4 ms·
Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 https://news.ycombinator.com/item?id=15302662 I felt
by CiPHPerCoder 9y ago
Previous HN discussion on the same topic (different source): https://news.ycombinator.com/item?id=15302662 https://news.ycombinator.com/item?id=15302662
I felt that tptacek's top comment in that thread was the best synopsis for the whole situation.
- mtgx 9y agoIt doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Speaking of which, is the NSA guy still running the crypto review group at the IETF? If so, how is that still a thing?! Everyone should make it clear that the NSA is not welcome in such groups anymore. That should be the consequence not just for "getting caught" trying to put a backdoor inside a crypto algorithm, but for constantly pushing legislators to increase their surveillance powers and pass anti-encryption laws. The NSA has made it clear in many more occasions than in the Dual_EC situation that they are the enemy of crypto, not its friend. I think that's more than enough reason to distrust all NSA projects by default.
- CiPHPerCoder 9y ago> It doesn't matter that this algorithm was backdoor-free. I'd rather see the community reject all NSA-proposed projects by default than let some of the backdoor-enabled ones sneak in once the NSA is "trusted" again. Politically, I'm inclined to agree. But the technical merits should be commented on as well. That's what Thomas's comment did. > Speaking of which, is the NSA guy still running the crypto review group at the IETF? Which is "the NSA guy" and how is he running the show? > If so, how is that still a thing?! For the same reason that the guy peddling the Crystalline cipher is still allowed to participate with the IETF. There's really no lock-out. > The NSA has made it clear in many more occasions than in the Dual_EC situation that they are the enemy of crypto, not its friend. I think that's more than enough reason to distrust all NSA projects by default. That sounds good on paper, but you're not advocating "distrust ... by default" in every part of your comment before this snippet. Your words are coming a cross as more on the "distrust ... forever" side. And I'm left wondering which of the two you actually want.
- beefhash 9y agoI disagree with this stance. Technical decisions should be made on technical merit, not because a person or institution has a shady background. The algorithms in questions have been under a lot of analysis precisely because the NSA designed them. Yet we rely on AES and SHA every day. There is no good that can come from knee-jerk reactions.
- psyc 9y agoPerhaps important decisions that affect everybody should be based on relevant information. Technical merit is relevant, but so is the known adversarial motivations of powerful actors.
- lvh 9y agoI’m not sure I follow entirely: AES isn’t an NSA design, and neither is SHA-3 (though earlier ones are). Are you referring to NIST, perhaps in the context of DualEC-DRBG?
- cptskippy 9y agoWhy should the NSA receive any more scrutiny than anyone else? The NSA is in a weird position. Their mission is to secure the state and to gain advantage over adversaries. So they have a vested interest in protecting state industry from it's adversaries, and no interest in protecting anyone from themselves. So with that in mind it's perfectly reasonable for them to try to slip backdoors into anything and everything, and to also prevent others from doing the same. The same is probably true of every other intelligence agency. If we start rejecting their contributions by default then they'll just start looking for other ways to exploit the process if they haven't already. What's to stop them from bribing or extorting independent researchers? Perhaps there needs to just be a paranoid level of scrutiny over anyone and everything? When securing software you assume every request is threatening, why not when evaluating it?
- JumpCrisscross 9y ago> Why should the NSA receive any more scrutiny than anyone else? They’re a large, well-funded agency with documented efforts antagonistic to the goals of cryptography. There aren’t that many organisations fitting that bill and submitting designs. It makes sense to give them special attention. Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher.
- cptskippy 9y ago> Unsaid in this is what prevents the NSA from submitting a scheme through an unaffiliated researcher. That's exactly my point. You can immediately reject or even ban them from submitting anything but they will end run the process. Rather than having a special procedure just for them, you're better off hold everyone to the same standard and assuming everyone is the NSA.
- meowface 9y ago>Why should the NSA receive any more scrutiny than anyone else? Because they were caught red-handed. They were effectively proven to have attempted to push a backdoored random number generator as a standard. They were the only ones who possessed the key to the backdoor. They never suggested that the backdoor (or "key escrow" as they call it) was present in the algorithm. Even the Clipper chip [1], as bad as it was, wasn't this bad, since they were trying to be semi-transparent by saying "we possess the master key to this so we can help law enforcement investigate terrorism and other serious crimes". Here, the scheme was executed entirely in secret. If any private person or organization in the US tried to do something like this, they would be arrested and prosecuted under the CFAA (among other things). One could even make an argument that their DRBG backdoor is even more willfully malicious and toxic to our security than the warrantless mass surveillance. If a conman tries to sell you some phony goods that he knows to be phony, you're never going to buy anything from him again, even if the later stuff seems legit. [1] https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip
- pbsd 9y agoKevin Igoe has been gone from the CFRG since mid-2015.
- jancsika 9y agotptacek's comment lower down is interesting: > I've already stipulated the politics of the story, which are deeply boring to me. I'm not sure it's possible to be bored by "politics"-- i.e., to be bored by evidence from the Snowden leaks that the NSA is interested in pushing and has pushed kleptographic cryptography to undermine standards-- and be seriously engaged in a technical analysis. It's like saying you're only interested in the code of the winning entry of the Underhanded C Contest, but not at all interested in the rules of the challenge. If someone's analysis under those circumstances is that the code looks like it does a fine job of completing its task, one should be skeptical. [1] http://www.underhanded-c.org/ http://www.underhanded-c.org/
- meowface 9y agoHis point is that he wanted to discuss the technical details of the cipher design and not the political background story. He specifically said he agrees that it seems sensible ISO has not adopted this standard in light of NSA's subversive Dual EC DRBG deception, but that it also is very unlikely these ciphers contain or could contain a backdoor. He's not at all arguing that ISO is in the wrong to decline accepting the algorithms or that the politics don't matter; just that they probably didn't backdoor these 2 particular algorithms. NSA has voided all of their goodwill, no doubt, but that's not what he was addressing. I imagine the cryptographers working at NSA who are genuinely trying to design secure, non-backdoored algorithms are very unhappy at how badly their organization shot themselves in the foot.