Cryptography Discussion: Speculation on "BULLRUN" (2013)
mail-archive.com
mail-archive.com
The power of strong and asymmetric cryptography led a lot of programmers into the belief that this is a political problem that can be solved with technical solutions but it is not.
Whether it is a subtle influence as is described here or as a heavy handed approach like in China, politics trump technological means.
If your government is actively trying to undermine the security and privacy of your technological solution, you need to be outspoken about it.
Something I find a bit disturbing is how much of our understanding of particular issues seems to depend on brilliant individuals. This is a bit like the Bernstein monoculture article that was discussed here recently but I'm also thinking of several of the items from Boneh's RSA attack overview paper, or maybe Xiaoyun Wang's hash function stuff.
Clearly all discoveries are going to be made and published by someone, but something about the academic field of cryptography keeps striking me as "wow, we're really lucky to have that person in this field". And that's a bit concerning because this phenomenon seems to suggest either that the field is still pretty small or still pretty immature, and in that sense may still be missing several important discoveries, for all the progress that it's made since the early nineties.
Bernstein is a bit of an odd duck in this regard, but if you look at some of the other "great personages of cryptography", you'll see that they're minting PhDs who are themselves going on to do important work, so the capacity of the field is expanding, not contracting to a single Bernstein monoculture point.
Bernstein's position in the field of practical cryptography is a product of an almost monomaniacal focus on commodity hardware performance and ease of use. The Bernstein monoculture will pass --- probably soon, after CAESAR finishes, or if people start taking pq crypto more seriously.
I think I had that sense about individual items there, like Coppersmith's attack.
> if you look at some of the other "great personages of cryptography", you'll see that they're minting PhDs who are themselves going on to do important work, so the capacity of the field is expanding, not contracting to a single Bernstein monoculture point.
That's great news.
It's like a marketing issue to me. He focused on what type of crypto there was a large demand for. His solutions now have the First Mover advantage. Others can still compete although his will stay widely deployed or long-lasting in legacy systems.
It's not just in crypto. I was looking at the guts of web sockets the other day and was like WHY WHY WHY WHY WHY. I usually find myself asking "what problem does this solve?" over and over when I look at modern systems.
Of course even with my strong bias against it I am still occasionally guilty of over engineering. I just rewrote a major system to de-engineer it. I just keep thinking I will need it even when I have YAGNI tattooed on the inside of my eyelids.
Unlike in politics, we've had success with technical solutions: strong E2E encrypted messaging is now normal, TLS is getting massive deployment, we have better crypto in general from key agreement to ciphers to libraries, and so much more.
To compare, what political solutions have equally improved the landscape? What's the political equivalent of getting Curve25519 into the hands of billions of users? What's the political equivalent of Signal Protocol going mainstream?
I've seen this same basic comment a lot in technical circles, and they ~all seem to subtly discredit technical solutions.
It makes me wonder: do people in political groups say, "let's stop with the political solutions and instead learn programming and cryptography and make technical solutions!" I sure hope not.
Just like all of the talk of crypto backdoors were DOA regardless of all the polticial rhetoric about its merits and downsides.
Further explanation:
I think this is the case, but I haven't confirmed it
I kind of feel like your comment here and the one you linked to are a bit of an appeal to authority - for me anyway, I'm no expert in this area, and you appear to know what you're talking about (generally speaking).
But then you added this gem at the end of the link comment:
Enemy action? No. Crypto standards groups don't need enemy action. They are intrinsically evil, and need to be avoided.
Yep, Design by Committee.
I read your comment and I find the topic/context is possiblly too vague or complex to use this as a reference. Not that your not busy enough, but it would be useful for progressing this discussion going forward.
We'd all benefit from not obsessing over crypto standards as lay people and let the professionals handle that for us. I don't have to trust that they'll be honest but trusting that nerds will work towards the optimal technical system is sufficient for me. Instead rather focusing on the implementation issues (or lack there of) that the general HN audience is more inclined to specialize in.
The IPSEC working group discussions I've read are infuriating. I hope it's clear that I believe cryptographic scientists could have improved IPSEC, but were prevented from doing so by cliques in the IETF. That's the "douchebaggery" I'm talking about.
I have different personal feelings about different people involved in this drama. But I don't mean to compound those feelings into the point I'm trying to making. I'm afraid that's what I end up doing when I use words like "douche". So: my apologies. I'd delete that part of my comment if I could.
http://www.mail-archive.com/cryptography@metzdowd.com/msg124...
another one: http://www.mail-archive.com/cryptography@metzdowd.com/msg124...
Reposting spurious allegations years after they've been debunked does not help anyone.
I had no idea this was the case.
Was it worth it? I guess for the stock prices of the contractors and the people the foreign power favors at the time. But everyone else gets screwed.
So who is in control of our country "now"?
"Intel Chiefs Presented Trump With Claims That Russia Has ‘Compromised’ Him" - http://nymag.com/daily/intelligencer/2017/01/cia-presented-t...
Just on face value of that statement, I suggest you temper the urge to emit hyperbole. ["influence" & "control"]
> CIA and FBI.
As far as national defense institutions go, I have far greater trust in the our military than the barely accountable agencies that cloak themselves in secrecy and operate in the shadows.
As far as Russian and their earlier incarnation as Soviets and influencing other nations, /and their populations/, I suggest you stop your (apparent) regiment of taking the word of Corporate media as gospel and acquaint yourself with the methodology of destabilizing target nations as practiced by the Russians. (They are old hands at it.)
Let me assure you: if this nation is destabilized and if well meaning but entirely naive Americans permit yourselves to be used as useful tools of external actors, America & Americans will be the biggest losers.
information allegedly includes a videotape of Trump watching several Russian sex workers urinate on the bed the Obamas slept in at the Ritz Carlton in Moscow.
Really? Who cares.
As to the second point, how dramatic. Russia rigged the US election? I far simpler explanation is that US politics really is on the path suggested in the film Idiocracy. You don't need an external enemy to account for your bizarre politics, yourselves will suffice.
If it's true, that Russia influenced the election, then the major scandal is not that Russia [whatever], rather it's that the US fell for it.
Anyway, I still have trouble getting past the idea that the Electoral College system in the US can result in a president who didn't win the popular vote. Before we go blaming anyone else for anything, perhaps we should get our own affairs in order. Generally speaking.
You believe pissgate was anything more than fanficfion/4chan trolling?
Over engineering is an absolute plague in software. In ordinary cases it just makes things buggy, hard to maintain, and bloated and inefficient. In crypto though the consequences are much more severe since every little ounce of complexity in a cryptosystem exponentially increases the likelihood of exploitable bugs.
DJB's boring crypto talk is worth reading:
Phil Rogaway is one of the world's great cryptographers; it's from him that we get OCB, OAEP, PSS, UMAC, XTS, SIV, and many others. Even non-cryptographers might be familiar with him for his "Moral Character of Cryptography" paper†.
I finagled a spot next to him at a dinner in Chicago once and asked him why he doesn't participate in IETF crypto standards (even with a recent renaissance of CFRG with Kenny Paterson at the helm, more expertise is badly needed). The impression I got from his answer is that he'd foresworn that kind of work.
If you look at his experience trying to contribute to the IPSEC standard, you can see why: he enters mailing list threads making clear, obvious statements about cryptographic soundness --- for instance, "it's a bad idea to chain CBC IVs". He's immediately attacked --- and attacked personally, for instance by being referred to as a "so-called" cryptographer (or something like that; I'm going from memory) by a clique of standards nerds. Rogaway goes so far as to circulate a petition/critique from other cryptographers --- people like Ron Rivest --- and that's shot down as well. The standard is finalized with things like chained IVs in it.
That's not enemy action. Or, if it is, the enemy is the standards process, not the NSA.
That would be an astoundingly stupid thing to say about Phil Rogaway...
It appears that by failing to be as vicious as possible about Phil Rogaway's lack of understanding of the architecture of IPSP that I have inspired people to take him seriously. It also appears that Phil has been lobbying people to have them comment. I can understand how even an intelligent reader, going through his comments, could become confused about the architectural issues here. However, let me say that I found his comments to be almost completely without merit. Other than a few comments about places where the text used ambiguous language (i.e. textual ambiguity) I found almost nothing of value in what he had to say.
Later:
Found it. It's Bill Simpson:
> You do not facilitate analysis
> by saying that Photuris is only required to work when its
> primitives are drawn from a certain concrete set of possibilities;
> exactly the opposite-- you render cryptographic analysis impossible.
>
Thank you, thank you!
It gladdens my heart to hear that *self-described cryptographers* find
that analysis is impossible!
I was worried that there would be some subtle flaw that would facilitate
cryptanalysis. Now that you have assured us that it is not possible,
that makes Photuris the only protocol that has ever come to perfection!
Emphasis mine.The irony is that the IETF was created in part as a reaction to these standards group pathologies. But they're too powerful to resist.
[1] http://theory.csail.mit.edu/ftp-data/pub/ftp/people/rivest/i...
It's just that the consequences of stupidity in crypto are higher, as I said.
Do those people grow on trees? No, because it's a much less common specialisation than most others (like aiming for the financials industry, or statistics/analytics/big data) simply because of the number of paying jobs in each field.
It takes only a few years of mathematical training.
I'm not seeing the legitimate concern here.