4 ms·
NSA and IETF, Part 9
- jauntywundrkind 2mo ago> I'm happy to report that 82 people spoke up on the TLS mailing list in unambiguous opposition to this spec during the voting period How many of them spoke before on this mailing list, in any capacity what so ever? I suspect this is 99% people who showed up because you organized a brigadging, because you incited people and told them to show up and be completely outraged. There's a >0% chance that DJB could be correct that there is some risk to this spec (which notably is not seeking recommendation status! So WTF?) The people approving and wanting this aren't fools, aren't lackies, aren't some great foe. There's little real opposition? Making up ghosts and enemies lurking in every corner, brigading people to show up in IETF meetings, who have never participated before, just to spread heat and anger you've programmed them for, is ignoble & indecent. All too recently: https://news.ycombinator.com/item?id=48760490 https://news.ycombinator.com/item?id=48760490 https://news.ycombinator.com/item?id=48811887 https://news.ycombinator.com/item?id=48811887
- cornstalks 2mo ago> which notably is not seeking recommendation status! I don’t have a dog in this fight, but some extremely important RFCs are only on the “informational” track. RFCs 1945 (HTTP 1.0), 4627 (JSON), 2818 (HTTPS), etc.
- tptacek 2mo agoHTTP, JSON, and HTTPS all have standards-track RFCs.
- cornstalks 2mo agoAs far as I know HTTP 1.0 doesn't have a standards-track RFC (HTTP 1.1 and later do). JSON and HTTPS do indeed have standards-track RFCs, but I stand by my original wording that their first informational RFCs were "extremely important."
- cassonmars 2mo agobecause the NSA has never surreptitiously pushed bad standards they used to exploit before /s
- tptacek 2mo agoWhich PQC standard are you suggesting they pushed, and how did they push it? Flesh the argument out.
- vlovich123 2mo agoThat’s a very unfair position to take when dealing with secret agencies who try very hard to obfuscate this stuff - it is hard to provide evidence for in the moment. The government has intentionally acted to weaken DES, standardized Dual_EC_DRBG, performed subtle subterfuge through interfering how NIST operates to inject weaknesses and vulnerabilities, trying to weaken SSL and IPSec, 4G smartphone encryption. These are all documented examples of the NSA engaging in bad faith. So whether or not it is happening in this particular case, there’s now just zero trust in the institutions acting in good faith. And given it took decades for the actions to come out after they were taken, how do you expect someone to answer your request to present evidence there’s anything nefarious happening now? Anyway, that’s what I think a fleshed out argument would look like
- tptacek 2mo agoIt's a simple question. I'm not asking anybody to prove anything. I'm literally asking: propose the PQC standard IETF could have subverted, and give a sketch of how they could have done it. The bar is merely "plausibility". I'm not asking whether NSA has subverted standards before; obviously they have. NSA, by the way, rescued DES from differential cryptography, the core mechanism by which block ciphers and hash functions have been attacked ever since.
- Vecr 2mo ago> NSA, by the way, rescued DES from differential cryptography, the core mechanism by which block ciphers and hash functions have been attacked ever since That's why you use ML-KEM 1024 at all... As part of a hybrid.
- stackghost 2mo agoIt's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-1 but from the outside there's no way to know whether they're making DES stronger against differential cryptanalysis or whether they're introducing a DUAL_EC-style vulnerability. I'm sure there's a game-theoretic optimum choice when it comes to accepting proposals from the NSA vs rejecting them out of hand, but I'm not sure what that optimal choice is.
- philodeon 2mo agoThe purpose of a system is what it does. https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html https://archive.nytimes.com/www.nytimes.com/interactive/2013...
- libroot 2mo agoImo "the optimal choice" is to be extremely skeptical to what comes to NSA proposing anything related to encryption/cryptography. From the first part of this blog series by DJB[1]: > Try to put yourself in the mindset of NSA as an attacker. You have a massive budget to "covertly influence and/or overtly leverage" systems to "make the systems in question exploitable"; "to the consumer and other adversaries, however, the systems' security remains intact". One of your action items is to "influence policies, standards and specification for commercial public key technologies". Another is to "shape the worldwide commercial cryptography marketplace to make it more tractable to advanced cryptanalytic capabilities being developed by NSA/CSS". And when you read the Snowden docs and you come across to things like this 2010 GCHQ presentation[2], stating "for the past decade, NSA has lead an aggressive, multipronged effort to break widely used Internet encryption technologies" such as "SSL" and "SSH" and "VPNs"; that "cryptanalytic capabilities are now coming on line"; and that "vast amounts of encrypted Internet data which have up till now been discarded are now exploitable." So we have these agencies like NSA and GCHQ, with stated, funded programs to make deployed cryptography exploitable (and historical evidence of them successfully doing just that)... It's an unbelievable conflict of interest for them to hold any role where they can shape what gets deployed. Absolutely bonkers. And on DES specifically, it was both at once, not a binary. NSA in secret pushed IBM to cut the key size, while strengthening the algo against every attack except brute force. The design criteria were classified and IBM's own research docs were literally locked up under gov classification at NSA's request meanwhile when IBM personnel publicly denied any NSA involvement (and the NSA director publicly denied any algo weakening, again, a lie). So DES came out genuinely hardened against differential cryptanalysis but at the same time breakable by brute force by organizations with budgets like NSA's, by NSA's request/order. For the "blue team" thing.. I guess it's actually better for them tactically to not spin off, because being NSA gives you authority in those circles. Standards bodies don't seem to treat the conflict of interest as a problem (as we can see), but rather as a qualification ("people who know cryptography best"). 1: https://blog.cr.yp.to/20251004-weakened.html https://blog.cr.yp.to/20251004-weakened.html 2: https://web.archive.org/web/20240420184725if_/https://cdn.prod.www.spiegel.de/media/f94a2e13-0001-0014-0000-000000035532/media-35532.pdf https://web.archive.org/web/20240420184725if_/https://cdn.pr...
- philodeon 2mo agoI enjoyed the @tptacek cameo. I suspect tptacek didn’t.
- cassonmars 2mo ago[flagged]
- timschmidt 2mo ago[flagged]
- philodeon 2mo ago[flagged]
- tptacek 2mo agoI have no idea what the fuck you're talking about here but nobody "lost a grad school spot" to Jacob Appelbaum. It is true that I was once a Bernstein stan. He's generally been nothing but nice to me. But then I met other cryptographers.
- philodeon 2mo agoQuoting https://archive.fo/3QWJF#selection-801.0-805.168 https://archive.fo/3QWJF#selection-801.0-805.168 “Als Appelbaum im September 2015 an der Technischen Universität Eindhoven ein Doktorandenprogramm beginnt, ist auch sie interessiert. Für Appelbaum ist die Universitätsstelle in Eindhoven auch eine existentielle Stütze, falls er, nach den Vorwürfen im März in Valencia, seine Arbeit beim Tor-Projekt nicht fortsetzen kann. Lovecruft versucht schließlich, bei den selben Professoren wie Appelbaum angenommen zu werden. Am Ende wird ihr das nicht gelingen. Ein anderer Mensch wird jedoch das Büro beziehen, das direkt neben Appelbaums liegt. Es ist der Lebenspartner von Isis Agora Lovecruft oder einer ihrer Lebenspartner, das ist nicht klar. Dieser Mann wird später Arbeiten von Appelbaum bewerten, deren Ergebnisse für dessen Vorankommen in der Universität wichtig sind. Im Januar 2016, kurz nachdem sie an der Universität in Eindhoven abgelehnt wird, beteiligt sich Isis Agora Lovecruft daran, Geschichten zu sammeln über Jacob Appelbaum.”
- ifh-hn 2mo agoCan someone ELI5 what the issue is here? I feel like I'm missing a lot of nuance here. Are the NSA people attempting to weaken TLS by removing ECC?
- tptacek 2mo agoNo. This whole situation is extremely dumb. Bernstein is a co-author on NIST PQC competition submissions that didn't win (Classic McEliece, which just had a huge new research result, and Streamlined NTRU Prime, a lattice cousin to MLKEM). When CRYSTALS/Kyber was selected in the NIST competition instead of SNTRUP, Bernstein didn't take it well. He claimed malfeasance by NIST and sued them for allegedly hiding documents. Meanwhile, over the subsequent years, the world has continued turning on its axes. CRYSTALS/Kyber is now ML-KEM. Because many cryptography engineers and other security people think there's a lot of urgency to getting PQC deployed (because of harvest-now decrypt-later [HNDL] attacks), the IETF got a move on standardizing hybrid ECDH/MLKEM TLS 1.3, which is what everyone uses. Nobody at IETF has ever to my knowledge even hinted that anyone should avoid hybrids. There is a standards-track RFC defining ECDH/ML-KEM hybrids. There are environments where hybrids are problematic. You won't likely use any of them ever. Some of them occur within the US Government, and some of them are on highly constrained platforms (people seem to disbelieve this is ever really a thing but I once gameovered a smart meter because its RF protocol only had like 16 bits of counter space for CTR). Because of this, there is also a proposed informational RFC --- not a standards track document --- that documents what pure MLKEM looks like in a TLS 1.3 setting. Bernstein's entire argument is that this is an NSA plot.
- throw0101a 2mo ago> Because of this, there is also a proposed informational RFC --- not a standards track document --- that documents what pure MLKEM looks like in a TLS 1.3 setting. For discussion on Bernstein's objection to that IETF draft see article from ~month ago, "NSA and IETF: Fairness": * https://news.ycombinator.com/item?id=48811887 https://news.ycombinator.com/item?id=48811887
- rasengan 2mo agoRFCs are used by developers as strict guidelines for implementation. The mere publishing of an RFC has customarily been treated by developers as a stamp of approval from the IETF. The NSA, contractors and their fans argue that simply adding a "RECOMMENDED=N" in an obscure section of this draft will somehow prevent said implementations in deployments. However, as an example, Canada's NSA equivalent specifically requested the draft to be published so that they can use it to support their poor choice in deployment of solo ML-KEM nation-wide. While ML-KEM may be sound, significant bugs in implementations in the wild continue to be published. To be clear, CRQCs do not exist today. ECC is battle tested, proven, and is used today. It makes no sense to delete working cryptography and replace it with potentially buggy, non-battle tested implementations of new cryptography for a threat that does not yet exist today. Instead, you fight HNDL [1] with hybrid which preserves the safety of today, and hopefully also, tomorrow. No serious security person should be recommending otherwise which is, perhaps, why some may question the motives of those that are pushing for solo ML-KEM. [1] Harvest now decrypt later
- alfiedotwtf 2mo agoI thought this was going to be rehashing of the old NULL-cypher IPsec thread, but it’s a different thing. Maybe we should treat standards like we do a free market - let anyone implement what they choose then let people chose which to adopt, but the main thing is get government out of the entire process. If the government wants to standardise, that’s fine… just don’t make it an industry standard adopted by civilians. Let them have their weakened protocols will the market moves on
- timschmidt 2mo agoBrings to mind this lovely quote from the Snowden documents: “The road to developing this standard was smooth once the journey began... However, beginning the journey was a challenge in finesse ... After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft ... Eventually, N.S.A. became the sole editor.” https://macleans.ca/society/technology/nsa-says-it-finessed-canada-seizing-control-of-global-crypto/ https://macleans.ca/society/technology/nsa-says-it-finessed-...
- 1vuio0pswjnm7 2mo agoA while ago I ran across this lame criticism of djb: https://cryptography.watch/articles/djb-cryptographic-odyssey/ https://cryptography.watch/articles/djb-cryptographic-odysse... As an end-user I find djb's critics are generally pathetic djb's work, specifically how others react to it, is like a litmus test for self-aggrandizing idiots