6 ms·
New Linux kernel debuts, adds more suspect NSA-sourced crypto
- lainga 8y agoI encourage ITNews or anyone else to point out what's suspect about Speck. It's so tiny I don't see where you can or would put the compromise.
- geggam 8y agoremember this guy ? https://en.wikipedia.org/wiki/Edward_Snowden https://en.wikipedia.org/wiki/Edward_Snowden
- tptacek 8y agoYes. Now, finish the thought.
- geggam 8y agoEverything the NSA and the US govt touches is suspect. Anything less is silly
- tptacek 8y agoThat's a non-sequitur. The commenter upthread asked how you would hide a backdoor in a tiny block cipher. Can you answer that?
- mitchty 8y agoI think anyone discounting things like this should also explain what they would accept to change their views. Skepticism isn’t the same as denial, these attitudes of permanent ignorance remind me of the late nineties with Microsoft in the Linux community.
- pdkl95 8y agoNobody said anything about a backdoor; the question was "what's suspect about Speck". Speck is suspicious (which includes more potential risks than just a "backdoor") because "Everything the NSA and the US govt touches is suspect". This is the same kind of security-minded heuristic as the advice that you should restore from a clean backup instead of assuming you can even know how to clean a compromised host of every rootkit/backdoor/etc. Once trust has been broken, you have to assume risks might exist until proven safe. This is why burning trust is often a very bad idea; regaining that trust takes a lot of time and effort. Also, suspicion does not require an actual risk to exist. edit: For the record, I don't know much about Speck, good or bad. It might be fine, but that's orthogonal to the NSA earning a reputation that invites suspicion.
- tptacek 8y agoThis is hand-waving. Backdoor, weakness, vulnerability, whatever you want to call it. What's the suggested mechanism? In fact, as another commenter here rightly points out, cryptography does not in fact run on trust; if anything, it runs on the opposite: verify.
- pdkl95 8y ago> cryptography does not in fact run on trust This is true if and only if you can and have read the underlying math/algorithm. I haven't read Speck. My mother hasn't read the details of any type of crypto. So we don't have a basis for trusting Speck from first principles; we have to trust someone else for their expert opinion. You're only looking at the technical details. In the real world, approximately nobody has the time and training to do that, and we must rely at least somewhat on trust. For those purposes, the NSA is no longer seen as a trustworthy expert. (I'll point out that I haven't suggested that nobody should use Speck. Also, my opinion of it might change upon seeing some basis for trust (i.e. endorsement by other trusted experts or if I find the time to actually read the technical details myself))
- wglb 8y agoThis is true if and only if you can and have read the underlying math/algorithm If you are doing cryptography, you do exactly that.
- dagenix 8y agoCryptographers ought to be suspect of everything. Reputation isn't nothing, but the key part of a design is what can be proved about it, not who proposed it.
- coatmatter 8y agoI think there'll be many people who would find a comment like this suspicious and question its overall validity. There's a lot of stuff the US government (and NSA) touches that isn't suspect - do we need to start making a list? Because if we do, just one item alone would invalidate the (not uncommon) point you appear to be drawing here.
- otp124 8y agoWell, is Speck enabled by default? If not, then this title sounds a bit like they fear-mongering, or just general FUD.
- deleted 8y ago[deleted]
- zaarn 8y agoTo my knowledge, on Arch it's enabled as module, so unless some application uses Speck (which are none that I have installed, care about or know) then the module will not be loaded and do nothing.
- dagenix 8y agoThis email outlines some potential issues with Speck: https://www.spinics.net/lists/linux-crypto/msg33291.html https://www.spinics.net/lists/linux-crypto/msg33291.html And that was discussed here: https://news.ycombinator.com/item?id=17214827 https://news.ycombinator.com/item?id=17214827 I really can't judge the quality of that critique of Speck, but, its a lot more interesting than just "NSA = bad".
- tptacek 8y agoA comment on the thread from the code's contributor is super useful: SPECK was added because on low-end Android devices with less than 50MB/s AES, it enables phones to have encryption enabled by default. That is, SPECK is useful in cases where the alternative would be no encryption at all. I'd be a little surprised if SPECK was the only workable answer here. Later: It isn't; Google is doing HPolyC instead.
- ebiggers 8y agoYou can read about some of the other options considered here: https://marc.info/?l=linux-crypto-vger&m=152573520705012 https://marc.info/?l=linux-crypto-vger&m=152573520705012. But in the end, a new ChaCha-based mode suitable for disk encryption (https://eprint.iacr.org/2018/720.pdf https://eprint.iacr.org/2018/720.pdf) had to be designed since there didn't seem to be any alternative block cipher that met the strict performance and security requirements. LEA-128 maybe comes close, but it hasn't undergone too much cryptanalysis yet (much less than Speck).
- amaccuish 8y agoGoogle has decided not to use it [1], so there is discussion of it being removed [2]. [1]: https://www.phoronix.com/scan.php?page=news_item&px=No-Speck-Yes-HPolyC-Encryption https://www.phoronix.com/scan.php?page=news_item&px=No-Speck... [2]: https://www.phoronix.com/scan.php?page=news_item&px=Linux-Kernel-RFC-Remove-Speck https://www.phoronix.com/scan.php?page=news_item&px=Linux-Ke...
- amaccuish 8y agoAfter Dual_EC_DRBG, and the early warnings and raised eyebrows, I feel like "there's no smoke without fire" is a good way to operate nowadays concerning the NSA.