3 ms·
Reading about this saga in Ben Buchanan's book "The Hacker and the State" made me realize how every government agency (NIST in this case) seems to be always sec
by DaftDank 5y ago
Reading about this saga in Ben Buchanan's book "The Hacker and the State" made me realize how every government agency (NIST in this case) seems to be always second fiddle to the "needs" of the NSA/national security apparatus. It seems clear from the book that there was a point in time when they essentially just left it in the NSA's hands to develop, knowing it was probably not secure. Not exactly some huge revelation that the national security apparatus can exert power and leverage over other government groups, or even private companies, but the extent to which it happens was surprising.
- nullc 5y agoBudiansky's Code Warriors emphasized the point that the NSA and its precursors has actively withheld information from the civilian government, including the president. Unfortunately, the very secrecy of it prevent us from knowing the full extent, we only know of the specific cases where its been documented.
- er4hn 5y agoAnother problem is how NIST should come up with standards. NIST is in charge of standards, but that means that they need to turn to subject matter experts for each separate field. They need to define the standards for everything from measuring weights, to chemicals in wastewater, to cryptography. So then for each standard you then end up with the government equivalent of an open process where there are requests for comments, maybe a meeting or two to discuss, and trusted folks end up defining the bulk of the document with oversight from editors. Where this breaks down is when you have the subject matter expert on crypto in government, the NSA, be interested in undermining the standards for their own specialty to serve their internal agenda.