6 ms·
The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised. Frankly, I would assume any m
by devmor 3y ago
The fact that NIST is not transparent is enough to assume that anything related to cryptography that NIST touches is compromised.
Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.
- tptacek 3y agoNIST standardized AES and SHA3, two designs nobody believes are compromised. The reason people trust AES and SHA3 is that they're the products of academic competitions that NIST refereed, rather than designs that NSA produced, as was the case with earlier standards. CRYSTALS-Kyber is, like AES and SHA3, the product of an academic competition that NIST simply refereed.
- gmerc 3y agoThe man walked into a bank many times over his life, no way he could decide to rob it one day.
- mesebrec 3y agoYou are creating a strawman. The original argument is not "they created encryption that isn't broken before". The argument is "encryption created by competitions that are only refereed by NIST is trustworthy"
- gmerc 3y agoSo it’s worse. They already robbed a bank in the past.
- stock_toaster 3y agoAnd lest we forget Dual_EC_DRBG
- conradludgate 3y agoSHA3 is fine but it's so slow, I don't many people that use it
- xeyownt 3y agoSlow? Fastest in HW, and comparable performance in SW. Moreover if you take into account security hardening, SHA3 is easier to protect than alternatives.
- lazide 3y agoFaster than Blake2/3? Not even close!
- throw0101c 3y ago> Faster than Blake2/3? Not even close! Blake2 was not created (December 2012) until after the SHA-3 competition, which ended on October 2012 (Keccak being the winner). It was Blake1 that was entered. Blake3 was released in 2020. I'm sure a Keccak2/3 could have also been better than the original Keccak1, but that was not available either.
- lazide 3y agoYou never specified timing. You made a blanket statement as if it was still true.
- tux3 3y agoComparable in software, to what? Password hashes? :)
- formerly_proven 3y agoLast I checked SHA3-512 is like 4x slower than SHA2-512 on x86.
- throw0101c 3y ago
- londons_explore 3y agoA competition is the perfect way to subvert a standard. A competition looks 'open', but in fact you can 'collaborate' with any team to make your weakened encryption and then persuade the judging panel to rate it highly.
- denton-scratch 3y agoBut the competition process looks weird to me. Aparently it's not like a sports fixture, where the rules are set before the competition, and the referee just enforces the rules; this referee adjusts the rules while the competition is underway. NIST has form for juking the standards, or at least for letting the NSA juke them. If they're not completely transparent, then any standard they recommend is open to question, which isn't good for a standard.
- Yeul 3y agoThe American people- who are the only ones who matter- want to live in a superpower. Everything America does is in service of maintaining its position as the hegemonic player. The US intelligence agencies have infiltrated every university and tech company since forever. It's their job.
- k12sosse 3y agoSlava America