Crypto AG — much wo…

As far as I know, NIST endorsed a weak random number generator, and they withdrew it after the flaws were found.

https://threatpost.com/nist-drops-weak-dual_ec-rng-from-offi...

It appears that BULLRUN was the name of the effort/program, not the faulty algorithm itself.

https://en.m.wikipedia.org/wiki/Dual_EC_DRBG

https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#52
post #51

Earlier quoted context omitted.

BULLRUN was done to NIST, not by them. It’s think it’s also an example of why NIST is so important. The subversion of the standard is a problem, but the real exploit using that subversion was the laziness and lack of skill that downstream practitioners demonstrated. People clicked next and installed that RSA BSAFE package without any configuration or reading of the manual. Without NIST, you’d have Crypto AG — much wo…

As far as I know, NIST endorsed a weak random number generator, and they withdrew it after the flaws were found. https://threatpost.com/nist-drops-weak-dual_ec-rng-from-offi... It appears that BULLRUN was the name of the effort/program, not the faulty algorithm itself. https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

That first sentence is not a good way to sum up what happened. Dual EC isn't "weak"; it's pretty plainly a backdoor.

(I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, it was immediately clear what was going on).

The idea of Dual EC is essentially that your output is internal RNG state encrypted with a public key, leaving open the obvious question of "who has the private key?". I think we all know the answer to that now.

i am being ironic

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#54
Shameless plug: I wrote about all these schemes in Chapter 14 on post-quantum cryptography of Real-World Cryptography https://www.manning.com/books/real-world-cryptography?a_aid=...

These are meant as a gentle introduction to the ideas and intuitions behind the schemes. The book is recent but some of that stuff (hash-based signatures) I started writing back in 2015 and is available on my blog: https://cryptologie.net/article/306/one-time-signatures/

At the time the schemes had not yet been chosen, fortunately I picked the right ones :) don't have to rewrite that chapter (yet).

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#55
post #52
post #51

Earlier quoted context omitted.

As far as I know, NIST endorsed a weak random number generator, and they withdrew it after the flaws were found. https://threatpost.com/nist-drops-weak-dual_ec-rng-from-offi... It appears that BULLRUN was the name of the effort/program, not the faulty algorithm itself. https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

That first sentence is not a good way to sum up what happened. Dual EC isn't "weak"; it's pretty plainly a backdoor. (I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, i…

While I largely agree with you, and respect your opinion on these matters, the truth is that Dual EC was indeed a standard of the NIST, and therefore as a practical matter did get deployed by the public in whatever ill-informed manner for not having your elite cadre advice (yes, joking).

I appreciate the point about trust in the authorship of those presenting these algorithms, and I personally do accept it, but there's a lack of trust broadly (in the very community that these standards are intended for) in the process that your comments don't account for in this instance.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#56
post #45

Earlier quoted context omitted.

> You aren't being asked to trust NIST in any meaningful way I understand that neither NIST nor NSA have designed these schemes, but isn't NIST the organization who picked these winning schemes after all? That's the impression I got, and my history of trusting what NIST picks, isn't the greatest, so I'd like to avoid that. I also understand that countless of people have reviewed the schemes as well, people from all a…

About the worst thing you could say about the NIST competitions is that if NSA knows some horrible flaw in CRYSTAL-KYBER, they're not going to tell us about it. But that's true of any other contest anybody else runs, too.

Why would that be true in any alternate versions of these contests? I understand the enormous incentive mechanisms involved, and yet I cannot see this being obviously true.

Edit to add: if the authorship of the submitters is as above reproach as we are led to assume, why can that not be the case for the NIST decision panel itself?

Edit 2: answered already elsewhere: https://news.ycombinator.com/item?id=31993896

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#57
post #52
post #51

Earlier quoted context omitted.

As far as I know, NIST endorsed a weak random number generator, and they withdrew it after the flaws were found. https://threatpost.com/nist-drops-weak-dual_ec-rng-from-offi... It appears that BULLRUN was the name of the effort/program, not the faulty algorithm itself. https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)

That first sentence is not a good way to sum up what happened. Dual EC isn't "weak"; it's pretty plainly a backdoor. (I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, i…

> it's pretty plainly a backdoor.

Nitpick: strictly speaking, it wasn't plainly a backdoor specifically, but plainly either a backdoor, or something deliberately designed to look backdoored, but with some unknown way for the NSA to 'reluctantly' declassify a proof that it wasn't backdoored in a attempt to discredit people who accused it of being backdoored (basically trying to recreate the DES S-box versus differential cryptanalysis thing). But smart money was on actually-a-backdoor.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#58

Earlier quoted context omitted.

Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? And didn’t they subsequently ban the NSA from their input once the Snowden leaks were out? So I don’t think it’s fair to disregard NIST completely. And the international counterparts can compare & perform their own due diligence

> Wasn’t it that NIST was unwittingly tricked into accepting the NSA’s expertise while the NSA maliciously provided that expertise in bad faith? Not sure if that's better or worse than them collaborating directly. Edit: from a paper linked in another comment: > Researchers raised concerns to NIST about both possible bias in the bits and a possible backdoor in Dual_EC_DRBG. NIST examined the issue. NSA dismissed NIST'…

> Not sure if that's better or worse than them collaborating directly.

Well, one is an issue of competency or at the very least experience. The other is an issue of ethics. I'll take a competency concerns over ethical ones any day.

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#59

Is there any alternative organizations like NIST but not-NIST? That NIST worked together with NSA to allow/insert backdoors into cryptography kind of left a sour taste in my mouth, and it's hard to trust them again after that.

> Is there any alternative organizations like NIST but not-NIST?

DJB

OpenSSH basically decided to ignore the NIST competition and implemented Streamlined NTRU Prime. https://www.openssh.com/txt/release-9.0

Re: NIST Announces First Four Quantum-Resistant Cryptographic Algorithms

#60

Does 'quantum-resistant' also imply 'P=NP' resistant?

You're thinking of P=BQP (which still falls into the seems-to-not-be-true-but-we-can't-prove-it category, but physics runs BQP already, so we don't need P=BQP for BQP attacks like Shor and Grover to be issue).
Post reply on HN