Those are not strong encryption standards. They have dual key escrow such that the government can backdoor the connection with their own key. Those are China made encryption standards for use primarily with government products but they are attempting to also force them on the general public.
> I don't see any clues stating that China forbids encryption technology with a key greater than 256 bits.
That is exactly what this results in, because your choice is either a government backdoored encryption method (which basically means it isn't encrypted at all) or a non-backdoored encryption method that is limited to a key size no greater than 256 bits.
I will note, with this over reliance on dual key escrow. If a foreign government were to steal that key through espionage without China's knowledge, it would let say the US government to backdoor China's own government communications.
Why would a government use key escrow for its own internal encryption (for actual important communications, as opposed to "retail" business functions like running garbage pickup operations)?
Because governments (especially dictatorships) are most scared of their own members who can possibly seize power.
So to answer the question, the govt is not using key escrow for its own internal communications. Because it isn’t a monolith, and it’s not internal. The different fiefs need to be watched as much as anyone else.
I guess that's a nit against the post title, but I don't think it really clarifies much.
So they have domestic >256bit ciphers, and this restricts foreign equipment that uses >256bit ciphers. China also has an extensive domestic surveillance system, has lots of weird "national security" regulations (e.g. they use an obfuscated coordinate system for public maps, and IIRC it's illegal to use a GPS receiver for anything resembling mapping), and is also pretty protectionist.
What's the purpose of these regulations? Is it...
1. To further strengthen domestic surveillance by encouraging the use of (possibly compromised) domestic encryption equipment, or...
2. protect domestic industry by making certain technology imports difficult, or encourage foreign entities to buy Chinese technology for interoperability reasons, or...
3. discourage the domestic use of foreign equipment on national security grounds (e.g. foreign backdoors), or use interoperability or market-access concerns to weaken foreign equipment, or...
4. all of the above?
On a side note, my own encryption software is now prohibited in China, but that hardly matters. I don't recall having any customer in China anyway.
A QC large and stable enough to run Grover's Algorithm would be a problem for symmetric keys and hashes smaller than about 192 bits. Most cryptographers recommend 256-bit or larger for a good margin of safety.
Asymmetric crypto is more complex story.
Sure log4j might have been recently patched, but it's not unrealistic to think that a nation-state has access to similar exploits.
This is not an argument for using shitty cryptography, but it is IMHO an argument for being more afraid of the implementation and the human beings using it than the crypto.
Unless we get quantum computers. Then what happens with AES-256?
While FB have many customers in China (much as Google do), I don't believe that they have any actual data centres, and they certainly don't have any (official) users.
Also FIPS 140-2 is outdated, please see FIPS 140-3.
Perhaps there is a rule that prevents someone in China from implementing any algorithm they want to implement with any number of bits they want to use, but that rule would hardly be an "import control", which is what the linked article is about.
Is there any well-defined, well-implemented cipher with a keysize of >256. AFAIR the AES is either 128 or 256.
That seems more (rightfully) careful than draconian..
Submitted title was "China forbids data encryption using a key greater than 256 bits". Submitters: please follow the site guidelines, which ask "Please use the original title, unless it is misleading or linkbait; don't editorialize."
https://news.ycombinator.com/newsguidelines.html
If you want to say what you think is important about an article, that's fine, but do it by adding a comment to the thread. Then your view will be on a level playing field with everyone else's: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...