NIST announces preliminary winners of post-quantum competition
feistyduck.com
feistyduck.com
The winner for signing stuff: https://pq-crystals.org/dilithium/index.shtml
Digital Signatures standardized: Falcon SPHINCS+
Advancing to Round 4 (Key Exchange):
BIKE Classic McEliece HQC SIKE
There will also be another program for post-quantum Digital Signature schemes with smaller signature size.
Dilithium: Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, Peter Schwabe, Gregor Seiler, and Damien Stehlé
Kyber: Roberto Avanzi, Joppe Bos, Léo Ducas, Eike Kiltz, Tancrède Lepoint, Vadim Lyubashevsky, John M. Schanck, Peter Schwabe, Gregor Seiler, and Damien Stehlé.
1312+ byte public keys are gonna suck badly for a lot of applications. hopefully, SPHINCS+ becomes ubiquitous (although it also isn't great comparing to ECC due to large 8 KiB signatures), or another similar alternative emerges
NIST will soon observe them to announce the final winner.
This great news for all teams involved, including the team members behind Falcon who some of them have developed the Algorand blockchain, which most highly likely be using Falcon for quantum resistance for many years to come.
"Issues relating to patents were a factor in NIST’s decision during thethird round as NIST became aware of various third-party patents. As noted in Section 2.2.3, NIST negotiated with several third parties to enter into various agreements to overcome potential adoption challenges posed by third-party patents."
And elsewhere in the report:
"In addition, NIST has engaged with third parties that own various patents directed to cryptography, and NIST acknowledges cooperation of ISARA, Philippe Gaborit, Carlos Aguilar Melchor, the laboratory XLIM, the French National Center for Scientific Research (CNRS), the University of Limoges, and Dr. Jintai Ding. NIST and these third parties are finalizing agreements such that the patents owned by the third parties will not be asserted against implementers (or end-users) of a standard for the selected cryptographic algorithm. NIST appreciates the efforts of those who helped obtain this outcome and the cooperation of the third parties."
So yeah, NIST realized part way through the competition that various 3rd party patents might conflict with KYBER and is trying to de-conflict. It seems like NIST probably got various 'handshake level' agreements before selecting KYBER (otherwise they would just be... really really irresponsible), and is trying to get the final signed agreements done.
https://nitter.net/hashbreaker?lang=en
For FIPS in particular, they've first gotta sunset the traditional algorithms for anyone to strictly need to care (and even then, parallel constructions of PQC+traditional could let other PQC algorithms in -- like the Chrome experiments -- from a FIPS perspective, you can treat the PQC like plaintext). And for them to be useful, adoption needs to occur in the IETF communities (PKIX, TLS, SSH, IKE, ...).
You're probably looking at least 5 years on the adoption window to customers running the lastest updates. NIST's blessing might help some of the IETF conversations that now need to happen. But not listening to DJB, given his track record, likely will anger a subset of IETF contributors and might hinder adoption.
It'll be interesting to see if IETF takes the more conservative approach advocates by DJB or if they continue on with NIST's blessing alone. But I'm just a watcher... :-)
Edit: and for the record, FIPS never mandated Dual EC DRBG but it was still a mistake for NIST to rubber stamp.
> (IDK what the TLS (and FIPS) PQ Algo versioning plans are: 1.4, 2.0?)
Kyber, NTRU, {FIPS-140-3}?
It looks more like a frantic attempt to get a back door into crypto in response to some post-9/11 mandate from a technically ignorant Congress than evidence for the hyper-competent super-intelligent NSA of Hollywood fiction.
Congress: "Backdoor crypto but don't tell anyone!"
NSA: "Won't work. Cryptographers will notice."
Congress: "We just added it as a line item buried in a bill about regulating the crunchiness of pork rinds. It's now a legal mandate."
NSA: "Okay, but people are gonna notice because math is math."
Congress: "Here's a billion dollars. Now go make a different math. Call it freedom math."
The rest of NIST's portfolio looks relatively sane. AES, SHA2, and SHA3 have received years and years of heavy duty cryptanalysis and have enormous implicit "bug bounties" on them by virtue of what one could steal if they could be effectively attacked. The NIST ECC curves are a frequent target of speculation about being backdoored but I've seen several cryptographers argue that if they are it means we really shouldn't use ECC at all. It would mean the NSA knows something very significant about ECC that is still after all these years (the NIST curves are two decades old) far beyond what the academic community knows.
Are there better things today outside NIST? To some extent. ARX ciphers and hashes have become immensely popular. They have the really nice properties of being efficient without special hardware (unlike AES) and being fairly side channel resistant. AES is still massively faster (2-4X) with hardware support though. In terms of cryptographic strength ChaCha has some theoretical advantages due to the wide (512-bit) state vector but neither AES nor ChaCha have anything that even smells like a practical attack against common (correct) use cases. In practice they're probably about the same.
Unless your cryptographic design is just broken or unless you are using a very weak cipher like single-DES or RC4, you are many many orders of magnitude more likely to be attacked via a bug in the implementation, a side channel, supply chain attacks, or some form of automated or targeted social engineering (phishing, spear phishing, social engineering, etc.). It's usually easier to con humans than break cryptography.
Edit: what the Snowden documents mostly showed is that the NSA has a huge trove of zero day exploits and that they tend to hoard them. They're sort of like a multi billion dollar state backed hacking group and most of what they do is not unlike what organized crime hacking groups do.
We also know that the NSA has relationships with industry. With so much reliance on cloud services and man-in-the-middle CDNs like Cloudflare the obvious way to compromise stuff would be to directly tap systems where they are not encrypted at all. You might have Wireguard with extra hipster super cryptography but who cares if the NSA can download everything from "your" cloud or push malware to your machine via any one of the dozens of package managers you implicitly trust?
There was a recent paper linked on HN that goes into a lot of the nuance around this question. It's very good (IMO, as an interested outsider):
Of course I can't do the verification myself. But there are people (stand up, DJB) who can, and I can pay attention to their observations. So perhaps "Trust, but verify by proxy". But that wouldn't have been recognisable as the well-known cold-war slogan...