Live data from Hacker News

Breaking rainbow takes a weekend on a laptop

eprint.iacr.org

61–66 of 66 posts

Re: Breaking rainbow takes a weekend on a laptop

#61
post #55

Earlier quoted context omitted.

I followed it and was trying to point out that your question was imprecise.

Respectfully, I think you're a little lost here.

It’s all good. I take it respectfully. Let me try again and I mean this entirely in good faith. I don’t think you’re an NSA shill as I think my other comments were taken by random readers. I do think you’re just mistaken and like many Americans (myself included) we want to believe in our institutions. You seem like a reasonable person, and I meant no slight towards you.

My read is that you asked what is the secret key with the implication that if they have it they should reveal it. No one who has it would do that to settle an argument. Well maybe someone would but it seems like an unreasonable ask. Absence of evidence isn’t evidence of absence (of the theft of the secret key for the q parameter for Dual EC), right?

If Dual EC didn’t have a backdoor, no could steal the secret key that NSA uses to exploit it. One is more secure than the other, and I take your comment as requiring the secret key for the corresponding Q to leak for that design to be a bad idea that is insecure. Again, I don’t think that is a reasonable standard of evidence. We know people steal stuff from NSA and we cannot expect that they will drop the secret key on hacker news to decide that it was a bad idea in the first place.

NOBUS is a fantasy idea - is there even a reasonable proposal that isn’t less secure than the same system without a backdoor? Even with ECDLP in play, if a CRQC is really in our future, Dual EC isn’t a forever NOBUS backdoor. If we knew how to do public key cryptography that could last 100+ years and we thought it was also post-quantum, maybe a backdoor wouldn’t weaken the system overall. But that’s a lot of maybes…

Re: Breaking rainbow takes a weekend on a laptop

#62
post #59

Earlier quoted context omitted.

At the time some cryptographers said it looked like a backdoor and they were largely dismissed by the public until Snowden related evidence came to light. Further reporting exposed the $10m bribe to RSA. To wax poetic: It was not a note in isolation but a note in a much larger song. It is important to remember that NSA is continuing to do this kind of thing and they try from every angle. It is literally their job. Co…

They were largely dismissed by "the public" --- and dismissive themselves --- because nobody believed anybody would actually use an expensive, janky PKRNG when far simpler, more performant CSPRNGs were already universally available in operating systems and standard C libraries. The revelation in the BULLRUN leaks wasn't that Dual EC was suspicious --- it had always been suspicious --- but rather that companies were a…

This comment is great and gets to the heart of the dispute. Thanks for making it.

I have spoken with one of the authors who found it and he did not dismiss it, so I don’t know why you frame it as it they did? Maybe this would be a useful citation?

I do not believe that this was the only surprise in BULLRUN. I was horrified (as an American) that NSA weakened cryptography to their advantage even including against American businesses. This is still going on today and it isn’t just BSAFE. The NSA also “enables” other products including hardware to their advantage.

I agree that IAD has an important positive goal for work, I’m not really in a position to know if they are trying to help but the goal seems solid. I agree that they do not get anything close to 50% of the funding and I think this should be solved by breaking them out from NSA entirely. They should probably be made into a transparent group which never ever gives NSA an advantage as the first time did so much damage that we are still discussing it today.

Re: Breaking rainbow takes a weekend on a laptop

#63
post #60

Earlier quoted context omitted.

My words included two options, one of which includes those words — and I disowned the first option. Please read it again and then read his comment again. Selective quoting won’t change that I was providing a reflection of two possible reads of his comments, and I endorsed the latter in good faith. If you think my first option is unreasonable as a characterization to write down, I’m not sure how I can more clearly exp…

Look, dude, I don't care about this NSA shill stuff, and you're not doing your arguments any favors trying to super-duper-duper explain what you really meant by dropping innuendo into the thread. Just stop talking about it and move on. Now you know that HN is super picky about "shillage" arguments. We can be done talking about it. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Yeah! Lesson learned. Thanks for hearing me about my intentions though, I appreciate it and wow, third rail touched!

Re: Breaking rainbow takes a weekend on a laptop

#64
post #55

Earlier quoted context omitted.

Respectfully, I think you're a little lost here.

It’s all good. I take it respectfully. Let me try again and I mean this entirely in good faith. I don’t think you’re an NSA shill as I think my other comments were taken by random readers. I do think you’re just mistaken and like many Americans (myself included) we want to believe in our institutions. You seem like a reasonable person, and I meant no slight towards you. My read is that you asked what is the secret ke…

The argument you're making doesn't even cohere. If quantum computers break conventional cryptography, they moot backdoors in conventional public key cryptography. But they can simply be re-established in PQ public key cryptography. The idea behind a PKRNG backdoor is simple!

Re: Breaking rainbow takes a weekend on a laptop

#65
post #57

Earlier quoted context omitted.

The point is that if the RNG didn’t artificially add elliptic curves in the form of a back door, even a CRQC wouldn’t be able to break the RNG. Grover can be assumed to reduce the security by roughly ~N/2. A design with a sufficiently large N isn’t going to fall to a CRQC generally. The design of Dual EC which includes a backdoor is strictly worse than a design without a low hanging Q to attack. NSA expects and is pu…

I think your entire argument boils down to "there's no such thing as a NOBUS backdoor because practical quantum computing breaks Dual EC". OK. Super interesting point.

That isn’t a fair summary but I take your point.

I pointed out two specific cryptographic backdoors. One follows from your premise - a regular person can’t just bust Dual EC because it is based on a hard problem. That’s true for now but it’s also the exception as far as I can tell. Other backdoors by NSA don’t all share that property.

The other example of an NSA backdoor is the DES replacement known as the PX-1000cr cipher. It is claimed also to be a backdoor from NSA but by your framing, it can’t be an NSA backdoor because it was broken by Stef on his laptop without much of a budget. Your framing suggests that because someone found it and broke it, it can’t be an NSA NOBUS backdoor. But as I pointed out even the Dual EC backdoor has limits and so your standard seems unreasonable.

Then there is DES itself which was intentionally weakened by NSA. IBM wanted 64 bits, NSA wanted fewer bits and at the time, Hellman said DES should have twice the bits. Between Hellman and NSA, I guess we know who won.

NSA doesn’t only want NOBUS backdoors. They want almost anything that gets them plaintext first in a reliable manner, and things related to long term security come a far distant second, if at all, as we see in the analysis of the PX-1000cr research.

Also yeah, having a quantum computer will give everyone the secret key for the Q in Dual EC. Recording that traffic now will probably have pay off for non NSA adversaries later if a CRQC is really coming. Who knows if that will happen, but we know NSA is exploiting fear of that happening to push for new cryptography that isn’t a hybrid design including some kind of ECC.

Re: Breaking rainbow takes a weekend on a laptop

#66
post #64

Earlier quoted context omitted.

It’s all good. I take it respectfully. Let me try again and I mean this entirely in good faith. I don’t think you’re an NSA shill as I think my other comments were taken by random readers. I do think you’re just mistaken and like many Americans (myself included) we want to believe in our institutions. You seem like a reasonable person, and I meant no slight towards you. My read is that you asked what is the secret ke…

The argument you're making doesn't even cohere. If quantum computers break conventional cryptography, they moot backdoors in conventional public key cryptography. But they can simply be re-established in PQ public key cryptography. The idea behind a PKRNG backdoor is simple!

Huh, okay. I will try to clarify, apologies if I’m being incoherent. The argument I’m making is that the evidence doesn’t support your original claim or your follow up ask for a secret key.

NSA isn’t trying to (only) make NOBUS backdoors where the NOBUS is forever. If it isn’t forever, it’s not secure in the “Nobody but US(A)” sense implied by NOBUS as thrown around.

NOBUS is a fantasy of a very large security claim because even with a PKRNG, the keys can be stolen. However in the Dual EC case the current PKRNG again will also fall to a CRQC in addition to key theft. Both cases are strictly worse than a purely CSPRNG without a backdoor. The damage done by this kind of sabotage is hard to measure.

The evidence about backdoors points to NSA malfeasance and not towards NSA wanting something that is never insecure as is very strongly implied by the common framing of NOBUS as a concept.

Post reply on HN