Earlier quoted context omitted.
> There's a mechanism Dan can use to push for engineering decisions to be reviewed - he didn't do that. This is the retort of every bureaucracy which fails to do the right thing, and signals to observers that procedure is being used to overrule engineering best practices. FYI. I'm thankful for the work djb has put in to these complaints, as well as his attempts to work through process, successful or not, as otherwise…
Hey, look, you're free to read the mailing list archives and observe that every issue Dan raised was discussed at the time, he just disagreed with the conclusions reached. He made a complaint to the ADs, who observed that he was using an email address with an autoresponder that asserted people may have to pay him $250 for him to read their email, and they (entirely justifiably) decided not to do that. Dan raised the…
NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
61–70 of 119 posts
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#62Earlier quoted context omitted.
For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…
> For the same reason your Toyota Camry doesn't have a roll cage. It does though. It's just been engineered integral to the unibody. And there are crumple zones, airbags, seat belts, ABS, emergency braking systems, collision sensors, and more layered defenses in addition. No sane engineer would argue that removing these layers of defense would make the car safer.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#63Earlier quoted context omitted.
> For the same reason your Toyota Camry doesn't have a roll cage. It does though. It's just been engineered integral to the unibody. And there are crumple zones, airbags, seat belts, ABS, emergency braking systems, collision sensors, and more layered defenses in addition. No sane engineer would argue that removing these layers of defense would make the car safer.
If you remove enough of them, then the car is much lighter: in some scenarios (such as when the car has no occupants), that makes it much safer. Of course, these scenarios are relatively rare – but a "sane engineer" could easily make an argument along these lines.
Which is why many engineers wear the ring.
Folks do love to argue though.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#64Earlier quoted context omitted.
> There's a mechanism Dan can use to push for engineering decisions to be reviewed - he didn't do that. This is the retort of every bureaucracy which fails to do the right thing, and signals to observers that procedure is being used to overrule engineering best practices. FYI. I'm thankful for the work djb has put in to these complaints, as well as his attempts to work through process, successful or not, as otherwise…
Hey, look, you're free to read the mailing list archives and observe that every issue Dan raised was discussed at the time, he just disagreed with the conclusions reached. He made a complaint to the ADs, who observed that he was using an email address with an autoresponder that asserted people may have to pay him $250 for him to read their email, and they (entirely justifiably) decided not to do that. Dan raised the…
Everyone has no issues forcing other people to use 2FA, which preferably requires a smartphone, but a simple reply to qsecretary is something heinous.
The $250 are for spam and everyone apart from bureaucrats who want to smear someone as a group knows that this is 1990s bravado and hyperbole.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#65Earlier quoted context omitted.
Kyber is not known to be weaker than any other well used algorithm.
Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.
There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith.
I'm not saying mjg59 is an NSA propagandist / covert influencer / astroturf / sockpuppet account, but they sure fail the duck test for sounding and acting like one.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#66Earlier quoted context omitted.
Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.
As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…
It has certainly affected my perception of the individuals involved.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#67Earlier quoted context omitted.
> unless presented with evidence The complaint seems well referenced with evidence of poor engineering decisions to me. > Dual EC DRBG ... had an obvious technical weakness that provided a clear mechanism for a back door Removing an entire layer of well tested encryption qualifies as an obvious technical weakness to me. And as I've mentioned elsewhere in these comments, opens users up to a https://en.wikipedia.org/wi…
Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#68Earlier quoted context omitted.
To use his analogy though, why remove seatbelts? It's like saying we have IPv6 now, why do we need IPv4 support.
For the same reason your Toyota Camry doesn't have a roll cage. I'd use a hybrid if I was designing a system; I am deeply suspicious of all cryptography, and while I don't think Kyber is going to collapse, I wouldn't bet against 10-15 years of periodic new implementation bugs nobody knew to look for. But I'm cynical about cryptography. It's really clear why people would want a non-hybrid code point. Let me just say t…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#69I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…