5 ms·
Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him".
by peppermint_gum 3y ago
Whenever the topic of DJB vs NIST comes up, there are always people saying "this may look petty, but he has a spotless track record, so we have to trust him".
I want to push back on this a little by linking this Twitter thread:
https://nitter.net/FiloSottile/status/1555669786826244096 https://nitter.net/FiloSottile/status/1555669786826244096
It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers.
It's entirely possible to be a brilliant cryptographer and also a petty person, those things aren't mutually exclusive.
- moefh 3y agoI did not dig through all the links in that twitter thread, but the first few tweets are pretty misleading. The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far ahead of what's being submitted that all they have to do is push NIST to pick an algorithm they know how to break. Now, I have no knowledge of any of this, so I have no idea if DJB's argument is insanely paranoid like the author of the thread implies (with the GIF in the 3rd tweet). All I can see is that the author's claim is a gross mischaracterization of what DJB wrote.
- denton-scratch 3y ago> no idea if DJB's argument is insanely paranoid Isn't paranoia an essential job requirement for cryptographers?
- Aachen 3y agoCryptography: <reference> is incorrect because <logic> and should therefore be <statement>. This allows a ciphertext produced by X to be breakable in 2²¹ operations when 2¹¹ messages are known to the attacker. Paranoia: NSA bribes the independent reviewers and is backdooring the whole thing because everyone knows the military and intelligence services are two decades ahead of public research and we just don't know what the algorithm flaw is yet, but I'm telling you, they're keeping something behind! I am not saying djb (or anyone) does the latter, example is given exaggerated for illustrative purposes only. The cryptographer's example is also exaggerated, as it does matter how algorithms are chosen and there's a measure of subjectivity involved. Still, I would not say that paranoia is the job of a cryptographer.
- Ar-Curunir 3y agoSpeaking as a cryptographer, a healthy amount of paranoia is good and necessary. DJB's level of paranoia re: Kyber and lattices is bordering on delusion.
- michael1999 3y agoIt isn’t paranoia when the NSA has been caught with their hand in the cookie jar before. There is no obligation to give known liars the benefit of the doubt.
- conradev 3y agoThank you for posting this – it is important context: "When his schemes won’t get picked by NIST, people will think it’s because they are not backdoored, and will point at the FOIA lawsuit as evidence."
- Aachen 3y agoThere is so much to unpack in that thread and its references. A lot of he said she said. For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not from the company themselves, and keeps things confidential. It's how we resolve the conflict where you can't just claim you're sick for unspecified reasons indefinitely and continue to expect money, but the employer isn't entitled to know your medical dossier either. This lets you have medical confidentiality and long-term sick leave where the employer can trust that appropriate action is being taken because they trust the impartial doctor to verify that. This is brought up as part of the conflict between djb, the author, and the university they work for. This isn't the only thing they allude to not knowing about while abuse was alleged to be allowed to happen by djb and others. I believe most of what is written, but at the same time, the problem is clearly being exacerbated by not using coworkers, friends, or even google/ddg to find out what legal system you've moved into. Djb even suggested they should take legal action, and HR offered arbitration, but the person declined both. So now the evidence amounts to their word on a blog and the alleged perpetrators faced zero consequences. As much as such references serve to convince me of djb=evil, they also convince me there may be more to the story than one side. Obviously I've just highlighted one thing here, there's a lot more he-said-she-said going on elsewhere in the threads that could give one pause in believing one side verbatim, even if they're likely right in spirit
- FiloSottile 3y agoFWIW, I don't believe Bernstein is evil. I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.
- myrion 3y agoHm. Yeah, I really need to adjust my view on this - I found NIST's responses dodgy precisely because they seemed so unwilling to engage, and I still thought of him as respected enough to warrant better responses. If he's turned so crank-y that his peers simply no longer engage with him beyond the strictly necessary, then this all looks a bit different. I'd still love to see some of his specific criticisms addressed, but that becomes a minor point...
- red_admiral 3y agoStrong agree. I've heard Bernstein described before now has having "all the subtlety of The Incredible Hulk". Quite possibly there's some things he can get away with only because he's a brilliant cryptographer. Designing curve25519 was, in terms of practical impact, an achievement I'd put in the same category as inventing RSA or Diffie-Hellman. Not because the ideas were new, but because they came together in a way that produces something that "just works" in practice, and you don't have to worry about invalid curve points and twist attacks and accidentally using the addition formula for a point doubling and many other things. The idea that instead of a framework where you can plug in your own parameter choices and some of them might be secure, you can just build a crypto library that does one thing well, was certainly new enough that no-one else seemed to be doing it at the time. The fact that when I need a key for real, most of the time I do `ssh-keygen -t ed25519` or the equivalent in other systems speaks for itself. As does the fact that github has deprecated the ssh-dss key type and recommends ed25519 and the default: in the contest between Ed25519 and DSA/ECDSA for digital signatures, Bernstein wins hands down and NIST has egg on their face. Although I have no proof of malice, I haven't yet heard a rational explanation for just how badly ECDSA mangles the Schnorr protocol in exactly the way that means a lot of implementations end up with horrible security holes. And then there's the Snowden leaks and DUAL_EC. "The NSA has interfered with crypto standards in the past, reliable leaks show it was part of their mission statement, and they could be doing so again." is to me a statement backed up by plausible evidence that's very far from the usual conspiracy theories. This is not faked-moon-landings territory. And I should also say, there are a lot of ways of being evil that to my knowledge no-one has ever accused Bernstein of: as far as I know, he's never been accused of raping or sexually assaulting anyone, nor has he said anything particularly racist or pushed any far-right ideology. He has been accused of insulting and occasionally threatening people who disagree with him on technical matters, but he's not what we usually mean by "bad/evil person, avoid if possible". I'd say he has a fairly spotless track record in cryptographic protocol design, and a fairly stained one in interacting with other humans. When he's pushing back against design decisions that actually are stupid/evil, that's an asset; in lots of other cases it's not.
- kdragon 3y ago> I haven't yet heard a rational explanation for just how badly ECDSA mangles the Schnorr protocol in exactly the way that means a lot of implementations end up with horrible security holes. I thought schnorr was under patent for a bit, so an open alternative was needed? Also ECDSA does allow for recovery of the public key from the signature, which can be useful.