Earlier quoted context omitted.
Claiming loyalty is a litmus test for layoffs is a bit incendiary and a needless introduction of a strongly biased view of politics into the conversation. No doubt for leadership levels an active disinterest in helping enable open inquiry into the state of things would be fireable, but calling this a loyalty test is a strong spin. One that’s been normalized lately to be sure, but there’s no need to further it. I’d be…
> I’d be more concerned with whether NIST colludes with the NSA to approve algorithms they could crack. It's more than a concern that the US government will select algorithms that their top spook agency can crack. One must assume it is the case.
NIST selects HQC as fifth algorithm for post-quantum encryption
51–60 of 126 posts
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#52Give how quickly quantum is potentially coming, I wonder if we should/could find some way of using multiple quantum-resistant algorithms simultaneously as a default, in case a fault is found after the limited time we have to verify that there are no faults. Also - should we not be switching over to these algorithms starting like... now? Am I wrong that anyone collecting https traffic now will be able to break it in t…
Signal has a post about using pre and post-quantum together: https://signal.org/blog/pqxdh/
> The essence of our protocol upgrade from X3DH to PQXDH is to compute a shared secret, data known only to the parties involved in a private communication session, using both the elliptic curve key agreement protocol X25519 and the post-quantum key encapsulation mechanism CRYSTALS-Kyber. We then combine these two shared secrets together so that any attacker must break both X25519 and CRYSTALS-Kyber to compute the same shared secret.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#53Earlier quoted context omitted.
That's a good question, the answer is no. That's the thing about politics... they touch everything. There's a popular youtuber that I like, he's got a funny saying "You might not fuck with politics, but politics will fuck with you!" Fits well here. You might wanna ignore politics when talking about something that should be pure math, but now that we're talking about why crypto is going to be the standards that all co…
> they touch everything. No. They don't. The level at which politics has actually intersected with my life in the past year is zero. I suspect the same is true for the majority of people in the US. Your politics are mostly a fashion choice. You don't need to put them on display in literally ever conversation. You also cannot possibly change the world around you with this behavior so I can't understand why so many peo…
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#54Earlier quoted context omitted.
That's a good question, the answer is no. That's the thing about politics... they touch everything. There's a popular youtuber that I like, he's got a funny saying "You might not fuck with politics, but politics will fuck with you!" Fits well here. You might wanna ignore politics when talking about something that should be pure math, but now that we're talking about why crypto is going to be the standards that all co…
> they touch everything. No. They don't. The level at which politics has actually intersected with my life in the past year is zero. I suspect the same is true for the majority of people in the US. Your politics are mostly a fashion choice. You don't need to put them on display in literally ever conversation. You also cannot possibly change the world around you with this behavior so I can't understand why so many peo…
Road maintenance, sewer connections, water and air quality, food safety, and a million other things that you interact with daily are all results of various levels of politics.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#55Earlier quoted context omitted.
Have people forgotten about this already? https://en.wikipedia.org/wiki/Dual_EC_DRBG It's not at all impossible to put a backdoor in a protocol which requires knowledge of a key in order to exploit. This isn't even the only example where this is thought to have occured.
I haven't forgotten about it, no, and I stand by my original comment. If you introduce a deliberate weakness to your encryption, the overall security is reduced to the security level of that weakness. Relying on NOBUS ("nobody but us") is hubris (see shadow brokers, snowden, etc.).
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#56Earlier quoted context omitted.
I haven't forgotten about it, no, and I stand by my original comment. If you introduce a deliberate weakness to your encryption, the overall security is reduced to the security level of that weakness. Relying on NOBUS ("nobody but us") is hubris (see shadow brokers, snowden, etc.).
This just doesn't make technical sense. I completely agree that backdooring encryption standards is a bad thing. But Dual EC DRBG is a clear example of a NOBUS backdoor actually being that. The backdoor is equivalent to "knowing" a private key. The weakness is not some sort of computational reduction. Using this logic, you would say that no encryption method is possibly secure because you can't rely on its security o…
There's no reason to think it would have remained a "NOBUS" backdoor forever. Especially if it was more widely used (i.e. higher value), and/or used for longer.
>Using this logic, you would say that no encryption method is possibly secure
I mean, to an extent that a little waterboarding will beat any encryption method, yes I would say that.
But, for 99.99% of people, your data isn't worth the waterboarding. On the flipside, a backdoor to, say, all TLS communication, would be very worth waterboarding people.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#57Meta: I can understand the math problems behind RSA and DH, and the general concepts of EC, but all stuff for post-quantum algorithms I have yet to have a intuitive understanding even after reading / watching a bunch of videos trying to explain things.
I found AI (combo Grok & ChatPPT 4o) to be the best resource for this. It was able to break it down to digestible chunks, then pull it together that made sense. It even made suggestions what math areas I need to brush up on.
Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#58Re: NIST selects HQC as fifth algorithm for post-quantum encryption
#59[flagged]
NIST is an untrustworthy government agency that occasionally produces useful encryption standards. The answer to "should we use a NIST standard" is to look at what the wider academic cryptography community is talking about. Dual_EC_DRBG was complained about immediately (for various strange statistical properties that made it impractical) and people found the ability to hide a backdoor in Dual_EC_DRBG in 2004.
If anything, the biggest issue is that the security experts pointing out the obvious and glaring flaws with NIST standards don't get listened to enough.
[0] A random number generator standard designed specifically with a back door that only the creator of its curve constants could make use of or even prove had been inserted. It was pushed by NIST during the Bush Jr. administration.