Remix.run Logo
NSA and IETF, Part 9(blog.cr.yp.to)
34 points by libroot 3 hours ago | 22 comments
philodeon an hour ago | parent | next [-]

I enjoyed the @tptacek cameo. I suspect tptacek didn’t.

tptacek 36 minutes ago | parent | next [-]

He didn't publicly call me an NSA shill, so I got off pretty easy. Obviously, I stand by what I said. I think it would be an understatement to suggest support for what Bernstein is arguing is a minority cause among cryptographers.

cassonmars 17 minutes ago | parent | next [-]

Are you a cryptographer?

I am. I literally hold six patents around secure key generation and management. I stand by DJB's points.

tptacek 16 minutes ago | parent [-]

Amazing. Six patents! I sign literally everything I write here with my own name, so it's pretty easy to find out my background.

directoron 32 minutes ago | parent | prev | next [-]

The argument from Roberto Avanzi is reasonable: "as a codesigner of ML-KEM myself I would not trust using it exclusively: what if it gets broken mathematically and in the classical computational model (I.e. non-quantum)? Hybrid is better, and the additional time used by ECC is not significant."

tptacek 30 minutes ago | parent [-]

A majority (but not a large majority) of cryptography engineers would use hybrids at this point, and hybrids are largely the default design for any mainstream deployment. Bernstein argument isn't "use hybrids, not pure MLKEM"; it's "MLKEM is so dangerous there shouldn't even be an informational standard saying how to use it". That's a problem, because there are non-mainstream deployment environments where you can't use hybrids.

Obviously, Bernstein is counting on you not following that level of nuance; he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

For clarity: I am not a cryptographer; I'm a vulnerability researcher who does some cryptography work and for several reasons I talk to a lot of academic cryptographers and cryptography engineers. You could not pay me to design a PQC transport protocol for you.

directoron 25 minutes ago | parent [-]

Yes, the argument is MLKEM is so dangerous that it shouldn't be used alone. Even its codesigner says so. Why is it so hard to accept?

Take a look at the crypto from the 80's and 90's. They are considered bad jokes nowadays, badly designed and easily breakable. Why would the first-generation PQC algorithms be any different? Of course they're going to be broken and ridiculed in 20 years, in ways you cannot comprehend yet

tptacek 22 minutes ago | parent [-]

I feel like what's most likely happening here, given your initial argument, is that you just learned that this is a debate about whether it should be forbidden to even document a particular MLKEM configuration, and you're now working backwards to the proposition that Bernstein is right.

To that I will only add that lattice cryptography is of approximately the same vintage as elliptic curve (both started in the late 1990s) and MLKEM is past the level of maturity relative to lattices that 25519 was relative to the original P-curves. (Correct me where I'm wrong here --- this is off the top of my head). This isn't "the first generation" of anything.

Just another nuance I think Bernstein is counting on you, the real audience for these posts, not having any intuition for.

directoron 13 minutes ago | parent [-]

That's a weak ad hominem deflection. Readers be the judge.

tptacek 8 minutes ago | parent [-]

In addition to noticing that your argument had moved goalposts (the part you claim is an ad hominem, but is not) I also responded substantively to a factual claim you made, and you're pretending otherwise.

eis 13 minutes ago | parent | prev [-]

I'm confused by your messages linked by DJB. You say that better cryptographers would not choose hybrids, which seems to say that you should indeed think that hybrids are not a good choice. Then you say you are not such a good cryptographer and would choose a hybrid. But if you know that more senior cryptographers think they are not the right choice then why choose them anyways? Or am I misreading "cryptography-literate" here?

Can you explain a bit more regarding your statement that DJB's POV on the matter has no broad support amongst his peers? I'm not in the field but Bernstein seemed like a highly respected member with a long track record in the crypto community, at least from the outside. Do you think the community is wrong or is it DJB who's wrong and why? There's also a good chance that I totally missed the argument being made.

tptacek 10 minutes ago | parent [-]

I can think of several academic cryptographers (or rather, practitioners with doctorates) who think the hybrid/pure thing is silly. I didn't claim that a majority oppose hybrids. The point of the message he snipped from the HN thread is that pure MLKEM is not considered an unserious design by actual cryptographers (people on the HN thread --- generally not cryptographers, like me --- think it is). Cryptography engineers tend to default to hybrids.

Downthread we develop more clarity about what it is Bernstein is actually in an argument about. It isn't hybrids vs. pure!

cassonmars 37 minutes ago | parent | prev [-]

frankly every time this topic comes up he's quick to try to spread disinformation on djb's posts, so it's about time he got mentioned

stackghost 2 hours ago | parent | prev | next [-]

It's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-1 but from the outside there's no way to know whether they're making DES stronger against differential cryptanalysis or whether they're introducing a DUAL_EC-style vulnerability.

I'm sure there's a game-theoretic optimum choice when it comes to accepting proposals from the NSA vs rejecting them out of hand, but I'm not sure what that optimal choice is.

philodeon an hour ago | parent [-]

The purpose of a system is what it does.

https://archive.nytimes.com/www.nytimes.com/interactive/2013...

jauntywundrkind 2 hours ago | parent | prev [-]

> I'm happy to report that 82 people spoke up on the TLS mailing list in unambiguous opposition to this spec during the voting period

How many of them spoke before on this mailing list, in any capacity what so ever? I suspect this is 99% people who showed up because you organized a brigadging, because you incited people and told them to show up and be completely outraged.

There's a >0% chance that DJB could be correct that there is some risk to this spec (which notably is not seeking recommendation status! So WTF?) The people approving and wanting this aren't fools, aren't lackies, aren't some great foe. There's little real opposition? Making up ghosts and enemies lurking in every corner, brigading people to show up in IETF meetings, who have never participated before, just to spread heat and anger you've programmed them for, is ignoble & indecent.

All too recently: https://news.ycombinator.com/item?id=48760490 https://news.ycombinator.com/item?id=48811887

cornstalks an hour ago | parent | next [-]

> which notably is not seeking recommendation status!

I don’t have a dog in this fight, but some extremely important RFCs are only on the “informational” track. RFCs 1945 (HTTP 1.0), 4627 (JSON), 2818 (HTTPS), etc.

tptacek 34 minutes ago | parent [-]

HTTP, JSON, and HTTPS all have standards-track RFCs.

cassonmars 36 minutes ago | parent | prev [-]

because the NSA has never surreptitiously pushed bad standards they used to exploit before

/s

tptacek 34 minutes ago | parent [-]

Which PQC standard are you suggesting they pushed, and how did they push it? Flesh the argument out.

vlovich123 4 minutes ago | parent [-]

That’s a very unfair position to take when dealing with secret agencies who try very hard to obfuscate this stuff - it is hard to provide evidence for in the moment.

The government has intentionally acted to weaken DES, standardized Dual_EC_DRBG, performed subtle subterfuge through interfering how NIST operates to inject weaknesses and vulnerabilities, trying to weaken SSL and IPSec, 4G smartphone encryption.

These are all documented examples of the NSA engaging in bad faith. So whether or not it is happening in this particular case, there’s now just zero trust in the institutions acting in good faith. And given it took decades for the actions to come out after they were taken, how do you expect someone to answer your request to present evidence there’s anything nefarious happening now?

Anyway, that’s what I think a fleshed out argument would look like

tptacek 2 minutes ago | parent [-]

It's a simple question. I'm not asking anybody to prove anything. I'm literally asking: propose the PQC standard IETF could have subverted, and give a sketch of how they could have done it. The bar is merely "plausibility". I'm not asking whether NSA has subverted standards before; obviously they have.

NSA, by the way, rescued DES from differential cryptography, the core mechanism by which block ciphers and hash functions have been attacked ever since.