Live data from Hacker News

NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

blog.cr.yp.to

81–90 of 119 posts

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#81
post #26
post #24

Earlier quoted context omitted.

It is concerning that the IETF is moving forward with a proposal that weakens security and is of questionable technical merit, with the most reasonable explanation being that this is the result of efforts by government surveillance agencies to enable or potentially enable monitoring of encrypted communications supposedly protected by this standard; additionally, it is concerning that disagreeing with this decision is…

I'm asking how, specifically, it "weakens security" and is of "questionable technical merits". The IETF isn't a government body.

they have 2 options:

1. adopt hybrid/dual encryption. This is safe against a break of the PQC layer which seems entirely plausible given that the algorithms are young, the implementations are younger, and there has been significant weakening of the algorithms in the past decade.

2. Adopt PQC without a backup layer. This approach is ~5% faster (PQC algorithms are pretty slow), with the cost of breaking encryption for everyone on the internet if any flaw in the PQC algorithms or implementations is found.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#82
post #74
post #12

I used to be such a fan of this guy. But he's turned into Ed Zitron, the same long rambling rants, except about cryptography, and except that he knows what he's talking about, and he knows that you have to know literally nothing at all about the field he's commenting on to associated Dual EC with anything happening in PQ. And if you know anything about the field, trying to compare MLKEM with SIKE is the same deal. It…

The SIKE comparison is not particularly inconsistent since Bernstein has been banging the drum that structured lattices may not be as secure as thought for years now. Currently the best attacks on NTRU, Kyber, etc, are essentially the same generic attacks that work for something like Frodo, which works on unstructured lattices. And while the resistance of unstructured attacks is pretty well studied at this point, it…

Without wanting to engage much more deeply on this topic let me just say I concede any cryptography point 'pbsd makes.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#83

Earlier quoted context omitted.

Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.

As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…

Matthew Garrett is not a secret NSA propagandist.

People can reasonably disagree with the djb position. His blog posts are notoriously divisive, and that doesn't make everyone on the other side a secret NSA influencer.

Please assume good faith, or discussions turn into personal attacks and wild accusations.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#84
post #52

Earlier quoted context omitted.

Encryption layers are actually pretty cheap for the vast majority of ciphers and applications. Seems dumb not to have like 10.

Nothing is as cheap (and secure at the same time) as hardware-accelerated AES. Thats why its often the only encryption-layer used.

> Nothing is as cheap as hardware-accelerated AES.

Yes, and at the same time all of modern crypto is incredibly cheap and can be added as wished on almost every application without any visible extra costs.

So the answer to the GP is not that trivial one. The actual answer is about software complexity making errors more likely, and similar encryption schemes not really adding any resiliency.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#86

Earlier quoted context omitted.

GGP stated: > trust me from experience.

And the point is “trust me: trust no one, but especially not them” is the meaning you are ignoring.

No it's not. The NSA has been the Federal Govt's designated expert on cryptography since the end of WW2. You are pretending that the current set of NIST standards and every previous NIST standard has not had incredibly intimate contact with the NSA.

You're lived experience tells you to trust the NSA, at least as it relates to NIST standards.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#87
The same applies to the raving push to replace RSA with ECC. A long trusted algorithm suddenly became ill-trusted, too complex to implement right, too slow, too unfashionable, and the influx of these accusations was too synchronized and templated to look like something organic.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#88
post #83

Earlier quoted context omitted.

As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…

Matthew Garrett is not a secret NSA propagandist. People can reasonably disagree with the djb position. His blog posts are notoriously divisive, and that doesn't make everyone on the other side a secret NSA influencer. Please assume good faith, or discussions turn into personal attacks and wild accusations.

I didn't claim mjg59 is NSA. I said their arguments function like NSA advocacy. Whether that's by design or coincidence doesn't change the effect. When someone consistently advances positions that serve surveillance state interests using procedural deflection to avoid security substance, noting that pattern isn't a personal attack - it's public, transparent, community-led threat assessment. Pointing out behavior that is functionally indistinguishable from NSA discourse manipulation in a community technical forum - in a conversation about NSA discourse manipulation in community technical forums, no less - isn't a personal attack, it's a social IDS system firing off an alert for a known-bad signature detection.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#89
post #83

Earlier quoted context omitted.

Matthew Garrett is not a secret NSA propagandist. People can reasonably disagree with the djb position. His blog posts are notoriously divisive, and that doesn't make everyone on the other side a secret NSA influencer. Please assume good faith, or discussions turn into personal attacks and wild accusations.

I didn't claim mjg59 is NSA. I said their arguments function like NSA advocacy. Whether that's by design or coincidence doesn't change the effect. When someone consistently advances positions that serve surveillance state interests using procedural deflection to avoid security substance, noting that pattern isn't a personal attack - it's public, transparent, community-led threat assessment. Pointing out behavior that…

The effect of claiming that people act like NSA propagandists is indistinguishable from claiming they are an NSA propagandist, except that the wording allows you to weasel out of it.

This turns a thread about cryptography into a thread about attacking someone's particular posting style. This is not going to advance the discussion in any sort of useful direction, the only thing this can do is divide people further while cementing existing positions.

If your IDS thinks well-known free software people are NSA agents because they disagree in a style you don't like, the problem is with the IDS.

Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?

#90
post #89

Earlier quoted context omitted.

I didn't claim mjg59 is NSA. I said their arguments function like NSA advocacy. Whether that's by design or coincidence doesn't change the effect. When someone consistently advances positions that serve surveillance state interests using procedural deflection to avoid security substance, noting that pattern isn't a personal attack - it's public, transparent, community-led threat assessment. Pointing out behavior that…

The effect of claiming that people act like NSA propagandists is indistinguishable from claiming they are an NSA propagandist, except that the wording allows you to weasel out of it. This turns a thread about cryptography into a thread about attacking someone's particular posting style. This is not going to advance the discussion in any sort of useful direction, the only thing this can do is divide people further whi…

If someone doesn't want to be characterized as sounding like an NSA advocate, perhaps they should consider not advocating for NSA objectives.

Anyway, sounds like I'm being dismissed for being "divisive" despite raising substantive security concerns, just like djb. Readers: form your own conclusions about the repetitive patterns here; don't listen to the people telling you not to trust your own eyes.

Note the hallmarks: zero engagement with the substance of the critique (functional equivalence), ad-hom strawman attacks against my character as a response to a misrepresentation of my position, emotional manipulation techniques: demanding focus on tone / civility, maligning moral character of opponent (accusations of divisiveness), still trying to reframe a critique about behavior into an attack against identity that it isn't.

Post reply on HN