5 ms·
so the cynical view here would be that the backdoor was discovered before the algorithm could get widely deployed?
by xt00 4y ago
so the cynical view here would be that the backdoor was discovered before the algorithm could get widely deployed?
- DarkmSparks 4y agoMy super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they always seem to get down voted :( like being cynical when it comes to encryption is a bad thing.....
- olliej 4y agoQuantum safe crypto isn’t FUD, NIST’s steadfast refusal to specify a dual system, especially given their historical laundering of NSA back doors is super questionable, but there exist (at least one that I know of) crypto systems that have no exploitable bias. The problem is the impractically large key sizes. Afaict a lot of pqc work is trying to reduce the key sizes to something reasonable.
- tptacek 4y agoHorseshit. It's literally not NIST's job to design a "dual system"; the project was to standardize PQC constructions, not whole protocols. Everybody that deploys PQC anywhere is going to deploy "dual systems". This complaint is like claiming NIST is corrupt because they didn't standardize an authenticated key exchange along with SHA-3.
- olliej 4y agoIt is literally NIST’s job to define the standards that people are meant to use. What you’re saying is that NIST not considering a dual system standard is fine because no one would consider relying solely on the standardized PQC algorithms and would obviously implement their own version of a dual system, only with less understanding of potential pitfalls or analysis for weaknesses.
- tptacek 4y agoNo. Once again: the NIST PQC competition is a project to standardize post-quantum cryptography constructions. It's not a protocol competition, any more than the AES and SHA-3 competitions were. This is literally spelled out on the competition page. I'm having trouble how anyone could have any confusion about this. It literally says: do hybrid systems if you want, that's outside the scope of this competition. How would it even have made sense to pursue hybrid systems in this competition? Like how would that have actually worked?
- api 4y agoNIST/FIPS allows HMAC(salt, key) where salt can be anything, so a dual system is trivial: HMAC(PQ secret, conventional secret).
- jabbany 4y ago> Its felt like FUD based on FUD for a while. Not really...? Quantum stuff is real, there are real quantum computers that have been demonstrated to really do quantum operations. They're not close to being usable to break crypto yet, but it certainly makes sense to get ahead of it. > There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... These are completely different problems. Encryption just keeps information confidential. By itself, it offers no _security_ guarantees. Even the strongest encryption would be moot against a keylogger. Crypto can be (and is being) used to provide some security, like via signed code, secure processors, and the such, but security is a multi-tiered thing -- you want all the protection you can get, and like keeping data encrypted at rest, air-gapping is just yet another layer of protection.
- spywaregorilla 4y agoquantum is used for problems like finding the factorization of the number 4. Jumping is also real, but we need not worry about people jumping out of the atmosphere.
- jabbany 4y ago> Jumping is also real, but we need not worry about people jumping out of the atmosphere. If people are jumping twice as high this year than last, we would ;) https://www.researchgate.net/figure/A-chart-shows-the-progress-of-quantum-computer-with-numbers-Quantum-Bits-Source-75_fig1_342377828 https://www.researchgate.net/figure/A-chart-shows-the-progre... (BTW this reply is not meant to make a point about the state of quantum -- it's complicated -- but merely as a response to the analogy)
- spywaregorilla 4y agoI'm not much of a believer. It's worth pointing out that as the number of qubits goes up, so too does the error rate.
- luc4 4y ago
- stjohnswarts 4y agoThis is a place where Hanlon's razor applies much better than assuming they want weak encryption.
- MacsHeadroom 4y agoIt really isn't, when the annual budget for states crippling cryptographic standards dwarfs the salaries and tuition of everyone in the global academics maths community combined.
- franknstein 4y agoThere is seemingly random interconnectedness in math, meaning that governments probably can't just throw money at some problem and force themselves much deeper than academia. For example you can hire 100 number theorists and ask of them to solve factorization (stupid example, i know), but it just might happen that the key insight to solving it comes from some random dude working in some seemingly disconnected problem in combinatorial algebra or something.
- kibwen 4y ago> My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption Not a cryptographer, but surely if you're worried about this then you could first encrypt your data using classical algorithms and then encrypt the output of that via the PQC algorithms, to produce a ciphertext that is at least no less safe than the classical encryption alone.