Earlier quoted context omitted.
The effect of claiming that people act like NSA propagandists is indistinguishable from claiming they are an NSA propagandist, except that the wording allows you to weasel out of it. This turns a thread about cryptography into a thread about attacking someone's particular posting style. This is not going to advance the discussion in any sort of useful direction, the only thing this can do is divide people further whi…
If someone doesn't want to be characterized as sounding like an NSA advocate, perhaps they should consider not advocating for NSA objectives. Anyway, sounds like I'm being dismissed for being "divisive" despite raising substantive security concerns, just like djb. Readers: form your own conclusions about the repetitive patterns here; don't listen to the people telling you not to trust your own eyes. Note the hallmark…
NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
91–100 of 119 posts
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#92Earlier quoted context omitted.
As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…
Appreciated. I'll only note that if this is the kind of resistance DJB encountered when raising his objections it goes a long way toward explaining why he might choose to publish his complaints publicly and lends additional credibility to his position. It has certainly affected my perception of the individuals involved.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#93Earlier quoted context omitted.
If someone doesn't want to be characterized as sounding like an NSA advocate, perhaps they should consider not advocating for NSA objectives. Anyway, sounds like I'm being dismissed for being "divisive" despite raising substantive security concerns, just like djb. Readers: form your own conclusions about the repetitive patterns here; don't listen to the people telling you not to trust your own eyes. Note the hallmark…
This quacking of theirs just gives them out as a duck many of us suspected them to be.
It is dishonest to state categorically that a person is not an X unless a person is in the position to know.
A pattern of behavior is a kind of evidence and the observed pattern of behavior does not seem to be in dispute.
There is no evidence presented that the person making a categorical statement is in a position to know about anyone's role or lack of a role in the NSA's clandestine activities.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#94Earlier quoted context omitted.
As a friendly reminder, you're arguing with an apologist for the security-flawed approach that the NSA advocates for and wants. There are absolutely NSA technical and psychological operations personnel who are on HN not just while at work, but for work, and this site is entirely in-scope for them to use rhetoric to try to advance their agenda, even in bad faith. I'm not saying mjg59 is an NSA propagandist / covert in…
Appreciated. I'll only note that if this is the kind of resistance DJB encountered when raising his objections it goes a long way toward explaining why he might choose to publish his complaints publicly and lends additional credibility to his position. It has certainly affected my perception of the individuals involved.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#95There is so much here to debate about. A) Never trust the cyber feds. B) The NSA is not the place anyone thinks, it’s a Wild West in the most bizarre of places, trust me from experience. C) Cryptology concerns more of than security and exchanging messages or packets, sometimes you don’t even know what kind of thing (living) can and has been decrypted. D) The NSA plays very, very, very dirty. It is like a digital CIA,…
Ok, aside from not trusting the NSA, could you expand on why someone should trust you ?
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#96Earlier quoted context omitted.
Why don't we hybridise all crypto? We'd get more security if we required RSA+ECDSA+ED25519 at all times, right? Or is the answer that the benefits are small compared to the drawbacks? I am unqualified to provide an answer, but I suspect you are also, and the answer we have from a whole bunch of people who are qualified is that they think the benefits aren't worth it. So why is it fundamentally and obviously true for…
Which insinuations do you think are ludicrous? Is it not a matter of public record at this point that the NSA and NIST have lied to weaken cryptography standards?
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#97Earlier quoted context omitted.
Kyber is not known to be weaker than any other well used algorithm.
Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#98Earlier quoted context omitted.
Kyber is not known to be weaker than any other well used algorithm.
Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#99Earlier quoted context omitted.
The vast majority of organisations just use whatever default security settings their Cisco router or web browser comes with. The NSA starts by requiring some insecure protocols be supported , and then when support is widespread they start requiring it be made a default by requiring compliance testing be done with default config.
They also historically have extremely deep access to networks, and even if a given corp doesn't allow them to put a box inside the corp's own network, they control / have access to many or all of the links between most corps' datacenters. From this privileged network position, if both sides support weaker crypto that NSA lobbied for, they can MitM the initial connection and omit the hybrid methods from the client's T…
Re: NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
#100Earlier quoted context omitted.
Kyber is not known to be weaker than any other well used algorithm.
Another strawman. No one in this thread said Kyber was known to be weaker. Just that elliptic curve cryptography is well tested, better understood as a consequence of being used in production longer, and that removing it opens up transmissions made without both to attacks on the less widely used algorithm which would not otherwise be successful. It really seems like you're trying not to hear what's been said.