5 ms·
I must be misunderstanding something - why would a standards group (or anyone with a functioning brain) accept a "secure" cipher standard developed by an organi
by PerilousD 8y ago
I must be misunderstanding something - why would a standards group (or anyone with a functioning brain) accept a "secure" cipher standard developed by an organization who's foundation in part is to be able to break encrypted communications?
- _wmd 8y agoBecause if it is possible to ascertain they are acting in good faith, there is no better collection of minds, money and official secrets suited to the task of designing a robust cipher. The problem is that it's somewhere between difficult and impossible to ascertain whether they are acting in good faith.
- api 8y agoThere is also no real need. Reduced round Salsa/ChaCha (12 rounds) is tiny and likely fast enough for the quantities of data any microcontroller would need to push over a network. Those ciphers were designed in the open and have been heavily analyzed with no attacks known against more than a few rounds. Why not use those?
- makomk 8y agoIn general that's true, but if I understood the discussion correctly the reason Speck was being considered here is because this specific application needed a fast block cipher - stream ciphers like Salsa/ChaCha were not suitable.
- craftyguy 8y agoTheir recent behavior suggests that they are not acting in good faith and, even if they were, the "between difficult and impossible to ascertain" bit should mean that they are, by default, not trustworthy.
- _wmd 8y agoIt's important to remember the desired goal - secure cryptography, and in that case even if the NSA is a known-bad actor, they might still be the best option to achieve an optimal outcome. There is a name for the kind of table below but I have forgotten it. Essentially on the balance of outcomes, a situation (of engineered choices, of course!) where the NSA is involved still produces, given unknown factors, a potentially better outcome than a situation where the NSA is excluded. Bad = 0.1, Fair = 0.5, Excellent = 1.0 Cipher Author | Known Weak | Security | Likelihood | Security*Likelihood | Academia | No | Excellent | Bad | 0.1 Academia | Nationally | Fair | Fair | 0.25 Academia | Internationally | BAD | Fair | 0.05 NSA | No | Excellent | Fair | 0.5 NSA | Nationally | Fair | Fair | 0.25 NSA | Internationally | BAD | Bad | 0.01 SUM(academia) = 0.31 SUM(nsa) = 0.76 (Does anyone know what this kind of table is called? Can someone do a version that makes more sense? It's 4am and quite a few beers were involved :))
- notveryrational 8y agoSecurity professional here. This isn't how security works. When the term "secure" is used, it is relative only to a threat model. Typically these threat models are implied, but different perspectives, levels of experience and communication barriers often see that this non-precise term causes confusion and mistakes. In the case of cryptography, the implied "security" of a cipher differs wildly across many different properties (the security margin the design, the caveats to its correct use, the modes it is used with, it's likelihood to be implemented properly, etc. One of the properties is how the integrity or confidentiality of the schemes fail to different types of adversaries - and who are trusted parties to the data security layer. All of this is to say that - if our threat model includes intelligence agencies and mass surveillance - the NSA is not able to provide encryption that can be trusted to be secure.
- ibotty 8y agoWhy should academia only produce excellent security algorithms with "Bad" likelihood?
- _jal 8y agoMultiple reasons, but a huge one is simply that, to be taken seriously, international standards bodies can't really ignore the biggest kid on the block. Even if the motives for doing so were pure as the driven snow, it would still be seen as a political decision, and now you're a national or maybe regional standards body.
- mtgx 8y agoIt's not the ISO that has tried to politicize the standards, but the NSA and FBI, by trying to put backdoors in encryption to "catch the bad guys" = a political motive used to break everyone's security.
- stouset 8y agoThe cryptographic community used to have a lot of trust in the NSA, and that trust was well-deserved. One of the most well-known contributions was improving the resistance of DES to differential analysis, which hadn’t even been discovered in the academic world yet. The NSA recommended an S-Box change, and provided next to no rationale for doing so. Only years later did we understand why. Recommendations from the NSA find their way into standards that are implemented by the government itself, and that is one of the reasons the community trusted the NSA to a degree. It wasn’t seen as being in their long-term self-interest to insert backdoors that others could find into their standards. Obviously that trust was wiped out by the DUAL_EC_DRBG debacle, although many cryptographers still believe it’s worthwhile to analyze and consider NSA ciphers on their own merits just as you would a cipher by DJB. In my personal opinion, as a general rule, I would wager that symmetric ciphers published by them can be reasonably assumed to be free of back doors, since there’s fewer degrees of freedom to insert them except through real cryptographic weaknesses which others could independently discover. Asymmetric algorithms probably shouldn’t be given this benefit of the doubt, since there are enough degrees of freedom to be possible to have a private master key of sorts (e.g., DUAL_EC_DRBG) which isn’t be able to be discovered independently and can only be revealed if it’s stolen directly.
- akira2501 8y ago> The NSA recommended an S-Box change Which is true and commendable; however, in the exact same system they proposed weakening the key from 64bits to 48bits. IBM split the difference and we got 56bit DES.
- NickNameNick 8y agoThe shorter key length better reflects the actual security of the cipher - the longer key lengths were misleading. Or at least, that was the later justification.
- simias 8y agoBecause you don't have to believe them or even trust them, it's maths. If their design was sound and well justified I don't see why it should be discarded. As pointed out in this email it seems far from being the case however. After all AES is endorsed by the US government as well (although not designed by them, admittedly), yet we trust it because we have no reason not to. While the NSA has an obvious incentive to be able to break encryption they also have an incentive to be able to use ciphers than are fast and not easily broken. Well, I suppose ideally they'd like a cipher that only they can break, which might be what's going on here. So while I don't think NSA's proposals for a new cipher shouldn't be dismissed merely because it comes from them it should obviously be met with the highest amount of skepticism and scrutiny. No stone left unturned. Fortunately it seems that's exactly what happened there and the ciphers were rejected.
- zitterbewegung 8y agoI think you forgot the bit that AES was created by a competition involving academics while SPECK is directly from the NSA. I think that is where people are having the issue of trust due to the NSA muddying the waters with their recent behavior.
- baby 8y ago> Because you don't have to believe them or even trust them, it's maths That is not true, the only way we know how to assess a cipher's security is to basically attack it and add a margin of security on top of the best attack you find. If the NSA has built its cipher on top of a flaw that only they know, and if third party research hasn't found the flaw then we're doomed.
- mtgx 8y ago> it's maths That's a joke. First off, we don't even know how NIST obtained this "magical" large number that we're supposed to trust it creates a safe formula for the P-256 curve: y^2 = x^3-3x+41058363725152142129326129780047268409114441015993725554835256314039467401291 https://safecurves.cr.yp.to/ https://safecurves.cr.yp.to/ Second, the NSA refused to reveal certain technical details that they should have been able to reveal to the ISO: https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/ https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/ So it's not all "just maths". Otherwise all of these people wouldn't be so suspicious about it. It's not all about the design, either, even if it was 100% transparent. But about how secure it actually is. We don't really know how secure an algorithm is, even as it passes a competition or standardization process. We have to see it in the real world, but once it's in the real world and everyone adopts it, it could take at least 10-15 years to get rid of it from most places. The NSA refused to reveal how Simon and Speck would resist against certain attacks. They kind of did the same with IPSEC, where they made it super-complex so that the implementers would almost always get it wrong, which means they'd leave holes in there that the NSA could exploit. This is how they muddied the waters in the standardization processes. It's their MO when they can't introduce an actual backdoor - they just design a crypto algorithm that looks okay on the surface, but hides high potential dangers: https://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html https://www.mail-archive.com/cryptography@metzdowd.com/msg12... Also this seems to perfectly describe how I've already thought the NSA would act. Why would anyone ever trust them when they act like this? It's quite strange to still see so much support here despite of this: > When some of the design choices made by the NSA were questioned by experts, Ashur states, the g-men's response was to personally attack the questioners, which included himself, Orr Dunkelman and Daniel Bernstein, who represented the Israeli and German delegations respectively. > Ashur further alleged that the NSA had plied the relevant ISO committee with "half-truths and full lies" in response to concerns, and said that if the American delegation had been "more trustworthy, or at least more cooperative, different alliances would have probably been formed." > Instead, he says, "they chose to try to bully their way into the standards which almost worked but eventually backfired." https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/ https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/
- adrianmonk 8y agoTheoretically, the NSA has a dual mission: 1. Gain access to information where that would be in US interests. 2. Protect US information from being accessed by others. From their web site ( https://www.nsa.gov/about/faqs/about-nsa-faqs.shtml https://www.nsa.gov/about/faqs/about-nsa-faqs.shtml ): > NSA/CSS has two interconnected missions: Signals Intelligence (SIGINT) and Information Assurance (IA). Through SIGINT, we respond to customer requirements for information relating to the plans, intentions, capabilities, and locations of foreign powers, organizations, terrorist groups, or persons, or their agents, who threaten America’s national security. Under Information Assurance, we protect our nation’s vital national security systems and information from theft or damage by others. Whether you trust them is another question. Many argue that this dual mission creates an inherent conflict of interest. But if you believe they take both halves of it seriously, you might see them as having a legitimate interest in ensuring good crypto is available. (I'm not advocating for that position, but it doesn't seem totally irrational to me either.)
- mtgx 8y agoYes, in theory. In practice, they've proven they are much more interested in everyone having vulnerable computers vs everyone having super-secure virtually unhackable computers. This "dual-mission" thing reminds of some tv networks presenting "equal sides" on a debate on climate change. In 99% of the cases, the NSA will choose to keep its vulnerabilities for computers rather than try to fix or disclose them.
- tptacek 8y agoThis comment doesn't really add anything to the discussion; it simply restates the concern that started the subthread.
- nickpsecurity 8y agoWhen I looked at it, they were only required to protect defense systems. For civilians, they had no strong, legal requirements. They did have a mandate to spy on them, though.This is why you can't get ahold of their TEMPEST- or Type 1-certified gear despite the nation's enemies using attacks those block with high confidence. The stuff they recommend is the stuff rated by them to be easy to moderately-difficult to attack. So, dual nature is misleading unless you're a defense contractor or agency. The SIGINT group has all the money, power, and executive backing. That last part means even IAD's honest folks will get overruled at some point forced to compromise somehow. There's definitely people trying with the security guides, funding things like Cryptol, and so on.
- rain1 8y agospeck and simon actually seem to be very good ciphers. It's unfortunate that NSA has tarnished its own reputation with earlier crypto mis-contributions.
- paulie_a 8y agoThe NSA has always had a shitty reputation. They are one step above the CIA who will fuck up a cup of coffee.
- Something1234 8y agoWell, according to coffee snobs it's really easy to fuck up a cup of coffee.
- mcguire 8y agoNot according to this email.