Earlier quoted context omitted.
Wasn’t Crypto AG - the Swiss company that was, oops, secretly owned by the CIA and West German intelligence - established by a Swede?
Ha, there go my two 'good' options in one fell swoop!
Mathematician warns US spies may be weakening next-gen encryption
81–90 of 218 posts
Re: Mathematician warns US spies may be weakening next-gen encryption
#82Earlier quoted context omitted.
SHA3 is fine but it's so slow, I don't many people that use it
Slow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.
Re: Mathematician warns US spies may be weakening next-gen encryption
#83Earlier quoted context omitted.
I believe the Solokey meets your definition. The hardware schematics are open, as is the software running on it. The Precursor is also open hardware and software. If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet . And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall…
Nice, last time I looked the Solo Hacker Edition was completely out of stock. Looks like the Solo HE lets you load your own firmware on to it, but it doesn't let you load your own signing or encryption key to ensure firmware updates are trusted. Apparently the Solo HE can be flashed once permanently by overwriting the bootloader, though. The non-HE versions of the Solo 1 and 2 will load new firmware signed by Solokey…
Re: Mathematician warns US spies may be weakening next-gen encryption
#84Earlier quoted context omitted.
The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.
NIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.
NIST has form for juking the standards, or at least for letting the NSA juke them. If they're not completely transparent, then any standard they recommend is open to question, which isn't good for a standard.
Re: Mathematician warns US spies may be weakening next-gen encryption
#85Earlier quoted context omitted.
Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.
Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.
Re: style, this seems longer and more rambling than usual, but other stuff on his blog has been long, and his style with lots of background, asides, references, self-quotes seems pretty distinctive, isn't it?
But I'm sure you paid more attention to this than me.
Re: Mathematician warns US spies may be weakening next-gen encryption
#86Earlier quoted context omitted.
Thanks for sharing. That's a long and tough read (in his style) but pretty interesting.
Is it? Can you summarize it? I'm asking seriously. This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.
In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims.
To make that argument, he points out a fairly egregious math mistake (the whole "2^40+2^40" bit) and then shows that NIST was inconsistent in applying the rules of the contest it refereed.
He also offers an explanation for why NIST would be so inconsistent about it, namely that they were influenced to pick KYBER, even if it wasn't the best candidate.
--
My personal takeaway was that he was both being a sore loser but also that KYBER-512 is weaker than it should be, weaker than it is claimed to be and that for some reason NIST still wanted it to win.
Makes me skeptical about KYBER-512 (but not larger sizes) and reinforces my worry that NIST can be influenced to pick less-than-optimal algorithms.
But then, I'm not a cryptographer and in the lucky situation where for any application I encounter, I can just go for KYBER-768 or 1024 or NTRU and just be fine - I don't have to understand this situation perfectly.
Hope you get some value from this outside perspective.
Re: Mathematician warns US spies may be weakening next-gen encryption
#87Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him". I want to push back on this a little by linking this Twitter thread: https://nitter.net/FiloSottile/status/1555669786826244096 It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers. It's entirely possible to be a bril…
I did not dig through all the links in that twitter thread, but the first few tweets are pretty misleading. The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far…
Isn't paranoia an essential job requirement for cryptographers?
Re: Mathematician warns US spies may be weakening next-gen encryption
#88Re: Mathematician warns US spies may be weakening next-gen encryption
#89Earlier quoted context omitted.
Because your options are Beijing or DC. We like to pretend the age of empires is past but realistically we still live in a time of where there are two major world powers and everyone gets to decide which side of the line they want to fall on, accept American hegemony or submit to Chinese control.
>Because your options are Beijing or DC. We have plenty of standards in Europe too :-) However, with cryptography historically the best crypto has been invented in the US and it made much more sense for allies to just use ready made solutions than to roll their own. Do countries on the US crypto exports ban lists have their own incompatible crypto? I dont know, they might, but they for sure don't share it as freely a…
ENIGMA?
Re: Mathematician warns US spies may be weakening next-gen encryption
#90Earlier quoted context omitted.
I don't think the problem is that kyber was designed weak. the fear is that the NSA/NIST saw an algorithm that was weaker than it should be and worked nice and hard to make sure it became the standard. the worry isn't a back door, it's unintentional mistakes that are being capitalized on.
Applying this logic, there is literally nothing NIST could have done here other than not run the competition in the first place; if it's not enough that almost every participant in the competition agrees that it was well conducted --- if the consensus of the whole academic field of post-quantum cryptography doesn't count for anything --- then all you're really saying is that there's no way to create a trustworthy sta…
The impression I have right now is that they made some mistakes and in response to having those pointed out went "well, that's just like, your opinion, man" instead of explaining why it's not a mistake, or fixing it, or something.
That's what makes me suspicious, anyway.