3 ms·
Don your shiny crinkly hats, but after https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Dual_EC_DRBG I started believing that NSA in
by slackingoff2017 9y ago
Don your shiny crinkly hats, but after https://en.m.wikipedia.org/wiki/Dual_EC_DRBG https://en.m.wikipedia.org/wiki/Dual_EC_DRBG I started believing that NSA involvement is not subtle in their exploits.
They only need to fool laymen, and backdoored primes are an easy way to do so. The number of true cryptography experts beyond their walls is a dozen in the world at best. Case in point https://en.m.wikipedia.org/wiki/Daniel_J._Bernstein https://en.m.wikipedia.org/wiki/Daniel_J._Bernstein . And BTW he's been sued by the US government for ???. Thank God the EFF has decent funding.
- tptacek 9y ago"The number of true cryptography experts beyond [the walls of the NSA] is a dozen in the world at best"? This kind of logic is super common on HN threads and it's incoherent. If the expertise and capabilities of the NSA with respect to basic cryptographic mathematics is so unknowable that thousands of published academic cryptographers are wasting their time, then what makes you think a random amateur Math Overflow post has somehow stumbled on a deep secret of NSA RSA subterfuge? For whatever it's worth to you, Dan Bernstein was not sued by the US Government. Dan Bernstein sued the US Government, over export restrictions on cryptography in the 1990s; his suit was mooted by the relaxation of those restrictions.
- theWatcher37 9y agoNSA made seemingly bening improvements to crypto standards that the academic community only discovered as valuable over a decade later. They’re the largest single employer of mathmaticians in the world.
- monocasa 9y ago> NSA made seemingly bening improvements to crypto standards that the academic community only discovered as valuable over a decade later. At the same time, they negotiated DES's key length down. It was 64 bits originally, the NSA wanted only 48 bits, IBM and the NSA compromised on 56 bits.
- caf 9y agoNote that the Dual EC DRBG backdoor you point to was in fact a NOBUS backdoor.
- EwanToo 9y agoDo you honestly believe that China and Russia don't take cryptography seriously, and between them only employ a tiny handful of experts...?
- trumpownsyou420 9y agomost amercians (you can tell he is) aren't fond of the places you named, chap.
- slackingoff2017 9y agoThe opposite. Government entities suck up all the world's crypto experts leaving very few working in the publics interest.
- tptacek 9y agoYou mean except for every professor, postdoc, and grad student working in every crypto research group at every large CS department in the world?