Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mswphd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
mswphd
3mo ago
the NSA also recommends elliptic curve cryptography, and designed SHA2 themselves. if you want we can talk through how to disable all of these ciphersuites, so you can be stuck with a bunch of shitty stuff from the 90s and feel warm and fuz
62.
▲
by
mswphd
3mo ago
as mentioned it's complicated, but the general trend of the NSA pushing cryptography they can break and others can't is well-known. https://en.wikipedia.org/wiki/NOBUS note that there is no even candidate w
63.
▲
by
mswphd
3mo ago
1. Kyberslash is mostly marketing. Some implementations (including the Kyber reference implementation, but *not* including the Kyber AVX implementation) had a non-constant time component. This is a meaningful CVE. It is not some fundamental
64.
▲
by
mswphd
3mo ago
there is no indication there are similar papers. Curiously, the best lattice cryptanalysts in the world are chinese and european (here I'm thinking of people like Ducas, Albrecht, and Ding). It's actually a weird blindspot of amer
65.
▲
by
mswphd
3mo ago
this is not what I said before. As I mentioned in the post you replied to, there are certain scenarios (e.g. hardware) where pure ML-KEM has significant performance benefits. It instead should not be the default implementation suggestion.
66.
▲
by
mswphd
3mo ago
if you blindly distrust the NSA, you should stop using x25519 immediately. It uses SHA2, which was solely developed by the NSA. If DJB blindly distrusts the NSA, he would also recommend against SHA2. But he doesn't, and instead wants t
67.
▲
by
mswphd
3mo ago
you would make poor decisions then. McEliece recently (in the last month) had a large new attack against it https://eprint.iacr.org/2026/1232 This doesn't hit classic McEliece yet, but is part of a line of work th
68.
▲
by
mswphd
3mo ago
this is entirely wrong. Lattice-based cryptography has been extremely well-studied theoretically and practically, even before standardization. For example, a (hybrid) lattice-based KEM was (experimentally) deployed in Chrome in 2016. https
69.
▲
by
mswphd
3mo ago
NTRU based schemes are not the most conservative. NTRU is an old design from the 90s, that had some shocking structural attacks against it appear ~2016. These attacks so far are only relevant for moduli q ~ (1/100) n^{2.3...}. This mak
70.
▲
by
mswphd
3mo ago
using pure ML-KEM is not a footgun. Some people may have doubts about lattice-based cryptography, despite being securely deployed in Chrome nearly a decade ago. Some people have doubts about many things. The fact that people have doubts doe
71.
▲
by
mswphd
3mo ago
note that this says something more limited than what you're saying. Specifically, an american company was not allowed to give access to the cryptography you describe to non-Americans. This was still a very bad policy, but private ameri
72.
▲
by
mswphd
3mo ago
actually another more basic point: SIKE is much more closely related to elliptic-curve cryptography than lattices. People would not use SIKE to argue that ECC is unreliable though.
73.
▲
by
mswphd
3mo ago
those are not remotely the same things though? You're also (formally) wrong about DUAL_EC_DRBG for two reasons 1. the payment to RSA (in 2004) was secret. So it could not have been a public indication of a problem, as it was not discov
74.
▲
by
mswphd
3mo ago
there has been no hint of a backdoor in ML-KEM. In fact, it (and every lattice-based scheme) has been made less efficient on purpose to rule out the only possible backdoor (the ephemeral "a" part in LWE-type samples could be f
75.
▲
by
mswphd
3mo ago
the IETF TLS working group has limited time/energy. He has been (very successfully) taking up a good deal of this with very annoying procedural techniques (and his most recent move, spreading falsehoods regarding an RFC then asking peo
76.
▲
by
mswphd
3mo ago
Very explicitly, this is not the main RFC for incorporating PQ crypto into TLS 1.3. This is an RFC with recommendation to implement = N about how to do pure ML-KEM if you must for some reason, in a standards-compliant way. That blog post is
77.
▲
by
mswphd
3mo ago
all cryptographic risks cannot be quantified. Every cryptographer knows this. It is consistent with everything we know that oneway functions do not exist, and cryptography as a field is limited to things like Merkle Puzzles/things that
78.
▲
by
mswphd
3mo ago
you're talking about what is known as NISQ quantum computers, namely quantum computers before they can do full error correction. There are no claimed cryptanalytic benefits for NISQ machines. The main claims I've seen are for quan
79.
▲
by
mswphd
3mo ago
That document is nonsense? The current RFC is not to say > use pure ML-KEM > hybrid ML-KEM. the current document is instead to say > If you are in a setting where you REALLY want to use pure ML-KEM (though we explicitly recommend y
80.
▲
by
mswphd
3mo ago
DJB wrote this article after asking people to brigadge the current TLS-WG's attempt to get rough consensus on a current draft RFC for pure ML-KEM. This is clearly part of this tirade for that. ML-KEM is not new. It's hardness is b
81.
▲
by
mswphd
3mo ago
it is easy to point to ghosts in the corner. Random fearmongering is not a technical argument though. There have been no technical arguments to justify the random fearmongering. Pointing to prior behavior in a way that is inconsistent wit
82.
▲
by
mswphd
3mo ago
SIKE is a completely different scheme based on completely different hardness assumptions from a completely different area of math. It is just as sensible to call elliptic curve cryptography to be a predecessor to ML-KEM. Nobody would do tha
83.
▲
by
mswphd
3mo ago
That was articulated this morning explicitly on the TLS WG, you can see here https://mailarchive.ietf.org/arch/msg/tls/_9i3uIVDQ3pDRswpm9... In general most cryptographers don't do hardware. Most cryptog
84.
▲
by
mswphd
3mo ago
quantum algorithm would make pure ML-KEM bad to support for the NSA. If the NSA has a quantum computer, they would want to delay proliferation of post-quantum schemes as long as possible, so they could get as much milage out of it as poss
85.
▲
by
mswphd
3mo ago
this RFC is marked "recommended to implement = N". It is not suggesting everyone should use pure ML-KEM. It is suggesting it should be an option, if hybrid encryption is not suitable for certain usecases. Think hardware, where hyb
86.
▲
by
mswphd
3mo ago
this is literally what happened with previous NSA meddling though? Both DUAL_EC_DRBG and DES were done "officially" by the NSA. Additionally, the main authors behind ML-KEM are all european. The design of ML-KEM is "very bori
87.
▲
by
mswphd
3mo ago
the NSA has a history of weakening cryptography in a very specific way, known as "NOBUS" https://en.wikipedia.org/wiki/NOBUS DES key-size weakening is consistent with NOBUS (given the computational dominance
88.
▲
by
mswphd
3mo ago
this is not an accurate picture of what is happening. Hybrid KEMs are already widely supported within the IETF, and are supported in an RFC with "recommended to implement = yes". This is about a separate RFC with "recommended
89.
▲
by
mswphd
3mo ago
DJB has for years claimed anyone who disagrees with him is affiliated with the NSA. See for example this post as part of the NIST-PQC competition https://blog.cr.yp.to/20220805-nsa.html > Some people seem to be unable to
90.
▲
by
mswphd
3mo ago
The IETF has published the russian TLS 1.2 standard (RFC 9189). This includes Kuznyechik, which is has a certain design choice consistent with it being backdoored. https://en.wikipedia.org/wiki/Kuznyechik#Cryptanalysis
More ›