3 ms·
Yeah. I'm not claiming they invented AES nor SHA-3. The monoculture stems from government ways of thinking that only NIST approved standards can be used. If it
by atoponce 10y ago
Yeah. I'm not claiming they invented AES nor SHA-3. The monoculture stems from government ways of thinking that only NIST approved standards can be used. If it doesn't have the NIST stamp of approval, it can't be deployed in production.
- pvg 10y agohttps://en.wikipedia.org/wiki/Advanced_Encryption_Standard_process https://en.wikipedia.org/wiki/Advanced_Encryption_Standard_p... Just as one example. A years-long open submission and selection process. In what way do you feel that results in a 'monoculture'? How would it be done differently and better?
- atoponce 10y agoAs I explained, it's a monoculture in that there are organizations, mostly U.S. government bodies, that will not deploy cryptographic primitives unless it has been standardized by NIST. This means strictly sticking with 3DES, AES, SHA-1, SHA-2, and SHA-3. For random number generation, this means CTR_DRBG, HMAC_DRBG, and Hash_DRBG. For password hashing, it's md5crypt, sha256crypt, and sha512crypt. It goes on and on. I used to work as a contractor for the Dept. of V.A. and am familiar with the red-tape required to implement libraries in code, push patches to production, rely on 3rd-party libraries, etc. It's a nightmare. As an admin, I couldn't certify a hard drive was digitally wiped unless it did the DoD 3-pass, even though I'm confident a single pass of zeros is sufficient. I couldn't use my LUKS encrypted laptop on premesis, because the encryption process hadn't been vetted by a committee. I couldn't deploy bcrypt as the password hash for authentication. So, my reference to "NIST/NSA monoculture", is the bullheaded requirement that only NIST-approved algorithms can be use, after committees and approval. It's a monoculture, because at least for the V.A., only government standardized algorithms are allowed.
- pvg 10y agoThat sounds like a pain, on the other hand, I don't think it really matches any reasonable definition of 'monoculture'. And I'd guess I'm in a majority that's ok with the Department of VA (or of Agriculture or Housing and Urban Development, etc) not inventing their own crypto practices and standards.
- tptacek 10y agoSo, I agree that NIST has been a force for evil in the world, in the same sense that the IETF has. If that's the core point you're trying to make, we're on the same page. I just don't think "monoculture" is the reason why. I think all crypto standards organizations are problematic.
- atoponce 10y ago> So, I agree that NIST has been a force for evil in the world, in the same sense that the IETF has. If that's the core point you're trying to make, we're on the same page. If you are defining "evil" as blind and bullheaded, then yes. I don't think NIST or the IETF are actively malicious, however.