Distrustful U.S. allies force spy agency to back down in encryption fight
reuters.com
reuters.com
(The point of both algorithms is to provide scalable low-profile crypto, instantiable at very small key and block sizes; this is something you'd want if you were, for instance, building an encrypted IOT scheme on microcontrollers).
That doesn't mean they should be international standards; maybe it makes sense that after Dual EC, the NSA doesn't have a shot at producing a global standard for low-profile encryption. But however well justified, it's mostly a political decision, not a technical one.
> SIMON and SPECK are both pretty straightforward block cipher designs. You can implement them in less than 100 lines of code.
If I super promise to never let the code off my computer, can you point me to resources to do that for educational purposes?
If you've never implemented a cipher before, they're both pretty good first ciphers to implement. They're simple without being unrealistically simple, like RC4. The paper has test vectors, so you can make sure what you come up with is actually correct.
http://csrc.nist.gov/groups/ST/lwc-workshop2015/papers/sessi...
Is there a good reason to trust the NSA's motivations?
The NSA's stated motivation from the article:
>encryption tools [...] without requiring a lot of computer processing power.
But it was noted that:
>“There are probably some legitimate questions around whether these ciphers are actually needed,” said Curtis Dukes, who retired earlier this year. Similar encryption techniques already exist, and the need for new ones is theoretical, he said.
The NSA's purpose is as a spy agency. No matter how effective that clear coat they're selling you might actually be, they're probably selling you on something you really don't need because it has a benefit to their purpose.
And ultimately, what's the difference between a publicly vetted algorithm proposed by the NSA and a publicly vetted algorithm proposed by someone else?
Everyone points at the Dual EC fiasco, but if vulnerabilities are possible either way it seems like throwing the baby out with the bathwater.
Furthermore, people act like there's a track record of super-sneaky NSA backdoors, and that Dual EC shows we can't trust anything NSA produces. I don't trust the NSA at all. But Dual EC wasn't sneaky. There were only two surprising things about Dual EC:
(1) That they actually managed to get anyone to use it, despite how clunky and slow and unreasonable the design was.
(2) That having produced a design that stuck out like a sore thumb for clunkiness, slowness, and unreasonableness, that design would be their backdoor; we gave them a lot more credit for tradecraft than that.
People knew there was something shady about Dual EC almost from the jump. It is a random number generator that works by encrypting random state with a public key for which the private key is undisclosed. It's obviously weird.
That's not the case with SPECK and SIMON. They're mainstream designs, and, more importantly, if you can hide a backdoor in a simple ARX Feistel block cipher that can be implemented in 100 lines of code, we probably have bigger concerns than these algorithms.
Should you use SIMON and SPECK? Of course not. You shouldn't go anywhere near lightweight ciphers unless you know exactly what you're doing, and if you know exactly what you're doing, there are less politically controversial lightweight ciphers to use. The problem here isn't that the world is being deprived of SIMON and SPECK; it's that we're getting too practiced at turning our brains off.
In the past there was a common idea that NSA's classified research might be a decade or more ahead of the academic world, even in an era when the academic world had gotten interested in crypto in earnest, and that they might know of entire classes of vulnerability that other people didn't. Probably the clearest precedent in support of this concern was differential cryptanalysis.
Recently I've heard more of a suggestion that we understand crypto dramatically better than we used to, that cryptanalysis that appears to be hard generally is hard, and that spy agencies have been migrating largely to side-channel attacks and exploitation of vulnerabilities (and maybe also supply-chain attacks). (The weak Diffie-Hellman thing is apparently not a counterexample because there was open literature giving appropriate defensive guidance about that for many years.) Famously Snowden said that "crypto works" and reportedly leaked very little information about novel cryptanalysis, although there's also the counterargument that he might not have access to the relevant compartments to know how crypto doesn't work.
I've even heard the claim that most of the unknowns for pure cryptanalytic attacks are in some way now known unknowns. At least, academic understanding of the mathematical problems has really matured significantly.
What do you think about this question? If someone said "but what if NSA has the next mathematical breakthrough akin to to differential cryptanalysis, which Nadia Heninger is only going to discover in 2027?", would you say "that's really implausible nowadays given the maturity of our understanding of the math here"?
(And I know Nadia mainly works on number theory and algebra rather than block ciphers.)
* I have been very unimpressed with the quality of NSA "TAO's" tooling, and, when I have conversations with people closer to NSA offensive cyber stuff than I am, what shakes out generally is that they people at the tip of that particular spear tend to be super young people in basically their first ever software job.
* But Stuxnet was sort of impressive.
* But then, what was impressive about Stuxnet was domain knowledge about a particular piece of industrial equipment, not hardcore computer science. The software engineering details of Stuxnet were kind of unimpressive.
* But there's Flame, which is impressive in a CS kind of way.
* NSA's original advantage in these kinds of systems probably stems largely from the fact that they were a monopsony buyer of cryptographic talent for many decades. You'd expect there to be a period of catching up.
* But cryptography is now one of the better known pipelines for applied mathematics research, particularly for people who cross over between math and CS, and there's a lot of those people, so it's hard to see why NSA's advantage would be sustainable over the long term.
* But also NSA does have a sustainable advantage in the kinds of cryptanalytic work that can only be done with massive, specialized compute resources, and for all I know when you can casually conduct research on gigantic ASIC clusters as easily as I can fire up Sage and add generate a curve point, you learn a whole bunch of stuff that is broadly applicable.
* But academics get to collaborate directly with everyone in their field and NSA not so much, which is a mitigating factor.
I think it's very healthy that we assume that NSA has space-alien capabilities. It adds rigor to our security models. And again I don't think we should use things like SIMON and SPECK.
I just don't think we have to stop talking about the engineering aspects of SIMON and SPECK simply because they came from the NSA.
Are you trying to find out who the TAO employees on HN are? They'll be itching to defend themselves.
In the past decade, I can think of 2 sort of new general cryptanalytic attacks: invariant subspace attacks, and the division property. The division property didn't really break anything; it claimed a full break of MYSTY1 with complexity 2^70, in case you happen to have the entire codebook already. It doesn't work well mostly for the same reason cube attacks haven't: most cipher designers know how dangerous a low algebraic degree can be.
The invariant subspace attack has been more successful, mainly in the lightweight space, mostly because it exploits the symmetries that tend to make a design smaller and elegant. But once again, against vetted ciphers it has not done so well.
So let's posit the NSA does have another couple of attacks in hand we don't know about. Chances are they're not going to be very useful. Do they specifically affect SIMON and/or SPECK? It would require an intersection of conditions that seems very implausible, and it seems tricky to have it affect both designs at the same time without being noticeable. But I guess we'll know in 2027.
In another note, if I was going to make a cipher with a hidden weakness to dupe the world into using, I probably wouldn't go with a block cipher---literally the most heavily analyzed kind of primitive in the public sphere. I would probably go with a stream cipher, or a stream-like dedicated authenticated cipher, whose security is much less studied than block ciphers, and can still be used in most places a block cipher would be.
By the way, I have the feeling that these attacks are more the consequence of these sort of designs becoming more popular than any particular breakthrough in cryptanalysis. For example, the symmetry properties of the AES round were already well known long ago, but it wasn't until people started taking the AES round and building primitives out of it without adding symmetry-breaking constants that this became a problem.
[1] https://eprint.iacr.org/2015/068
If someone has gotten a jump on research and found a novel attack against their math, but the math looks good enough to convince others to use, that is an enormous advantage.
The "unknowable secret math" argument works both ways. As I said upthread: if you believe this, how do you rule out the possibility that ARX designs are the ones NSA can't break, that they have secret math that only works against iterated ciphers built solely on bitwise primitives, and that they published this particular cipher --- something they rarely do! --- precisely to create the kind of suspicion we're seeing on the thread?
If you want to play Kremlinology instead of talking about engineering, arguments like that are fair game too. I'd rather rule both of them out.
Isn't the bigger concern that the NSA may be proposing these because they already know how to break them, and not necessarily that they'll sneak back doors into implementations?
It wasn't a backdoor, but doesn't this sound a lot like SHA-0? The NSA fixed the mistake and published SHA-1, but they didn't say why. They might as well have designed the cyphers a similar issue and kept it hidden.
SIMON and SPECK have been analyzed by the wider cryptography community, but in principle something like the above wouldn't be surprising from the NSA...
If you're asking, "do we actually need lightweight ciphers", well, the NSA isn't the only organization designing them; it's a whole field of research. If you want cryptographic security on machines that don't have multipliers and count their capacity for program text space in single-digit kilobytes, you're probably going to reach for special-purpose designs.
It seems that taking motivations into account could lead you into a false sense of security, but that if you keep up the same amount of security and distrust known bad actors that you increase it.
If your response to this is "don't worry about it, its unlikely these ciphers are backdoored", you are missing the point.
Probably only other algorithm with similar level of scalability which was openly peer reviewed is RC5. In comparison to Speck/Simon, RC5 is significantly more complex (due to it's key schedule) and is not constant time on platforms without barrel shifter. (X)TEA and such things can be similarly tuned for various block and key sizes, but there are no recommended parameters for doing that and thus you get into the "rolling your own crypto" territory very fast.
The weak modes, though! A 32-bit block(!), 64-bit key, and 22 XOR/add/XOR rounds is just an excuse to say you have int'l standard crypto despite it being painfully weak.
If we see demand for a standard cheaper than hardware AES or software ChaCha20 (or 12 if you live dangerously), we should pick one in an open process like the many we've had.
To the extent industry is calling for cheaper crypto, there are some existing civilian candidates (like the eSTREAM hardware profile though I haven't seen much interest in it), or we could have an open competition, responding to what civilian security folks say they're missing. You could definitely get, e.g. gate area down vs. AES or ChaCha without sacrificing sane block/key sizes.
As you note, and as I mentioned above, some standards processes have already picked some ciphers meant to be better for constrained environments than those two. The ones I know about (as a nonspecialist!) still use higher parameters than smallest versions of Simon/Speck. PRESENT, accepted by the same committee, has an 80-bit key and 64-bit block, for example, and eSTREAM has its 80-bit hardware profile. That's the "smaller primitives that still have sane-ish params" I was talking about. The smallest Simon/Speck variants go lower, and seem like skating too close to the edge to recommend and standardize, even if there's somewhere they're the right/only fit.
After posting the comment you replied to, I found a PDF from IAD that suggested that the 32/64 block/key size was never going to be submitted to the ISO committee because they have a minimum key size of 80 bits, and 48/96 was canned out of technical concern about the 48-bit block. (Posted it as a self-reply (a...great-uncle? of this comment), because it was too late to edit.) What they wrote actually makes dropping the weaker versions sound a lot less contentious than the Reuters story does, though of course it's one party's version of the story. And the continued pushback from some countries to the 128/256 versions clearly has other causes.
If you mostly just want to dunk on me, I'm sure I've said something wrong here, but not wanting to standardize very low parameters at least isn't the same as just not being aware of lightweight crypto.
The grump in me still sees a pretty narrow niche for this sort of algo (like, maybe most considering it should just be using AES?), but whatever.
“I don’t trust the designers,” Israeli delegate Orr Dunkelman, a computer science professor at the University of Haifa, told Reuters, citing Snowden’s papers. “There are quite a lot of people in NSA who think their job is to subvert standards. My job is to secure standards.”
Chris Mitchell, a member of the British delegation, said he supported Simon and Speck, noting that “no one has succeeded in breaking the algorithms.” He acknowledged, though, that after the Dual EC revelations, “trust, particularly for U.S. government participants in standardization, is now non-existent.”
“How can we expect companies and citizens to use security algorithms from ISO standards if those algorithms come from a source that has compromised security-related ISO standards just a few years ago?” - Christian Wenzel-Benner.
These are coming from Israel, Britain, and Germany - all close US allies.
I'm not a crypto guy, but I looked at Speck. The code is really clean and efficient. If it's secure that's really awesome. But how is anyone supposed to trust it given the past actions of its creator?
Also keep in mind that the DUAL_EC backdoor was discovered within a year of its publication; SIMON and SPECK were published years ago and nobody has found or suggested a backdoor (plenty of people have been analyzing the ciphers). ARX designs have been proposed by plenty of other cryptographers, so nothing about the SIMON or SPECK designs would immediately raise eyebrows other than the fact that the NSA proposed them.
Personally, I doubt that the effort to subvert standards involves backdoors, which are pretty hard to hide and pretty easy to avoid (DUAL_EC is the only credible candidate for a backdoor, it was discovered quickly, and it was not widely used). It seems more likely that the effort involves (this is all speculation):
1. Making standards more complex than necessary.
2. Making standards more sensitive to bad randomness (e.g. DSA signatures).
3. Making standards where constant-time implementations are harder or slower.
In other words, they have pushed for standards that are harder to securely implement and easy to use insecurely. Why bother with backdoors when you can exploit common and easy-to-make mistakes? Given their expertise in spotting and exploiting these kinds of bugs, the NSA can probably satisfy the "information assurance" mission by vetting / correcting implementations used by the government, at least for the most important government secrets (most government communication would just use COTS; of course, most government communication is of limited value to foreign governments).
One could get out their tinfoil hat (as another posterdid) and suggest that the allies are publicly questioning it so people don't adopt simple and secure encryption. After all, the result of their vote is that it does not become a standard.
In the end we have to go by actual analysis. As it should be.
I would have presumed a lack of trust was the default mentality when evaluating any security based algorithm -- after all any CS professor could be in the NSA's pocket.
They're "lightweight" block ciphers; SIMON is designed for optimal performance in hardware implementations, and SPECK for software. According to the NSA PDF, "The relatively new field of lightweight cryptography addresses security issues for highly constrained devices." Indeed, SIMON is about a third of the hardware gate requirement of AES, and SPECK is about 15% the number of flash bytes. Some of the space savings is from skipping ciphertext/plaintext whitening.
https://en.m.wikipedia.org/wiki/Key_whitening
Presumably something like rot13 would count as whitening? Also, assuming the name comes from analogy with "white noise", ie reducing signal quickly, cheaply?
Say you encrypt a message M with key K1 and get encrypted message E: encrypt(M, K1) = E. An attacker might brute force your encryption, if your key space is small this might be an issue. So what you can do is XOR the message with another key K2 before encryption and a third key K3 after encryption to get: E = encrypt(M XOR K2, K1) XOR K3. Now the attacker has three keys to brute force. (though I think the actual effective key size is between 2x and 3x the length if the attacker knows the message distribution)
I'm not an expert but I imagine XOR is popular because it's a basic logical operator and so has gate level hardware implementations.
Maybe the "most robust" version is harder for the NSA to break, maybe the NSA doesn't know of a way to break it, or maybe the NSA just proposed the lightweight versions so they'd have room to negotiate, and have just achieved exactly what they hoped.
I'm glad other countries are suspicious of the NSA, but I'm not sure that distrust goes far enough.
Bruce Schneier's [thanks tptacek] 2013 opinion on the presence of an NSA-known backdoor: "maybe, but I don't think so."
His post today is also interesting, saying the ISO "rejects" (which seems a bit stronger than the source article): https://www.schneier.com/blog/archives/2017/09/iso_rejects_n...
He concludes [2017]: "I don't trust the NSA, either."
This is one of those things where, if NSA can break 128/128 SPECK, we probably have bigger problems than SPECK.
Instead of blindly supporting or rejecting an author, we should insist on public crypto competitions which are the best route for obtaining well-tested, studied, and trusted ciphers.
There are decent correlations between:
* crypto that's been de jure standardized before deployment and bad crypto (DUAL EC, DNSSEC, etc.)
* crypto that's been through a public competition before deployment and good crypto (Salsa20, Argon2)
* crypto that's been de facto standardized and good crypto (Curve25519, Signal protocol, etc.)
As an aside, high-level APIs like in NaCl, libsodium, libtls (from LibreSSL), etc. are a new, in-progress form of de facto standardization. It would be hard to introduce a new low-level general-purpose crypto library and attract major adoption."The Americans distributed a 22-page explanation of its design and a summary of attempts to break them"
That doesn't really sound like a peer review :)
https://scholar.google.com/scholar?hl=en&q=speck+cipher&btnG...
In any case, it seems like the NSA was dragging its feet in trying to fully explain the designs (from the OP):
> Finally, at a March 2017 meeting in Hamilton, New Zealand, the Americans distributed a 22-page explanation of its design and a summary of attempts to break them - the sort of paper that formed part of what delegates had been seeking since 2014.
Given they're more recent history, I'd be mistrustful. It seems to me that the design of a good cipher should be done totally in the open, so any vulnerabilities are inadvertent. This includes explaining the design and the decisions and trade-offs that brought you there.
Implausible, considering that the mathematical attacks NSA is aware of but designing ciphers to be resistant to are still classified and currently being used by the NSA against older generation ciphers.
See history of differential cryptanalysis and DES design.
I find it exceedingly unlikely that the NSA is years ahead of public efforts on this front in 2017.
Everything known by the public is also known by the NSA, but the NSA only tells the public what it wants them to know.
That practically guarantees that there is a lot they know that we don't.
Of course that proves nothing about this specific instance, and measuring "how far ahead" in years is hard, but I think it is likely the NSA has some extremely sophisticated techniques that we know nothing about.
Whereas the public community is made stronger by its interactions.
They are all going to be peer reviewed before becoming a standard like AES was reviewed, and they are much less complex. I view political subversion of the technical process as a bigger issue.
Paranoia is fine, but you have to pick your battles.
It seems though, regarding the complex dependency on encrypted information, abuse can have epic results in a very short time.
Everybody can purchase a huge analysis network in minutes and have the information crunched in almost any way possible. Maybe paranoia, but quite possible as well.
You'd think deliberately compromising the goals of the body in such a cavalier fashion would do it.
Notes on the design and analysis of Simon and Speck
Ray Beaulieu Douglas Shors Jason Smith Stefan Treatman-Clark Bryan Weeks Louis Wingers
June 8, 2017
Note. This document was prepared by the designers of Simon and Speck in order to address questions regarding the design rationale and analysis of the algorithms.
What record of inspections and promises would convince you to buy?
The NSA provides that record https://eprint.iacr.org/2017/560.pdf
We currently know of no technical reason to reject the ciphers.
On the other hand this seems like deliberate design choice in order to remove any unexplained constants from the design (the counter in the key schedule seems "explainable"). Alternative with the same design would be to supply the key into the key schedule as subkeys (cyclically or so), which would then mean that initial state is some kind of unexplained constant (there is good reason why {0,0} is not good initial state and given the fact that it comes from NSA any other value will seem suspect)
Edit: the fact that key schedule is invertible does not decrease the security as long as it is used as block cipher (in fact on this level of analysis it slightly increases the confidence in the design as long as it is only meant as block cipher). On the other hand it means that insecure constructions of hash function from block cipher are probably not only theoretically insecure, but readily breakable by NSA. (I wouldn't be surprised if this was the motivation of NSA, because for many IoT applications one is more interested in authentication than in confidentiality)
Both NSA and CIA had their crown jewels stolen and exposed, yet they assume that states like China and Russia (to name a few) don't have the ability to find these bugs. Heads should roll