4 ms·
Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough. But it's probably bes
by devx 13y ago
Let's see how they dramatically improve the process then. I hope they don't think statements like "we didn't do it, trust us" are enough.
But it's probably best to just forget about NIST and start from scratch with a new standards body with zero influence from the government - any government(how it should be).
- zeckalpha 13y agoAlmost by definition, a standards organization would have some form of government (lowercase g) running it. What would you suggest as an alternative? Wikistandards? Even a wiki has government.
- ganeumann 13y agoThey can't fix it. As the article noted, they are required by law to consult with the NSA. While the NSA is an expert on cryptography, they are obviously (and were, obviously, at the time that law was written) conflicted. That the law says that NIST has to consult with the NSA means that the law-writers, our government, want NIST to allow NSA to weaken cryptography standards. This is not conspiracy-thinking, anyone who thought through the consequences of this law would see that this is what the NSA would try to do. Why would the cryptography community ever again cooperate with NIST while the requirement to consult with the NSA is in place? It's not a question of feeling betrayed, it's simply irrational to try to create a strong cryptography standard when the NSA is in the room. They can do that work outside of NIST.