Recommendations from the NSA find their way into standards that are implemented by the government itself, and that is one of the reasons the community trusted the NSA to a degree. It wasn’t seen as being in their long-term self-interest to insert backdoors that others could find into their standards.
Obviously that trust was wiped out by the DUAL_EC_DRBG debacle, although many cryptographers still believe it’s worthwhile to analyze and consider NSA ciphers on their own merits just as you would a cipher by DJB.
In my personal opinion, as a general rule, I would wager that symmetric ciphers published by them can be reasonably assumed to be free of back doors, since there’s fewer degrees of freedom to insert them except through real cryptographic weaknesses which others could independently discover. Asymmetric algorithms probably shouldn’t be given this benefit of the doubt, since there are enough degrees of freedom to be possible to have a private master key of sorts (e.g., DUAL_EC_DRBG) which isn’t be able to be discovered independently and can only be revealed if it’s stolen directly.
Which is true and commendable; however, in the exact same system they proposed weakening the key from 64bits to 48bits. IBM split the difference and we got 56bit DES.
Or at least, that was the later justification.
1. Gain access to information where that would be in US interests.
2. Protect US information from being accessed by others.
From their web site ( https://www.nsa.gov/about/faqs/about-nsa-faqs.shtml ):
> NSA/CSS has two interconnected missions: Signals Intelligence (SIGINT) and Information Assurance (IA). Through SIGINT, we respond to customer requirements for information relating to the plans, intentions, capabilities, and locations of foreign powers, organizations, terrorist groups, or persons, or their agents, who threaten America’s national security. Under Information Assurance, we protect our nation’s vital national security systems and information from theft or damage by others.
Whether you trust them is another question. Many argue that this dual mission creates an inherent conflict of interest. But if you believe they take both halves of it seriously, you might see them as having a legitimate interest in ensuring good crypto is available. (I'm not advocating for that position, but it doesn't seem totally irrational to me either.)
This "dual-mission" thing reminds of some tv networks presenting "equal sides" on a debate on climate change. In 99% of the cases, the NSA will choose to keep its vulnerabilities for computers rather than try to fix or disclose them.
So, dual nature is misleading unless you're a defense contractor or agency. The SIGINT group has all the money, power, and executive backing. That last part means even IAD's honest folks will get overruled at some point forced to compromise somehow. There's definitely people trying with the security guides, funding things like Cryptol, and so on.
After all AES is endorsed by the US government as well (although not designed by them, admittedly), yet we trust it because we have no reason not to.
While the NSA has an obvious incentive to be able to break encryption they also have an incentive to be able to use ciphers than are fast and not easily broken. Well, I suppose ideally they'd like a cipher that only they can break, which might be what's going on here.
So while I don't think NSA's proposals for a new cipher shouldn't be dismissed merely because it comes from them it should obviously be met with the highest amount of skepticism and scrutiny. No stone left unturned. Fortunately it seems that's exactly what happened there and the ciphers were rejected.
That is not true, the only way we know how to assess a cipher's security is to basically attack it and add a margin of security on top of the best attack you find. If the NSA has built its cipher on top of a flaw that only they know, and if third party research hasn't found the flaw then we're doomed.
That's a joke. First off, we don't even know how NIST obtained this "magical" large number that we're supposed to trust it creates a safe formula for the P-256 curve:
y^2 = x^3-3x+41058363725152142129326129780047268409114441015993725554835256314039467401291
Second, the NSA refused to reveal certain technical details that they should have been able to reveal to the ISO: https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/
So it's not all "just maths". Otherwise all of these people wouldn't be so suspicious about it.
It's not all about the design, either, even if it was 100% transparent. But about how secure it actually is. We don't really know how secure an algorithm is, even as it passes a competition or standardization process. We have to see it in the real world, but once it's in the real world and everyone adopts it, it could take at least 10-15 years to get rid of it from most places.
The NSA refused to reveal how Simon and Speck would resist against certain attacks. They kind of did the same with IPSEC, where they made it super-complex so that the implementers would almost always get it wrong, which means they'd leave holes in there that the NSA could exploit. This is how they muddied the waters in the standardization processes. It's their MO when they can't introduce an actual backdoor - they just design a crypto algorithm that looks okay on the surface, but hides high potential dangers:
https://www.mail-archive.com/cryptography@metzdowd.com/msg12...
Also this seems to perfectly describe how I've already thought the NSA would act. Why would anyone ever trust them when they act like this? It's quite strange to still see so much support here despite of this:
> When some of the design choices made by the NSA were questioned by experts, Ashur states, the g-men's response was to personally attack the questioners, which included himself, Orr Dunkelman and Daniel Bernstein, who represented the Israeli and German delegations respectively.
> Ashur further alleged that the NSA had plied the relevant ISO committee with "half-truths and full lies" in response to concerns, and said that if the American delegation had been "more trustworthy, or at least more cooperative, different alliances would have probably been formed."
> Instead, he says, "they chose to try to bully their way into the standards which almost worked but eventually backfired."
https://www.theregister.co.uk/2018/04/25/nsa_iot_encryption/
There is a name for the kind of table below but I have forgotten it. Essentially on the balance of outcomes, a situation (of engineered choices, of course!) where the NSA is involved still produces, given unknown factors, a potentially better outcome than a situation where the NSA is excluded.
Bad = 0.1, Fair = 0.5, Excellent = 1.0
Cipher Author | Known Weak | Security | Likelihood | Security*Likelihood |
Academia | No | Excellent | Bad | 0.1
Academia | Nationally | Fair | Fair | 0.25
Academia | Internationally | BAD | Fair | 0.05
NSA | No | Excellent | Fair | 0.5
NSA | Nationally | Fair | Fair | 0.25
NSA | Internationally | BAD | Bad | 0.01
SUM(academia) = 0.31
SUM(nsa) = 0.76
(Does anyone know what this kind of table is called? Can someone do a version that makes more sense? It's 4am and quite a few beers were involved :))This isn't how security works. When the term "secure" is used, it is relative only to a threat model. Typically these threat models are implied, but different perspectives, levels of experience and communication barriers often see that this non-precise term causes confusion and mistakes.
In the case of cryptography, the implied "security" of a cipher differs wildly across many different properties (the security margin the design, the caveats to its correct use, the modes it is used with, it's likelihood to be implemented properly, etc.
One of the properties is how the integrity or confidentiality of the schemes fail to different types of adversaries - and who are trusted parties to the data security layer.
All of this is to say that - if our threat model includes intelligence agencies and mass surveillance - the NSA is not able to provide encryption that can be trusted to be secure.
I guess we could add more score levels to make it more explicit, but I'm pretty sure that beer-addled table has bigger problems