34 ms·
NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
- crabbygrabby 4y agoSeems like a baaad idea lol.
- zitterbewegung 4y agoHe won a case against the government representing himself so I think he would be on good footing. He is a professor where I graduated and even the faculty told me he was interesting to deal with. Post QC is his main focus right now and also he published curve25519.
- matthewdgreen 4y agoHe was represented by the EFF during the first, successful case. They declined to represent him in the second case, which ended in a stalemate.
- throwaway654329 4y agoThe full story is interesting and well documented: https://cr.yp.to/export.html https://cr.yp.to/export.html Personally my favorite part of the history is on the “Dishonest behavior by government lawyers” page: https://cr.yp.to/export/dishonesty.html https://cr.yp.to/export/dishonesty.html - the disclaimer at the top is hilarious: “This is, sad to say, not a complete list.” Indeed! Are you implying that he didn’t contribute to the first win before or during EFF involvement? Are you further implying that a stalemate against the U.S. government is somehow bad for self representation after the EFF wasn’t involved? In my view it’s a little disingenuous to call it a stalemate implying everything was equal save EFF involved when the government changes the rules. He challenged the new rules alone because the EFF apparently decided one win was enough. When the judge dismissed the case, the judge said said that he should come back when the government had made a “concrete threat” - his self representation wasn’t the issue. Do you have reason to believe otherwise? To quote his press release at the time: ``If and when there is a concrete threat of enforcement against Bernstein for a specific activity, Bernstein may return for judicial resolution of that dispute,'' Patel wrote, after citing Coppolino's ``repeated assurances that Bernstein is not prohibited from engaging in his activities.'' - https://cr.yp.to/export/2003/10.15-bernstein.txt https://cr.yp.to/export/2003/10.15-bernstein.txt
- matthewdgreen 4y agoI’m saying that the EFF are skilled lawyers who won a major case, and they should not be deprived of credit for that accomplishment.
- throwaway654329 4y agoSure, EFF played a major role in that case as did Bernstein. It made several lawyers into superstars in legal circles and they all clearly acknowledge his contributions to the case. Still you imply that he shouldn’t have credit for that first win and that somehow he failed in the second case. EFF shouldn’t have stopped fighting for the users when the government changed the rules to something that was also unacceptable.
- matthewdgreen 4y agoThe original poster said “he won a case against the government representing himself” and I felt that statement was incomplete, if not inaccurate and wanted to correct the record. I’m pretty sure Dan, if he was here, would do the same.
- zitterbewegung 4y agoSorry I didn’t know that part. I have only seen Professor Bernstein once (he had a post QC t shirt on so that’s the only way I knew who he was ). I have never interacted with him really. He is also the only faculty that is allowed to have a non UIC domain. Thank you for correcting me .
- throwaway654329 4y agoYou appear to be throwing shade on his contributions. Do I misunderstand you? A stalemate, if you already want to diminish his efforts, isn’t a loss by definition - the classic example is in chess. He brought the government to heel even after EFF bailed. You’re also minimizing his contributions to the first case. His web page clearly credits the right people at the EFF, and he holds back on criticism for their lack of continuing on the case. I won’t presume to speak for Dan.
- yieldcrv 4y agoseems like they just need a judge to force the NSA to comply with a Freedom of Information Act request, its just part of the process I'm stonewalled on an equivalent Public Record Act request w/ a state, and am kind of annoyed that I have to use the state's court system Doesn't feel super partial and a couple law journals have written about how its not partial at all in this state and should be improved by the legislature
- throwaway654329 4y agoThis is part of a class division where we cannot practically exercise our rights which are clearly enumerated in public law. Only people with money or connections can even attempt to get many kinds of records. It’s wrong and government employees involved should be fired, and perhaps seriously punished. If people at NIST had faced real public scrutiny and sanction for their last round of sabotage, perhaps we wouldn’t see delay and dismissal by NIST. Delay of responding to these requests is yet another kind of sabotage of the public NIST standardization processes. Delay in standardization is delay in deployment. Delay means mass surveillance adversaries have more ciphertext that they can attack with a quantum computer. This isn’t a coincidence, though I am sure the coincidence theorists will come out in full force. NIST should be responsive in a timely manner and they should be trustworthy, we rely on their standards for all kinds of mandatory data processing. It’s pathetic that Americans don’t have several IG investigations in parallel covering NIST and NSA behavior. Rather we have to rely on a professor to file lawsuits for the public (and cryptographers involved in the standardization process) to have even a glimpse of what is happening. Unbelievable but good that someone is doing it. He deserves our support.
- PaulDavisThe1st 4y agoEven though I broadly agree with what you've written here ... the situation in question isn't really about NIST/NSA response to FOIA requests at all. It's about whether the US government has deliberately acted to foist weak encryption on the public (US and otherwise), presumably out of desire/belief that it has the right/need to always decrypt. Whether and how those agencies respond to FOIA requests is a bit of a side-show, or maybe we could call it a prequel.
- gruturo 4y agoYeah, terrible idea, except this is Daniel Bernstein, who already had an equally terrible idea years ago, and won. That victory was hugely important, it pretty much enabled much of what we use today (to be developed, exported, used without restrictions, etc etc etc)
- throwaway654329 4y agoThe history in this blog post is excellently researched on the topic of NSA and NIST cryptographic sabotage. It presents some hard won truths that many are uncomfortable to discuss, let alone to actively resist. The author of the blog post is also well known for designing and releasing many cryptographic systems as free software. There is a good chance that your TLS connections are secured by some of these designs. One of his previous lawsuits was critical to practically protecting free speech during the First Crypto War: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States https://en.m.wikipedia.org/wiki/Bernstein_v._United_States I hope he wins.
- aliqot 4y agoGiven his track record, and the actual meat of this suit, I think he has a good chance. - He is an expert in the domain - He made a lawful request - He believes he's experiencing an obstruction of his rights I don't see anything egregious here. Being critical of your government is a protected right for USA. Everyone gets a moment to state their case if they'd like to make an accusation. Suing sounds offensive, but that is the official process for submitting an issue that a government can understand and address. I'm seeing some comments here that seem aghast at the audacity to accuse the government at your own peril, and it shows an ignorance of history.
- maerF0x0 4y agoI'd add * and it's been 20 yrs since the 9/11 attacks which predicated a lot of the more recent dragnets
- feet 4y agoI'll also add Which have not prevented anything and instead are used in parallel construction to go after Americans
- gene91 4y agoI don’t like the collateral damages of many policies. But it’s not fair to say that the policies “have not prevented anything” because we simply don’t know. The policies could have stopped in-progress evil acts (but they were never revealed to the public for intel reasons) or prevented attempts of an evil acts (well, nothing happened, nothing to report).
- lawrenceyan 4y agoHere's an interesting question. Even if post-quantum cryptography is securely implemented, doesn't the advent of neurotechnology (BCIs, etc.) make that method of security obsolete? With read and write capability to the brain, assuming this comes to fruition at some point, encryption as we know it won't work anymore. But I don't know, maybe this isn't something we have to worry about just quite yet.
- deleted 4y ago[deleted]
- yjftsjthsd-h 4y agoThe encryption is fine, that's just a way to avoid it. Much like how tire-iron attacks don't break passwords so much as bypass them.
- lawrenceyan 4y agoOk that's actually a great point. To make the comparison: Tire-irons require physical proximity. And torture generally doesn't work, at least in the case of getting a private key. Reading/writing to the brain, on the other hand, requires no physical proximity if wireless. And the person(s) won't even know it's happening. These seem like totally different paradigms to me.
- ziddoap 4y agoI think we are a long way away from being able to wirelessly read a few specific bytes of data from the brain of an unknowing person. Far enough away that I'm not sure it's productive to begin thinking of how to design encryption systems around it.
- lawrenceyan 4y agoMemory and experience aren't encoded in the brain like traditional computers. There's no concept of a "byte" when thinking about the human computational model.
- xenophonf 4y agoGood god, this guy is a bad communicator. Bottom line up front: > NIST has produced zero records in response to this [March 2022] FOIA request [to determine whether/how NSA may have influenced NIST's Post-Quantum Cryptography Standardization Project]. Civil-rights firm Loevy & Loevy has now filed suit on my behalf in federal court, the United States District Court for the District of Columbia, to force NIST to comply with the law. Edit: Yes, I know who DJB is.
- jcranmer 4y agoThat is truly burying the lede... I spent most of the post asking myself "okay, I'm guessing this is something about post-quantum crypto, but what are you actually suing about?"
- deleted 4y ago[deleted]
- kube-system 4y agoWell, he is an expert in cryptic communication
- gred 4y agoThis guy is the best kind of curmudgeon. I love it.
- eointierney 4y agoYippee! DJB for the win for the rest of us!
- mort96 4y agoWeirdly, any time I've suggested that maaaybe being too trusting of a known bad actor which has repeatedly published intentionally weak cryptography is a bad idea, I've received a whole lot of push-back and downvotes here on this site.
- throwaway654329 4y agoIndeed. Have my upvote stranger. The related “just ignore NIST” crowd is intentionally or unintentionally dismissing serious issues of governance. Anyone who deploys this argument is questionable in my mind, essentially bad faith actors, especially when the topic is about the problems brought to the table by NIST and NSA. It is a good sign that those people are actively ignoring the areas where you have no choice and you must have your data processed by a party required to deploy FIPS certified software or hardware.
- deleted 4y ago[deleted]
- glitchc 4y agoMany government or government affiliated organizations are required to comply with NIST approved algorithms by regulation or for interoperability. If NIST cannot be trusted as a reputable source it leaves those organizations in limbo. They are not equipped to roll their own crypto and even if they did, it would be a disaster.
- icodestuff 4y ago"Other people have no choice but to trust NIST" is not a good argument for trusting NIST. Somehow I don't imagine the NSA is concerned about -- and is probably actively in favor of -- those organizations having backdoors.
- wmf 4y agoIt's an argument for fixing NIST so that it is trustworthy again.
- bsaul 4y agoholy crap, i wondered why the post didn't mention work by dj bernstein outing flaws in curves submitted by nsa... Well, didn't expect the post to actually be written by him.
- xiphias2 4y agoAn interesting thing that is happening on Bitcoin mailing list is that although it would be quite easy to add Lamport signatures as an extra safety feature for high value transactions, as they would be quite expensive and easy to misuse (they can be used only once, which is a problem if money is sent to the same address twice), the current concensus between developers is to ,,just wait for NSA/NIST to be ready with the algorithm''. I haven't seen any discussion on the possibility of never being ready on purpose because of a sabotage.
- potatototoo99 4y agoWhy not start that discussion yourself?
- jack_pp 4y agoIndeed as potato said, link this article in the ML for them to see that NIST can not be fully trusted
- bumper_crop 4y agoThis definitely has the sting of bitterness in it, I doubt djb would have filed this suit if NTRU Prime would have won the PQC NIST contest. It's hard to evaluate this objectively when there are strong emotions involved.
- pixl97 4y agoWhen it comes to the number of times DJB is right versus the number of times that DBJ is wrong, I'll fully back DJB. Simply put the NSA/NIST cannot and should not be trusted in this case.
- bumper_crop 4y agoYou misread. I'm saying his reasons for filing are in question. NIST probably was being dishonest. That's not the reason there is a lawsuit though.
- throwaway654329 4y agoThey’re not in question for many people carefully tracking this process. He filed his FOIA before the round three results were announced. The lawsuit is because they refused to answer his reasonable and important FOIA in a timely manner. This is not unlike how they also delayed the round three announcement.
- deleted 4y ago[deleted]
- cosmiccatnap 4y agoIt's funny how often the bitterness of a post is used as an excuse to dismiss the long and well documented case being made.
- bumper_crop 4y agoIf NTRU Prime had been declared the winner, would this suit have been filed? It's the same contest, same people, same suspicious behavior from NIST. I don't think this suit would have come up. djb is filing this suit because of alleged bad behavior, but I have doubts that it's the real reason.
- politelemon 4y agoSo, question then, isn't one of the differences between this time's selection, compared to previous selections, that some of the algorithms are open source with their code available. For example, Kyber, one of the finalists, is here: https://github.com/pq-crystals/kyber https://github.com/pq-crystals/kyber And where it's not open source, I believe in the first round submissions, everyone included reference implementations. Does the code being available make it easy to verify whether there are some shady/shenanigans going on, even without NIST's cooperation?
- deleted 4y ago[deleted]
- lostcolony 4y agoNot really. For the same reason that "here's your github login" doesn't equate to you suddenly being able to be effective in a new company. You might be able to look things up in the code and understand how things are being done, but you don't know -why- things are being done that way. A lot of the instances in the post even show the NSA giving a why. It's not a particular convincing why, but it was enough to sow doubt. The reason to make all discussions public is so that there isn't an after the fact "wait, why is that obviously odd choice being done?" but instead a before the fact "I think we should make a change". The burden of evidence is different for that. A "I think we should reduce the key length for performance" is a much harder sell when the spec already prescribes a longer key length, than an after the fact "the spec's key length seems too short" "Nah, it's good enough, and we need it that way for performance". The status quo always has inertia.
- politelemon 4y agoThanks for the response, that's making sense. I've also tried following the PQC Google Groups but a lot of the language is beyond my grasp. Also... I don't understand why I've been downvoted for asking a question, I'm trying to learn but HN can certainly be unwelcoming to the 'curious' (which is why I thought we are here)
- aaaaaaaaaaab 4y ago
- tptacek 4y agoI may believe almost all of this is overblown and silly, as like a matter of cryptographic research, but I'll say that Matt Topic and Merrick Wayne are the real deal, legit the lawyers you want working on something like this, and if they're involved, presumably some good will come out of the whole thing. Matt Topic is probably best known as the FOIA attorney who got the Laquan McDonald videos released in Chicago; I've been peripherally involved in some work he and Merrick Wayne did for a friend, in a pretty technical case that got fierce resistance from CPD, and those two were on point. Whatever else you'd say about Bernstein here, he knows how to pick a FOIA lawyer. A maybe more useful way to say the same thing is: if Matt Topic and Merrick Wayne are filing this complaint, you should probably put your money on them having NIST dead-to-rights with the FOIA process stuff.
- encryptluks2 4y agoI have no doubt that they are great at their job, but when it comes to lawsuits the judge(s) are equally as important. You could get everything right but a judge has extreme power to interpret the law or even ignore it in select cases.
- NolF 4y agoI wouldn't say they ignore the law, but legislation like FOIA has a lot of discretion to balance competing interests and that's where a judge would make the most different despite all the great articulations of the most brilliant lawyers.
- tptacek 4y agoThere are very few public bodies that do a solid, to-the-letter job of complying with their open records requirements. Almost all FOIA failings are due to the fact that it isn't staffed adequately; FOIA officers, clerks, and records attorneys are all overworked. When you do a bunch of FOIA stuff, you get a feel for what's going on with the other side, and you build a lot of empathy (which is helpful in getting your data over the long run). And then other times you run into bloody-mindedness, or worse. I don't think NIST has many excuses here. It looks like they botched this straightforwardly. It's a straightforward case. My bet is that they'll lose it. The documents will get delivered. That'll be the end of it.
- taliesinb 4y agoWhy is the submission URL using http instead of https? That just seems... bizarre.
- CharlesW 4y agohttps://blog.cr.yp.to/20220805-nsa.html https://blog.cr.yp.to/20220805-nsa.html works too.
- effie 4y agoWhy? Http is simpler, less fragile, not dependent on good will of third parties, the content is public, and proving authenticity of text on Internet is always hard, even when served via the https scheme. I bet Bernstein thinks there is little point in forcing people to use https to read his page.
- z9znz 4y agoMITM could change what the client receives, right?
- effie 4y agoYes. But if you worry about being a target for MITM attacks, https alone does not fix that problem. You need some reliable verification mechanism that is hard to fool. The current CA system or "trust on first use" are only partial, imperfect mechanisms.
- oittaa 4y agoThat's just wrong on so many levels. Troy Hunt has an excellent explanation: https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs...
- effie 4y agoTroy Hunt points out that HTTP traffic is sometimes MITMed in a way that clients and servers do not like, and HTTPS sometimes prevents that. I never said otherwise. I am saying for certain kinds of pages, it's not a major concern. Like for djb website. Why not use HTTPS for everything? Because it also has costs, not just benefits.
- jcranmer 4y agoIf anyone is curious, the courtlistener link for the lawsuit is here: https://www.courtlistener.com/docket/64872195/bernstein-v-national-institute-of-standards-and-technology/ https://www.courtlistener.com/docket/64872195/bernstein-v-na... (And somebody has already kindly uploaded the documents to RECAP, so it costs you nothing to access.) Aside: I really wish people would link to court documents whenever they talk about an ongoing lawsuit.
- Natsu 4y ago> Aside: I really wish people would link to court documents whenever they talk about an ongoing lawsuit. I just want to second that and thank you for the link. Most reporting is just horribly bad at covering legal stuff because all the stuff that makes headlines that people click on is mostly nonsense.
- AndyMcConachie 4y agoAnd a big thank you to the wonderful people at the Free Law Project for giving us the ability to find and link to this stuff. They're a non-profit and they accept donations. (hint hint)
- tptacek 4y agoIt's just a vanilla FOIA lawsuit, of the kind hundreds of people file every month when public bodies fuck up FOIA. If NIST puts up any kind of fight (I don't know why they would), it'll be fun to watch Matt and Wayne, you know, win a FOIA case. There's a lot of nerd utility in knowing more about how FOIA works! But you're not going to get the secrets of the Kennedy assassination by reading this thing.
- chasil 4y agoI will draw to your attention two interesting facts. First, OpenSSH has disregarded the winning (crystals) variants, and implemented hybrid NTRU-Prime. The Bernstein blog post discusses hybrid designs. "Use the hybrid Streamlined NTRU Prime + x25519 key exchange method by default ("sntrup761x25519-sha512@openssh.com"). The NTRU algorithm is believed to resist attacks enabled by future quantum computers and is paired with the X25519 ECDH key exchange (the previous default) as a backstop against any weaknesses in NTRU Prime that may be discovered in the future. The combination ensures that the hybrid exchange offers at least as good security as the status quo." https://www.openssh.com/releasenotes.html https://www.openssh.com/releasenotes.html Second, Daniel Bernstein has filed a public complaint against the NIST process, and the FOIA stonewalling adds more concern and doubt that the current results are fair. https://www.google.com/url?q=https://groups.google.com/a/list.nist.gov/group/pqc-forum/attach/6f5422d4f193d/complaint-re-apon.pdf%3Fpart%3D0.0.1&sa=U&ved=2ahUKEwipx_av07H5AhUUhIkEHWReCvMQFnoECAcQAg&usg=AOvVaw1LzwGP-O8OkCw1IJjU96V5 https://www.google.com/url?q=https://groups.google.com/a/lis... What are the aims of the lawsuit? Can the NIST decision on crystals be overturned by the court, and is that the goal?
- thrway3344444 4y agoWhy is the link in the URL http: not https: ? Irony?
- cosmiccatnap 4y agoIf you spend all day making bagels do you go home and make bagels for dinner? It's a static text blog, not a bank
- theandrewbailey 4y agoThe NSA has recorded your receipt of this message.
- pessimizer 4y ago> It's a static text blog, not a bank I want those delivered by https most, because http leaks the exact page I've visited, rather than just the domain.
- effie 4y agoIf you care about preventing those kinds of leaks, do not use mainstream browsers (they are likely to leak even your https URLs to the browser company), and do not access those pages directly using your home connection (there may be mitms between you and the page).
- creatonez 4y agoSee: "Here's Why Your Static Website Needs HTTPS" by Troy Hunt https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs...
- sam0x17 4y agoWell https uses the NIST standards so.... ;)
- creatonez 4y agoThis is just due to the way that the OP posted it, not how it was originally published. This website forces HTTPS using ChaCha20-Poly1305 standard.
- theknocker 4y ago
- dt3ft 4y agoPerhaps the old advice (“never roll your own crypto”) should be reevaluated? If you’re creative enough, you could combine and apply existing algorithms in such ways that it would be very difficult to decrypt? Think 500 programmatic combinations (steps) of encryption applying different algorithms. Content encrypted in this way would require knowledge of the encryption sequence in order to execute the required steps in reverse. No amount of brute force could help here…
- TobTobXX 4y ago> Would require knowledge of the encryption sequence... This is security by obscurity. Reputable encryptions work under the assumption that you have full knowledge about the encryption/decryption process. You could however argue that the sequence then becomes part of the key. However, this key [ie. the sequence of encryptions] would then be at most as strong as the strongest encryption in this sequence, which kindof defeats the purpose.
- Tainnor 4y agoNo, an important property of a secure cryptographic cipher is that it should be as close to a random permutation of the input as possible. A "randomly assembled" cipher that just chains together different primitives without much thought is very unlikely to have that, which will mean that it will probably have "interesting" statistical properties that can be observed given enough plaintext/ciphertext pairs, and those can then be exploited in order to break it.
- anfilt 4y agoNo not at all, that advice is still good. Even more important if your are talking about modifying algorithms. Your gonna want proofs of resistance or immunity to certain classes of attacks. A subtle change can easily make a strong primitive useless.
- sgt101 4y agoyeah, but where do all these big primes come from?
- dataflow 4y agoTangential question: while some FOIA requests do get stonewalled, I continue to be fascinated that they're honored in other cases. What exactly prevents the government from stonewalling practically every request that it doesn't like, until and unless it's ordered by a court to comply? Is there any sort of penalty for their noncompliance? Tangential to the tangent: is there any reason to believe FOIA won't be on the chopping block in a future Congress? Do the majority of voters even know (let alone care enough) about it to hold their representatives accountable if they try to repeal it?
- Panzer04 4y agoPresumably most government employees are acting in good faith - why wouldn’t they fulfil a reasonable FOIA request? This is likely the result of some actors not acting in good faith, and so have no choice but to stonewall lest their intransigence be revealed.
- lupire 4y agoAll execs have to do is not staff the FOIA department, and requests get ignored. People generally prefer free time to doing paperwork, if boss allows.
- linuxandrew 4y agoI know someone who works in gov (Australia, not US) who told me all about a FOI request that he was stonewalling. From memory, the request was open ended and would have revealed more than it possibly intended it to, and would have revealed some proprietary trade secrets from a third party contractor. That said, it was probably a case that would attract some public interest. The biggest factors preventing governments from stonewalling every FOI case are generally time and money. Fighting FOI cases is time consuming and expensive and it's simply easier to hand over the information.
- dataflow 4y agoInteresting, thanks for the anecdote! > The biggest factors preventing governments from stonewalling every FOI case are generally time and money. Is there any backpressure in the system to make the employee(s) responsible for responding/signing off on the disclosure actually care about how expensive it is to fight a case? I would've thought they would think, "Well, the litigation cost doesn't affect me, I just approve/deny requests based on their merits."
- thorwayham 4y agodig @1.1.1.1 blog.cr.yp.to is failing for me, but 8.8.8.8 works. Annoying!
- ehzy 4y agoIronically, when I visit the site Chrome says my connection is not secured by TLS.
- kzrdude 4y agoI was hoping for chacha20+Poly1305
- ziddoap 4y agoYou can see for yourself if you visit the HTTPS version. >Connection Encrypted (TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256, 256 bit keys, TLS 1.2)
- encryptluks2 4y agoAre you logging into the site?
- bsaul 4y agoside question : I've only recently started to digg a bit deeper into crypto algorithms ( looking into various types of curves etc), and it gave me the uneasing feeling that the whole industry is relying on the expertise of only a handful of guys to actually ensure that crypto schemes used today are really working. Am i wrong ? are there actually thousands and thousands of people with the expertise to actually proove that the algorithms used today are really safe ?
- deleted 4y ago[deleted]
- benlivengood 4y agoThere may be thousands of people in the entire world who understand cryptanalysis well enough to accurately judge the security of modern ciphers. Most aren't living or working in the U.S. It's very difficult to do better. The mathematics is complex and computer science hasn't achieved proofs of the hypotheses underlying cryptography. The best we can achieve is heuristic judgements about what the best possible attacks are, and P?=NP is an open question.
- Tainnor 4y ago> The mathematics is complex and computer science hasn't achieved proofs of the hypotheses underlying cryptography. No unconditional proofs (except for the OTP ofc), but there are quite a few conditional proofs. For example, it's possible to show that CBC is secure if the underlying block cipher is.
- NavinF 4y agoMost programmers don't need to prove crypto algorithms. There are many situations where you can just use TLS 1.3 and let it choose the ciphers. If you really need to build a custom protocol or file format, you can still use libsodium's secretbox, crypto_box, and crypto_kx functions which use the right algorithms.
- ziddoap 4y ago
- ForHackernews 4y agoMaybe this is too much tinfoil hattery, but are we sure DJB isn't a government asset? He'd be the perfect deep-cover agent.
- throwaway654329 4y agoPlease don’t do the JTRIG thing. Dan is a national treasure and we would be lucky to have more people like him fighting for all of us. Between the two, material evidence shows that NIST is the deep-cover agent sabotaging our cryptography.
- temptemptemp111 4y ago
- rethinkpad 4y agoThough 99% of the time I would agree with you, the public has to have faith in people who claim to be fighting (with previously noted successes in Bernstein v. US) in our best interests.
- temptemptemp111 4y ago
- lizardactivist 4y agoAn expert, prominent, and someone who the whole cryptography community listens to, and he calls out the lies, crimes, and blatant hypocrisy of his own government. I genuinely fear that he will be suicided one of these days.
- ok_dad 4y agoI think the United States is more about charging people with crimes and ruining their lives that way rather than disappearing people. Russia might kill you with Polonium and make sure everyone knows it, but America will straight up “legally“ torture you in prison via several means and then argue successfully that those methods were legal and convince the world you weren’t tortured. Anyone who’s a target for that treatment, though, knows that’s a lie.
- danuker 4y agoMcAfee and Epstein pop to mind. Maybe also Aaron Swartz.
- oittaa 4y agoIt seems silly to me how so many people immediately dismiss anyone even suggesting that something fishy was going on with those cases, when we already know about MKUltra, Tuskegee expirement, etc.
- discordance 4y agoAssange too.
- danuker 4y agoNot yet. Maybe he will survive to come out the other end, like Chelsea Manning.
- discordance 4y ago
- pyuser583 4y agoPlease include links with https:// https://
- jacooper 4y agoFlippo valrosida and Matthey green aren't too happy. https://twitter.com/matthew_d_green/status/1555683856262520834 https://twitter.com/matthew_d_green/status/15556838562625208...
- jeffparsons 4y agoI think this is a sloppy take. If you read the full back-and-forth on the FOI request between D.J. Bernstein and NIST, it becomes readily apparent that there is _something_ rotten in the state of NIST. Now of course that doesn't necessarily mean that NIST's work is completely compromised by the NSA (even though it has been in the past), but there are other problems that are similarly serious. For example, if NIST is unable to explain how certain key decisions were made along the way to standardisation, and those decisions appear to go against what would be considered by prominent experts in the field as "good practice", then NIST has a serious process problem. This is important work. It affects everyone in the world. And certain key parts of NIST's decision making process seem to be explained with not much more than a shrug. That's a problem.
- tptacek 4y agoAll you're saying here is that NIST failed to comply with FOIA. That's not unusual. No public body does a reliably good job of complying with FOIA, and many public bodies seem to have a bad habit of pre-judging the "merits" of FOIA requests, when no merit threshold exists for their open records requirements. NIST failing to comply with FOIA makes them an intransigent public body, like all the rest of them, from your local water reclamation board to the Department of Energy. It emphatically does not lend support to any of this litigants concerns about the PQC process. I don't know enough (really, anything) about the PQC "contest" to judge claims about its validity, but I do know enough --- like, the small amount of background information needed --- to say that it's risible to suggest that any of the participating teams were compromised by intelligence agencies; that claim having been made in this post saps its credibility. So, two things I think a reasonable person would want to establish here: first, that NIST's behavior with respect to the FOIA request is hardly any kind of smoking gun, and second that the narrative being presented in this post about the PQC contest seems somewhere between "hand-wavy" and "embarrassing".
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- benreesman 4y agodjb has got to be the single biggest pain in the ass for the NSA and I love it.
- josh2600 4y agoI just want to say, the problem here is worldwide standards bodies for encryption need to be trustworthy. It is incredibly hard to know what encryption is actually real without a deep mathematics background and even then, a choir of peers must be able to present algorithms, and audits of those algorithms with a straight face. Presenting broken-by-design encryption undermines public confidence in what should be one of our most sacrosanct institutions: the National Institute of Standards and Technology (NIST). Many enterprises do not possess the capability to audit these standards and will simply use whatever NIST recommends. The danger is that we could be engineering embedded systems which will be in use for decades which are not only viewable by the NSA (which you might be ok with depending on your political allegiance) but also likely viewable by any capable organization on earth (which you are probably not ok with irrespective of your political allegiance). In short, we must have trustworthy cryptography standards. If we do not, bedlam will follow. Please recall, the last lawsuit that DJB filed was the one that resulted in essentially "Code is speech" in our world (https://en.wikipedia.org/wiki/Bernstein_v._United_States https://en.wikipedia.org/wiki/Bernstein_v._United_States).
- bananapub 4y agohow could NIST possibly be "one of our most sacrosanct institutions" after the NSA already fucked them with Dual_EC_DRBG? whoever wants to recommend standards at any point since 2015 needs to be someone else https://en.wikipedia.org/wiki/NIST_SP_800-90A https://en.wikipedia.org/wiki/NIST_SP_800-90A for this who have forgotten.
- josh2600 4y agoLook, my point is that there are lots of companies around the world who can’t afford highly skilled mathematicians and cryptographers on staff. These institutions rely on NIST to help them determine what encryption systems may make sense. If NIST is truly adversarial, the public has a right to know and determine how to engage going forward.
- tptacek 4y agoThey don't have to (and shouldn't) retain highly skilled mathematicians. Nobody is suggesting that everyone design their own ciphers, authenticated key exchanges, signature schemes, and secure transports. Peer review is good; vital; an absolute requirement. Committee-based selection processes are what's problematic.
- kvetching 4y ago
- dang 4y agoWe ban accounts that post like this, so please don't. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- deleted 4y ago[deleted]
- elif 4y agoPerhaps the best way to build trust in a cryptographic algorithm is to have it devised by certifiably neutral general purpose mathematic neural net. It could even generate an algorithm so complicated it would be close to impossible for a human mind to comprehend the depth of it.
- tooltower 4y ago"Certifiably neutral" So, by a process that hasn't been designed yet. Especially when one considers how opaque most neutral nets are to human scrutiny.
- elif 4y agoI mean, if the source, training data, and query interface are public, it would be insanely difficult to hide a backdoor There i "designed" your impossible criterion in just a few obvious steps you could have inferred
- tooltower 4y agoThere are many, many papers that show how you can make innocuous changes to inputs to make neutral nets produce the wrong result. You might be overestimating the difficulty of this process.
- elif 4y agoCould be worse. At least I don't dismiss entire classes of problems simply because they sound hard.
- creatonez 4y ago> It could even generate an algorithm so complicated it would be close to impossible for a human mind to comprehend the depth of it. Okay... then some nefarious actor's above-human-intelligence neural network instantly decodes the algorithm deemed too complicated for human understanding? I don't see how opaque neural nets are suddenly going to make security-through-obscurity work.
- sigil 4y agoNear the end of the post – after 50 years of axe grinding – djb does eventually get to the point wrt pqcrypto. I find the below excerpt particularly damning. Why not wrap nascent pqcrypto in classical crypto? Suspect! -- The general view today is that of course post-quantum cryptography should be an extra layer on top of well-established pre-quantum cryptography. As the French government cybersecurity agency (Agence nationale de la sécurité des systèmes d'information, ANSSI) put it at the end of 2021: Acknowledging the immaturity of PQC is important: ANSSI will not endorse any direct drop-in replacement of currently used algorithms in the short/medium term. However, this immaturity should not serve as an argument for postponing the first deployments. ANSSI encourages all industries to progress towards an initiation of a gradual overlap transition in order to progressively increase trust on the post-quantum algorithms and their implementations while ensuring no security regression as far as classical (pre-quantum) security is concerned. ... Given that most post-quantum algorithms involve message sizes much larger than the current pre-quantum schemes, the extra performance cost of an hybrid scheme remains low in comparison with the cost of the underlying post-quantum scheme. ANSSI believes that this is a reasonable price to pay for guaranteeing an additional pre-quantum security at least equivalent to the one provided by current pre-quantum standardized algorithms. But NSA has a different position: it says that it "does not expect to approve" hybrids. Publicly, NSA justifies this by - pointing to a fringe case where a careless effort to add an extra security layer damaged security, and - expressing "confidence in the NIST PQC process". Does that mean the original NISTPQC process, or the current NISTPQC process in which NIST, evidently surprised by attacks, announced plans to call for new submissions? Of course, if NSA/IDA have secretly developed an attack that works for a particular type of post-quantum cryptosystem, then it makes sense that they'd want people to start using that type of cryptosystem and turn off the existing pre-quantum cryptosystem.
- tptacek 4y agoThis is the least compelling argument Bernstein makes in the whole post, because it's simply not the job of the NIST PQC program to design or recommend hybrid classical/PQC schemes. Is it fucky and weird if NSA later decides to recommend against people using hybrid key establishment? Yes. Nobody should listen to NSA about that, or anything else. But NIST ran a PQC KEM and signature contest, not a secure transport standardization. Sir, this is a Wendy's.
- dmix 4y agoThis is one hell of a well written argument.
- frogperson 4y agoSeems odd to me a crypto blog isn't using https these days.
- mramadany 4y ago
- dang 4y agoWe detached this subthread from https://news.ycombinator.com/item?id=32363982 https://news.ycombinator.com/item?id=32363982.
- tptacek 4y agoYou could not have less of an idea of what you're talking about here.
- pvg 4y agoThis isn't the sort of shit you can start here, take a look at https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- mramadany 4y agoIf you think I went around looking to dig up dirt, I didn't. I just searched djb's name on Twitter to find more discussions about the subject, as post-quantum cryptography is an area I'm curious about. Regarding asking for a disclosure, I thought that was widely accepted around here. If the CEO of some company criticised a competitor's product, we would generally expect them to disclose that fact upfront. I thought that was appropriate here given the dismissive tone of GP.
- pvg 4y agoIf you think I went around looking to dig up dirt It doesn't matter, you can't toss stuff like that at people here, never mind characterize it the way you did, as a form of argument. It's in the guidelines, there are lots of moderator comments bout it, don't be doing it. I thought that was appropriate here given the dismissive tone of GP. It's not, no matter how 'dismissive' you think a comment is.
- 4y ago
- er4hn 4y ago> The same people tend to have trouble grasping that most of the vulnerabilities exploited and encouraged by NSA are also exploitable by the Chinese government. These people start with the assumption that Americans are the best at everything; ergo, we're also the best at espionage. If the Chinese government stole millions of personnel records from the U.S. government, records easily usable as a springboard for further attacks, this can't possibly be because the U.S. government made a policy decision to keep our computer systems "weak enough to still permit an attack of some nature using very sophisticated (and expensive) techniques". I'm not sure if I understand this part. I was under the impression that the OPM hack was a result of poor authn and authz controls, unrelated to cryptography. Was there a cryptography component sourced somewhere?
- danielheath 4y agoIf, rather than hoarding offensive tools & spying, the NSA had interpreted its mission as being to harden the security of government infrastructure (surely even more firmly within the remit of national security) and spent its considerable budget in that direction, would authn and authz controls have been used at the OPM?
- woodruffw 4y agoThis is my understanding as well. I asked this very same question less than a week ago[1], and now it's the first Google result when you search "OPM Dual_EC_DRBG." The response to my comment covers some circumstantial evidence. But I'm not personally convinced; human factors are a much more parsimonious explanation. [1]: https://news.ycombinator.com/item?id=32286528 https://news.ycombinator.com/item?id=32286528
- graderjs 4y agoSo the TLDR is… you do roll your own crypto? I mean you probably need to know how to create a RNG that passes Practrand and smasher first and also a hash function that does the same but cool.
- efitz 4y agoWhy don’t we invert FOIA? Why don’t we require that all internal communications and records be public, available within 24 hours on the web, and provide a very painful mechanism involving significant personal effort of high level employees for every single communication or document that is to be redacted in some way? The key is requiring manual, personal (non-delegatable) effort on the part of senior bureaucrats, and to allow a private cause of action for citizens and waiver of immunity for bureaucrats. We could carve out (or maybe not) specific things like allowing automatic redaction of employee PII and PII of citizens receiving government benefits. After many decades, it’s clear that the current approach to FOIA and sunshine laws just isn’t working. [ed] fixed autocorrect error
- voz_ 4y ago
- efitz 4y agoWe should rethink the concept of a “secret”. If it’s really a secret, it will still be worth the effort to protect.
- acover 4y agoThey are erroring on the side of caution because people have determined secret information from public information - like the energy in a nuclear bomb (censored) by the blast radius (public). Another example is they want to protect their means and methods. But those means and methods are how they know most information. Often times it's easy to work backwards from they know x therefore y is compromised. It's a hard problem similar to how to release anonymized data. See K-anonymity attacks and caveats. https://en.wikipedia.org/wiki/K-anonymity https://en.wikipedia.org/wiki/K-anonymity
- vasco 4y agoDo you think it's tough for those regimes to pay someone to do FOIA requests for them? Or to get jobs at government agencies?
- 4y ago
- rnhmjoj 4y agoIf there's the suspiscion that NIST interests aren't aligned with the public ones (at least wrt cryprography, I hope they're at least honest with the physical constants), why do we still allow them do dictate the standards? I mean, there's plenty of standards bodies and experts in the cryptography community around the world that could probably do a better job. At this point NIST should be treated as a compromised certificate authority: just ignore them and move along.
- sylware 4y agoI have the feelings the govs around the world get more and more sued related to serious digital matters. Here, once the heat wave is finally over, I will see again my lawyer about the interoperability of gov related sites with noscript/basic (x)html browsers.
- tomgs 4y agoMy background is in normal, enterprise-saas-style software development projects, and the whole notion of post-quantum crypto kind of baffles me. Funnily enough, this post coincides with the release of a newsletter issue[0] by a friend of mine - unzip.dev - about lattice-based cryptography. A bit of a shameless plug, but it really is a great bit of intro for noobs in the area like myself. [0] https://unzip.dev/0x00a-lattice-based-cryptography/ https://unzip.dev/0x00a-lattice-based-cryptography/
- aaaaaaaaaaab 4y ago
- ris 4y agoThere are ways of writing that make one look less like a paranoid conspiracy theorist.
- londons_explore 4y agoSo... Common pattern:. NSA, it's representatives or affiliates make claims that longer key lengths are unnecessary or have too much of a performance cost. So... I make the claim again. Let's multiply all key lengths by 10. Ie. 2048 bit RSA becomes 20480 bit RSA. Who here thinks that's a bad idea? Previously on HN such ideas have been downvoted and comments have been made against them. I wonder, who has it been doing that, and what were their motives?
- londons_explore 4y agoSo this lawsuit is to try and force the release of some documents that might be embarrassing. However, if the lawsuit is won, I would think it very unlikely the documents aren't rewritten 'on national security ' grounds before release. So nothing will be learned either way.
- timcavel 4y ago