NSA and IETF, Part 9

(cr.yp.to)

28 points | by libroot 2 hours ago

3 comments

  • philodeon 33 minutes ago
    I enjoyed the @tptacek cameo. I suspect tptacek didn’t.
    • tptacek 5 minutes ago
      He didn't publicly call me an NSA shill, so I got off pretty easy. Obviously, I stand by what I said. I think it would be an understatement to suggest support for what Bernstein is arguing is a minority cause among cryptographers.
      • directoron 1 minute ago
        The argument from Roberto Avanzi is reasonable: "as a codesigner of ML-KEM myself I would not trust using it exclusively: what if it gets broken mathematically and in the classical computational model (I.e. non-quantum)? Hybrid is better, and the additional time used by ECC is not significant."
    • cassonmars 6 minutes ago
      frankly every time this topic comes up he's quick to try to spread disinformation on djb's posts, so it's about time he got mentioned
  • stackghost 1 hour ago
    It's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-1 but from the outside there's no way to know whether they're making DES stronger against differential cryptanalysis or whether they're introducing a DUAL_EC-style vulnerability.

    I'm sure there's a game-theoretic optimum choice when it comes to accepting proposals from the NSA vs rejecting them out of hand, but I'm not sure what that optimal choice is.

  • jauntywundrkind 1 hour ago
    > I'm happy to report that 82 people spoke up on the TLS mailing list in unambiguous opposition to this spec during the voting period

    How many of them spoke before on this mailing list, in any capacity what so ever? I suspect this is 99% people who showed up because you organized a brigadging, because you incited people and told them to show up and be completely outraged.

    There's a >0% chance that DJB could be correct that there is some risk to this spec (which notably is not seeking recommendation status! So WTF?) The people approving and wanting this aren't fools, aren't lackies, aren't some great foe. There's little real opposition? Making up ghosts and enemies lurking in every corner, brigading people to show up in IETF meetings, who have never participated before, just to spread heat and anger you've programmed them for, is ignoble & indecent.

    All too recently: https://news.ycombinator.com/item?id=48760490 https://news.ycombinator.com/item?id=48811887

    • cornstalks 25 minutes ago
      > which notably is not seeking recommendation status!

      I don’t have a dog in this fight, but some extremely important RFCs are only on the “informational” track. RFCs 1945 (HTTP 1.0), 4627 (JSON), 2818 (HTTPS), etc.

      • tptacek 3 minutes ago
        HTTP, JSON, and HTTPS all have standards-track RFCs.
    • cassonmars 5 minutes ago
      because the NSA has never surreptitiously pushed bad standards they used to exploit before

      /s

      • tptacek 3 minutes ago
        Which PQC standard are you suggesting they pushed, and how did they push it? Flesh the argument out.