Furthermore, people act like there's a track record of super-sneaky NSA backdoors, and that Dual EC shows we can't trust anything NSA produces. I don't trust the NSA at all. But Dual EC wasn't sneaky. There were only two surprising things about Dual EC:
(1) That they actually managed to get anyone to use it, despite how clunky and slow and unreasonable the design was.
(2) That having produced a design that stuck out like a sore thumb for clunkiness, slowness, and unreasonableness, that design would be their backdoor; we gave them a lot more credit for tradecraft than that.
People knew there was something shady about Dual EC almost from the jump. It is a random number generator that works by encrypting random state with a public key for which the private key is undisclosed. It's obviously weird.
That's not the case with SPECK and SIMON. They're mainstream designs, and, more importantly, if you can hide a backdoor in a simple ARX Feistel block cipher that can be implemented in 100 lines of code, we probably have bigger concerns than these algorithms.
Should you use SIMON and SPECK? Of course not. You shouldn't go anywhere near lightweight ciphers unless you know exactly what you're doing, and if you know exactly what you're doing, there are less politically controversial lightweight ciphers to use. The problem here isn't that the world is being deprived of SIMON and SPECK; it's that we're getting too practiced at turning our brains off.
In the past there was a common idea that NSA's classified research might be a decade or more ahead of the academic world, even in an era when the academic world had gotten interested in crypto in earnest, and that they might know of entire classes of vulnerability that other people didn't. Probably the clearest precedent in support of this concern was differential cryptanalysis.
Recently I've heard more of a suggestion that we understand crypto dramatically better than we used to, that cryptanalysis that appears to be hard generally is hard, and that spy agencies have been migrating largely to side-channel attacks and exploitation of vulnerabilities (and maybe also supply-chain attacks). (The weak Diffie-Hellman thing is apparently not a counterexample because there was open literature giving appropriate defensive guidance about that for many years.) Famously Snowden said that "crypto works" and reportedly leaked very little information about novel cryptanalysis, although there's also the counterargument that he might not have access to the relevant compartments to know how crypto doesn't work.
I've even heard the claim that most of the unknowns for pure cryptanalytic attacks are in some way now known unknowns. At least, academic understanding of the mathematical problems has really matured significantly.
What do you think about this question? If someone said "but what if NSA has the next mathematical breakthrough akin to to differential cryptanalysis, which Nadia Heninger is only going to discover in 2027?", would you say "that's really implausible nowadays given the maturity of our understanding of the math here"?
(And I know Nadia mainly works on number theory and algebra rather than block ciphers.)
* I have been very unimpressed with the quality of NSA "TAO's" tooling, and, when I have conversations with people closer to NSA offensive cyber stuff than I am, what shakes out generally is that they people at the tip of that particular spear tend to be super young people in basically their first ever software job.
* But Stuxnet was sort of impressive.
* But then, what was impressive about Stuxnet was domain knowledge about a particular piece of industrial equipment, not hardcore computer science. The software engineering details of Stuxnet were kind of unimpressive.
* But there's Flame, which is impressive in a CS kind of way.
* NSA's original advantage in these kinds of systems probably stems largely from the fact that they were a monopsony buyer of cryptographic talent for many decades. You'd expect there to be a period of catching up.
* But cryptography is now one of the better known pipelines for applied mathematics research, particularly for people who cross over between math and CS, and there's a lot of those people, so it's hard to see why NSA's advantage would be sustainable over the long term.
* But also NSA does have a sustainable advantage in the kinds of cryptanalytic work that can only be done with massive, specialized compute resources, and for all I know when you can casually conduct research on gigantic ASIC clusters as easily as I can fire up Sage and add generate a curve point, you learn a whole bunch of stuff that is broadly applicable.
* But academics get to collaborate directly with everyone in their field and NSA not so much, which is a mitigating factor.
I think it's very healthy that we assume that NSA has space-alien capabilities. It adds rigor to our security models. And again I don't think we should use things like SIMON and SPECK.
I just don't think we have to stop talking about the engineering aspects of SIMON and SPECK simply because they came from the NSA.
Are you trying to find out who the TAO employees on HN are? They'll be itching to defend themselves.
In the past decade, I can think of 2 sort of new general cryptanalytic attacks: invariant subspace attacks, and the division property. The division property didn't really break anything; it claimed a full break of MYSTY1 with complexity 2^70, in case you happen to have the entire codebook already. It doesn't work well mostly for the same reason cube attacks haven't: most cipher designers know how dangerous a low algebraic degree can be.
The invariant subspace attack has been more successful, mainly in the lightweight space, mostly because it exploits the symmetries that tend to make a design smaller and elegant. But once again, against vetted ciphers it has not done so well.
So let's posit the NSA does have another couple of attacks in hand we don't know about. Chances are they're not going to be very useful. Do they specifically affect SIMON and/or SPECK? It would require an intersection of conditions that seems very implausible, and it seems tricky to have it affect both designs at the same time without being noticeable. But I guess we'll know in 2027.
In another note, if I was going to make a cipher with a hidden weakness to dupe the world into using, I probably wouldn't go with a block cipher---literally the most heavily analyzed kind of primitive in the public sphere. I would probably go with a stream cipher, or a stream-like dedicated authenticated cipher, whose security is much less studied than block ciphers, and can still be used in most places a block cipher would be.
By the way, I have the feeling that these attacks are more the consequence of these sort of designs becoming more popular than any particular breakthrough in cryptanalysis. For example, the symmetry properties of the AES round were already well known long ago, but it wasn't until people started taking the AES round and building primitives out of it without adding symmetry-breaking constants that this became a problem.
[1] https://eprint.iacr.org/2015/068
If someone has gotten a jump on research and found a novel attack against their math, but the math looks good enough to convince others to use, that is an enormous advantage.
The "unknowable secret math" argument works both ways. As I said upthread: if you believe this, how do you rule out the possibility that ARX designs are the ones NSA can't break, that they have secret math that only works against iterated ciphers built solely on bitwise primitives, and that they published this particular cipher --- something they rarely do! --- precisely to create the kind of suspicion we're seeing on the thread?
If you want to play Kremlinology instead of talking about engineering, arguments like that are fair game too. I'd rather rule both of them out.
Isn't the bigger concern that the NSA may be proposing these because they already know how to break them, and not necessarily that they'll sneak back doors into implementations?
It wasn't a backdoor, but doesn't this sound a lot like SHA-0? The NSA fixed the mistake and published SHA-1, but they didn't say why. They might as well have designed the cyphers a similar issue and kept it hidden.
SIMON and SPECK have been analyzed by the wider cryptography community, but in principle something like the above wouldn't be surprising from the NSA...