3 ms·
For anyone that would like to catch up with this unfortunate saga, I recommend reading the following, that (partially due to being presented less inflammatorily
by FiloSottile 3y ago
For anyone that would like to catch up with this unfortunate saga, I recommend reading the following, that (partially due to being presented less inflammatorily and through the appropriate channels) are getting much less coverage.
Ray Perlner (NIST PQC), Re: Kyber security level? https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VOzy0wz_E/m/UGeTmPCqBAAJ https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...
Christopher J Peikert, Re: Kyber security level? https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VOzy0wz_E/m/LjmQyMurBQAJ https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VO...
Matthew Green on Mastodon https://ioc.exchange/@matthew_d_green/111227593416987176 https://ioc.exchange/@matthew_d_green/111227593416987176
tptacek on HN https://news.ycombinator.com/item?id=37874682 https://news.ycombinator.com/item?id=37874682
Personally, I am woefully unqualified to judge the intricacies of attack cost estimation myself, but I have followed enough of the process to find some of the conspiracy claims risible. For example, that NIST made a graph a little smaller on a slide to "deemphasize" it (search for "thinner red bars" in https://blog.cr.yp.to/20231003-countcorrectly.html https://blog.cr.yp.to/20231003-countcorrectly.html).
Moreover, I fail to understand why NIST would pick a weak algorithm (designed by independent researchers) to secure the data of US federal agencies and industry. This is critically different from Dual_EC_DRBG in that there is nowhere to hide a NOBUS (https://en.wikipedia.org/wiki/NOBUS https://en.wikipedia.org/wiki/NOBUS) backdoor, so it would be a ridiculous bet that no one else in the world will find the weakness in the next fifty years.
The one bit of color I will add is that every community of cryptographers I am in has had enough of this, as far as I can tell, and is not taking Bernstein seriously anymore. The most common reactions are eyerolls and popcorns. As I said before (https://news.ycombinator.com/item?id=37868974 https://news.ycombinator.com/item?id=37868974), I am worried that Bernstein has increasingly argued in bad faith and alienated his peers (through spurious accusations, personal attacks, endless never-retracted arguments, and legal threats) to the point that they're unwilling to engage with him, which from the outside can look like his points are unrefutable. Like Matthew Green, I am worried about what that will do to confidence in modern cryptography, given Bernstein's following.