3 ms·
It's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-
by stackghost 2mo ago
It's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-1 but from the outside there's no way to know whether they're making DES stronger against differential cryptanalysis or whether they're introducing a DUAL_EC-style vulnerability.
I'm sure there's a game-theoretic optimum choice when it comes to accepting proposals from the NSA vs rejecting them out of hand, but I'm not sure what that optimal choice is.
- philodeon 2mo agoThe purpose of a system is what it does. https://archive.nytimes.com/www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html https://archive.nytimes.com/www.nytimes.com/interactive/2013...
- libroot 2mo agoImo "the optimal choice" is to be extremely skeptical to what comes to NSA proposing anything related to encryption/cryptography. From the first part of this blog series by DJB[1]: > Try to put yourself in the mindset of NSA as an attacker. You have a massive budget to "covertly influence and/or overtly leverage" systems to "make the systems in question exploitable"; "to the consumer and other adversaries, however, the systems' security remains intact". One of your action items is to "influence policies, standards and specification for commercial public key technologies". Another is to "shape the worldwide commercial cryptography marketplace to make it more tractable to advanced cryptanalytic capabilities being developed by NSA/CSS". And when you read the Snowden docs and you come across to things like this 2010 GCHQ presentation[2], stating "for the past decade, NSA has lead an aggressive, multipronged effort to break widely used Internet encryption technologies" such as "SSL" and "SSH" and "VPNs"; that "cryptanalytic capabilities are now coming on line"; and that "vast amounts of encrypted Internet data which have up till now been discarded are now exploitable." So we have these agencies like NSA and GCHQ, with stated, funded programs to make deployed cryptography exploitable (and historical evidence of them successfully doing just that)... It's an unbelievable conflict of interest for them to hold any role where they can shape what gets deployed. Absolutely bonkers. And on DES specifically, it was both at once, not a binary. NSA in secret pushed IBM to cut the key size, while strengthening the algo against every attack except brute force. The design criteria were classified and IBM's own research docs were literally locked up under gov classification at NSA's request meanwhile when IBM personnel publicly denied any NSA involvement (and the NSA director publicly denied any algo weakening, again, a lie). So DES came out genuinely hardened against differential cryptanalysis but at the same time breakable by brute force by organizations with budgets like NSA's, by NSA's request/order. For the "blue team" thing.. I guess it's actually better for them tactically to not spin off, because being NSA gives you authority in those circles. Standards bodies don't seem to treat the conflict of interest as a problem (as we can see), but rather as a qualification ("people who know cryptography best"). 1: https://blog.cr.yp.to/20251004-weakened.html https://blog.cr.yp.to/20251004-weakened.html 2: https://web.archive.org/web/20240420184725if_/https://cdn.prod.www.spiegel.de/media/f94a2e13-0001-0014-0000-000000035532/media-35532.pdf https://web.archive.org/web/20240420184725if_/https://cdn.pr...
- tptacek 2mo agoSee, this is what upsets me about this situation. Bernstein has managed to get you to a point where you think NSA "proposed" MLKEM, or had some hand in its design. That's not remotely what happened. A team of European cryptographers, including a famous former longtime collaborator of Bernstein himself, designed CRYSTALS/Kyber, which was selected by NIST in an open competition (where progress through the competition was based on open academic cryptanalysis work) to become MLKEM. Bernstein is counting on you not knowing that, even though it's a very rudimentary fact about MLKEM. It bothers me that he thinks so little of his audience.
- libroot 2mo agoWhat a weird comment. > where you think NSA "proposed" MLKEM or had some hand in its design Never said this and don't think it. Kyber came from an academic team through an open NIST competition, no one is disputing that. The fight is over a spec for deploying ML-KEM without the ECC layer, and the fact that NSA and GCHQ are argumenting that that weakening is a good thing, and about corrupt standardization process.
- tptacek 2mo agoNo it isn't! Everyone is fine with hybrids, hybrids are the default, and hybrids have a standards-track, recommended=y RFC, unlike pure. If you think this is about hybrids, Bernstein has bamboozled you.
- libroot 2mo agoAgain you responded to a position I havent taken. My argument was about who holds procedural power in standards bodies, given that some of the significant participants (NSA & GCHQ) have funded programs with hundreds of millions of $ per year to make deployed cryptography exploitable. And DES and Dual EC and others are what that looks like when it succeeds.
- tptacek 2mo ago