7 ms·
"All we can do is tell people that NIST are the ones in the room making the decisions, but if you don't believe us, there's no way you could verify that withou
by nonrandomstring 3y ago
"All we can do is tell people that NIST are the ones in the room
making the decisions, but if you don't believe us, there's no way
you could verify that without being inside NIST" says Moody.
There's our problem - right there!
If a body as important as NIST is not so utterly transparent that any
random interested person cannot comb through every meeting, memo, and
coffee break conversation then it needs disbanding and replacing with
something that properly serves the public.
We have bastardised technology to create a world of panopticonic
surveillance, and then misused it by scrutinising the private lives of
simple citizens.
This is arse-backwards. If monitoring and auditing technology has any
legitimate use the only people who should morally (though willingly)
give-up some of their privacy are those that serve in public, in our
parliaments, councils, congress, government agencies and standards
bodies.
> All we can do is tell people
No. You can prove it, and if you cannot, step aside for leadership
better suited to serving the public interest.
- devmor 3y agoThe fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.
- tptacek 3y agoNIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.
- gmerc 3y agoThe man walked into a bank many times over his life, no way he could decide to rob it one day.
- mesebrec 3y agoYou are creating a strawman. The original argument is not "they created encryption that isn't broken before". The argument is "encryption created by competitions that are only refereed by NIST is trustworthy"
- gmerc 3y agoSo it’s worse. They already robbed a bank in the past.
- stock_toaster 3y agoAnd lest we forget Dual_EC_DRBG
- conradludgate 3y agoSHA3 is fine but it's so slow, I don't many people that use it
- xeyownt 3y agoSlow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.
- lazide 3y agoFaster than Blake2/3? Not even close!
- throw0101c 3y ago> Faster than Blake2/3? Not even close! Blake2 was not created (December 2012) until after the SHA-3 competition, which ended on October 2012 (Keccak being the winner). It was Blake1 that was entered. Blake3 was released in 2020. I'm sure a Keccak2/3 could have also been better than the original Keccak1, but that was not available either.
- lazide 3y agoYou never specified timing. You made a blanket statement as if it was still true.
- tux3 3y agoComparable in software, to what? Password hashes? :)
- formerly_proven 3y agoLast I checked SHA3-512 is like 4x slower than SHA2-512 on x86.
- throw0101c 3y ago
- londons_explore 3y agoA competition is the perfect way to subvert a standard. A competition looks 'open', but in fact you can 'collaborate' with any team to make your weakened encryption and then persuade the judging panel to rate it highly.
- denton-scratch 3y agoBut the competition process looks weird to me. Aparently it's not like a sports fixture, where the rules are set before the competition, and the referee just enforces the rules; this referee adjusts the rules while the competition is underway. NIST has form for juking the standards, or at least for letting the NSA juke them. If they're not completely transparent, then any standard they recommend is open to question, which isn't good for a standard.
- Yeul 3y agoThe American people- who are the only ones who matter- want to live in a superpower. Everything America does is in service of maintaining its position as the hegemonic player. The US intelligence agencies have infiltrated every university and tech company since forever. It's their job.
- k12sosse 3y agoSlava America
- manonthewall 3y agoSounds like it's time that academia form a crypto equivalent of NIST amongst universities so they can put out transparent versions of new cryptographic algorithms that can be traced back to their birth so that other cryptographers can look for holes, if NIST is unwilling to be open about their processes.
- tptacek 3y agoWhy aren't other participants in the competition --- most of them didn't win! --- saying the same thing? Why are the only two kinds of people making this argument a contest loser writing inscrutable 50,000 word manifestos and people on message boards who haven't followed any of the work in this field?
- RandomLensman 3y agoSo 24x7 surveillance with anything gathered visible to anyone for any person working there on this stuff? Would anyone take such jobs?
- rho138 3y agoEvery US government office - at both the state and federal - levels has records keeping requirements. It’s the reason we can submit FOIA requests that return with data from the 30s.
- RandomLensman 3y agoIs every conversation in a rest room recorded and available? If you don't trust people creating cryptography standards you cannot really leave gaps, can you?
- hugh-avherald 3y agoMost officials communicate in ways that circumvent FOIA.
- LinuxBender 3y agoAdding to this FOIA doesn't guarantee useful answers. Having gone through the process whilst in the military I found a few loopholes. They can give a bloated answer with boxes and boxes of useless mostly unrelated information. They did this to me. They can also decline to answer and just say it's classified. They can also just decline to answer through stalling tactics. It served my purpose and that was to stall them from collecting DNA.
- willcipriano 3y agoHillary Clinton's email server is a famous example of attempting to avoid FOIA requests.
- ethbr1 3y agoFrom what I hear, it's also an example of how ineptly run the State Dept's IT systems were. Complex tasks like "set up a new computer" had months of lead time.
- electrozav 3y agoI'm now picturing a slightly different government to ours, where the oversight bodies have the additional function of making sure officials don't talk to one another outside of recorded meetings under the public's eye. It seems like a huge burden. It is the kind of thing, though, that in a parallel universe would make total sense: our representatives should be beholden to us.
- ethbr1 3y agoOTOH, ensuring our representatives are 100% beholden to us also means screaming in the next primary about every bipartisan deal made. Which has the net effect of decreasing the ability to reach nobody-is-happy compromises. Which is something else people say they want. I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well.
- nonrandomstring 3y ago> I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well. I hear that, and there's a case for it. Diplomacy, maneuvering and negotiation require secrets and enclaves. So to allow for that you need a few things; - Strict official records of affairs - Strong penalties for fraud, malinfluence, intimidation - Whistleblower protection The last of these essential checks-and-balances has gone to shit our culture. Even if we pardoned Edward Snowden and made him a "hero of democracy" tomorrow, it's still a mountain of work to restore the essential sense of civic responsibility, patriotism and duty that allows those people who discover or witness corruption to step-up and challenge it safe in the knowledge that the law and common morality are on their side.
- ethbr1 3y agoBillions (the tv show), of all places, made a somewhat similar argument in favor of post-hoc investigations, in the last episode. Record and share everything immediately = no room for deals Record nothing = too much room for corruption So we land at... record everything + only review with just cause + strict whistleblower protections. Which seems a nice splitting of the matter, but requires a strong, independent third party (e.g. judicial branch) to arbitrate access requests. With tremendous pressure and incentives to breach that limit.
- breakwaterlabs 3y agoIt seems wildly shortsighted as well. I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust that it can spend on very narrow issues. But over the years there have been enough strange things (Dual EC DRBG being the most notorious) that that trust, at least when it comes to crypto design, simply isn't there. My perception is that newer ECC standards promoted by NIST have been trusted substantially less than AES was when it was released, and I can think of a number of major issues over the years that would lead to this distrust. The inevitable outcome is that NIST loses much of its influence on the industry, which certainly is not in its own interest.
- nonrandomstring 3y ago> view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor. Without any /sarcasm tags I have to take that on face value, and frankly there are few words to fully describe what a colossally stupid idea (not your idea, I am sure) that is. Belief in containable backdoors is the height of naivety and recklessly playing fast and loose with everyone's personal security, our entire economy and national security. That is to say, even taking Hollywood Terror Plots into consideration [0], I don't believe there is ever a "mandate to insert a backdoor". > In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust that it can spend on very narrow issues. Having some "trust to burn" is great for lone operatives, undercover mercs, double agents and crooks that John le Carre described as fugitives living by the seat of expedient alliances and fast goodbyes. Fine if you can disappear tomorrow, reinvent yourself and pop up somewhere else anew. But absolutely no use for institutions holding on to any hope for permanence and the power that brings. > The inevitable outcome is that NIST loses much of its influence on the industry, which certainly is not in its own interest. Exactly this. And corrosion of institutional trust is a massive loss. Not for NIST or a bunch of corrupt academics who'd stop getting brown envelopes to stuff their pockets, but for the entire world. But since you obliquely raise an interesting question... what is NIST's "interest" here? Surely we're not saying that by spending trust "on very narrow issues" it's ultimate ploy is to deceive, defect and double-cross everything the public believe it was created to protect? [1] I'm all for the game, subterfuge and craft, but sometimes you just bump up against the brute reality of principles and this is one of those cases. Backdoors always cost you more than you ever thought you'd save, and I've always assumed the people at a place like NIST are smart enough to know that. [0] https://www.schneier.com/essays/archives/2005/09/terrorists_dont_do_m.html https://www.schneier.com/essays/archives/2005/09/terrorists_... [1] https://cybershow.uk/episodes.php?id=16 https://cybershow.uk/episodes.php?id=16
- api 3y agoModern panopticon level surveillance is not deployed through weakening encryption. It's just built right into platforms and apps and people willfully install it because it gives them free services and addictive social media feeds. You don't need to weaken encryption to spy on people. You just have to give them a dancing bunny and to see the dancing bunny they must say yes to "allow access to contacts" and "allow access to camera" and "allow access to microphone" and "allow access to documents" and ... For the higher-brow version replace dancing bunny with free service. In addition the more we adopt and make use of cloud command and control architectures the more surveilled we become, because it becomes trivial for anyone with access to the cloud provider's internals to tap everyone's behavior. This could be done with or without the knowledge of the provider itself. The more such services we use the more data points we are surrendering, and these can be aggregated to provide quite a lot of information about us in near-real-time.
- nonrandomstring 3y ago> In addition the more we adopt and make use of cloud command and control architectures the more surveilled we become, because it becomes trivial for anyone with access to the cloud provider's internals to tap everyone's behavior. Spoke about this last night in London https://www.youtube.com/watch?v=mcWIQALtOtg https://www.youtube.com/watch?v=mcWIQALtOtg