Mathematician warns US spies may be weakening next-gen encryption
newscientist.com
newscientist.com
There's our problem - right there!
If a body as important as NIST is not so utterly transparent that any random interested person cannot comb through every meeting, memo, and coffee break conversation then it needs disbanding and replacing with something that properly serves the public.
We have bastardised technology to create a world of panopticonic surveillance, and then misused it by scrutinising the private lives of simple citizens.
This is arse-backwards. If monitoring and auditing technology has any legitimate use the only people who should morally (though willingly) give-up some of their privacy are those that serve in public, in our parliaments, councils, congress, government agencies and standards bodies.
> All we can do is tell people
No. You can prove it, and if you cannot, step aside for leadership better suited to serving the public interest.
Frankly, I would assume any modern encryption is compromised by default - the gamble is just in who compromised it and how likely it would be that they want access to your data.
The original argument is not "they created encryption that isn't broken before". The argument is "encryption created by competitions that are only refereed by NIST is trustworthy"
Blake2 was not created (December 2012) until after the SHA-3 competition, which ended on October 2012 (Keccak being the winner). It was Blake1 that was entered. Blake3 was released in 2020.
I'm sure a Keccak2/3 could have also been better than the original Keccak1, but that was not available either.
For high entropy inputs, like for a HMAC signature, you want the hash to be fast because its practically impossible to brute force the 256bit input key, and you often apply this to large inputs.
SHA-1 SW according to smhasher is 350mib/s as is MD5, so never use MD5 as SHA-1 is always stronger (sha2 supposedly is 150mib/s). Hw accelerated SHA-1 and SHA-2 are both ~1.5 Gib/s and on x86 HW acceleration is always available.
Blake3 is the most interesting because it’s competitive with SHA2 even without HW acceleration. I wonder how it would fare with HW acceleration.
Not really? SHA-2 was released in 2001:
* https://en.wikipedia.org/wiki/SHA-2
Blake3 was released 2020. I'm sure if the folks that created SHA-2 did a hash in 2020 they could do something better/faster as well.
FWIW, SHA-3 is slower than SHA-2 although of course SHA-3 is a totally different construction from SHA-2 by design.
NIST has form for juking the standards, or at least for letting the NSA juke them. If they're not completely transparent, then any standard they recommend is open to question, which isn't good for a standard.
Everything America does is in service of maintaining its position as the hegemonic player. The US intelligence agencies have infiltrated every university and tech company since forever. It's their job.
If you don't trust people creating cryptography standards you cannot really leave gaps, can you?
Complex tasks like "set up a new computer" had months of lead time.
Maybe I've worked in large corporations too much, but my first question when I see policy violations is not "How is this person conspiring?" but rather "What made following the official policy difficult? And how can we fix that?"
Also, the State Dept seems like exactly the sort of place policy violations become culturally routine: non-technical experts, doing work that is arguably "more important", with IT seen as a cost rather than profit center.
Perfect storm for policy-in-name-only.
And it was in fact not, because there was no functioning policy enforcement at State.
I agree, the laws were not enforced in this case.
If you can't do your work for the public under public scrutiny, you shouldn't.
Anyway, interesting take that people working for the public should have no right to privacy in any way. Not sure you will find many people for such work, though.
Even innocently, if, for example, two employees meet at home for dinner with their respective families and there is talk about work - needs to be recorded in that view. Or people car sharing on the way to work - recorded. Any work related communication is very very broad.
And everything recorded open to the public, too.
You don't have privacy in what you do at work when it comes to your employer. That's why it's called privacy, it relates to private and personal things. Your work for someone else is, by definition, not private.
You don't get to push stuff into production and play coy about what you're pushing, do you? Why would that change when the employer is the public?
The solution can't possibly be not even knowing the difference between someone putting salt or toe nails into a pan -- but ensuring cooks don't talk to each other, so even though we have no clue what they're doing or should be doing, we magically know nothing bad is going on.
It seems like a huge burden. It is the kind of thing, though, that in a parallel universe would make total sense: our representatives should be beholden to us.
Which has the net effect of decreasing the ability to reach nobody-is-happy compromises.
Which is something else people say they want.
I'm unconvinced that private, smoke-filled backrooms don't have an essential place as the grease that keeps things running well.
I hear that, and there's a case for it. Diplomacy, maneuvering and negotiation require secrets and enclaves.
So to allow for that you need a few things;
- Strict official records of affairs
- Strong penalties for fraud, malinfluence, intimidation
- Whistleblower protection
The last of these essential checks-and-balances has gone to shit our
culture. Even if we pardoned Edward Snowden and made him a "hero of
democracy" tomorrow, it's still a mountain of work to restore the
essential sense of civic responsibility, patriotism and duty that
allows those people who discover or witness corruption to step-up and
challenge it safe in the knowledge that the law and common morality
are on their side.Record and share everything immediately = no room for deals
Record nothing = too much room for corruption
So we land at... record everything + only review with just cause + strict whistleblower protections.
Which seems a nice splitting of the matter, but requires a strong, independent third party (e.g. judicial branch) to arbitrate access requests. With tremendous pressure and incentives to breach that limit.
I think everyone here is pretty clear how they would ethically view such a thing, but view it from NIST's (/ NSA's) perspective for the sake of argument. Maybe there's a specific threat where NIST (or presumably the NSA) believes it has a mandate to insert a backdoor.
In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust that it can spend on very narrow issues.
But over the years there have been enough strange things (Dual EC DRBG being the most notorious) that that trust, at least when it comes to crypto design, simply isn't there. My perception is that newer ECC standards promoted by NIST have been trusted substantially less than AES was when it was released, and I can think of a number of major issues over the years that would lead to this distrust.
The inevitable outcome is that NIST loses much of its influence on the industry, which certainly is not in its own interest.
Without any /sarcasm tags I have to take that on face value, and frankly there are few words to fully describe what a colossally stupid idea (not your idea, I am sure) that is. Belief in containable backdoors is the height of naivety and recklessly playing fast and loose with everyone's personal security, our entire economy and national security.
That is to say, even taking Hollywood Terror Plots into consideration [0], I don't believe there is ever a "mandate to insert a backdoor".
> In order to successfully do this, NIST needs to maintain a very large bank of social capital and industry trust that it can spend on very narrow issues.
Having some "trust to burn" is great for lone operatives, undercover mercs, double agents and crooks that John le Carre described as fugitives living by the seat of expedient alliances and fast goodbyes. Fine if you can disappear tomorrow, reinvent yourself and pop up somewhere else anew.
But absolutely no use for institutions holding on to any hope for permanence and the power that brings.
> The inevitable outcome is that NIST loses much of its influence on the industry, which certainly is not in its own interest.
Exactly this. And corrosion of institutional trust is a massive loss. Not for NIST or a bunch of corrupt academics who'd stop getting brown envelopes to stuff their pockets, but for the entire world.
But since you obliquely raise an interesting question... what is NIST's "interest" here?
Surely we're not saying that by spending trust "on very narrow issues" it's ultimate ploy is to deceive, defect and double-cross everything the public believe it was created to protect? [1]
I'm all for the game, subterfuge and craft, but sometimes you just bump up against the brute reality of principles and this is one of those cases. Backdoors always cost you more than you ever thought you'd save, and I've always assumed the people at a place like NIST are smart enough to know that.
[0] https://www.schneier.com/essays/archives/2005/09/terrorists_...
What if it is acceptable for potential enemies to (eventually) also have access to that backdoor, and your goal in providing the backdoor is just to give the masses a false belief that they can communicate secretly?
Obviously those in the know would not use the flawed system, but instead would have a similar/better one without the intentional flaws.
Perhaps the clearest argument against such a ploy is the TETRA radio system. Turns out in this case that "the masses" are our:
- police and emergency services
- military and civil defence forces
- diplomatic and political security, escorts, attaches and close security
You see the problem is this concept of "in the know". It's an insoluble information-hazard and boundary problem;
Two people can keep a secret, if one of them is dead.
And therefore want to do things-which-seem-pointless-to-everyone-else to an algorithm to guard against it.
Without disclosing what "it" is.
Everyone's quick to jump to the "NSA is weakening algorithms" explanation, but there's both historical and practical precedent for the strengthening alternative.
After all, if the US government and military use a NIST-standardized algorithm too... how is using one with known flaws good for the NSA? They have a dual mission.
I'm aware of the DES S-boxes, are there other examples of this?
Which is why I don't buy anything from the apologists for "manageable" backdoors.
> strengthen
This is a good theory and interesting take.
Or, more likely, to exploit it.
That's an incredibly charitable version of their point of view. How's this for their POV: They're angry that they can't see every single piece of communications, and they think they can get away with weakening encryption because nobody can stop them legally (because the proof is classified), and nobody's going to stop them by any other avenue either.
You don't need to weaken encryption to spy on people. You just have to give them a dancing bunny and to see the dancing bunny they must say yes to "allow access to contacts" and "allow access to camera" and "allow access to microphone" and "allow access to documents" and ...
For the higher-brow version replace dancing bunny with free service.
In addition the more we adopt and make use of cloud command and control architectures the more surveilled we become, because it becomes trivial for anyone with access to the cloud provider's internals to tap everyone's behavior. This could be done with or without the knowledge of the provider itself. The more such services we use the more data points we are surrendering, and these can be aggregated to provide quite a lot of information about us in near-real-time.
Spoke about this last night in London
- Berstein, an extremely esteemed security researcher[0], published a long blog post last week[1] criticizing NIST's standardization process for new Post-Quantum-Crypto algorithms. He is focusing on the selection of Key Encapsulation Mechanisms (think TLS key exchange). Two big options are Kyber and NTRU (coauthored by Berstein).
- His main complaint is that NIST is playing fast and loose with the selection process, and had disqualified a fast NTRU variant due to barely not meeting a certain security threshold. The missing variant makes NTRU look slower and less flexible than it actually is.
- Meanwhile, NIST accepted a similar fast Kyber variant based on shaky assumptions. Berstein argues at length that it doesn't meet the security threshold either and should be disqualified. Funnily, NIST used Berstein's own research in (seemingly) incorrect fashion to argue for Kyber's security.
- There's an air of impropriety, as if NIST was favoring one algorithm over the other, for unknown reasons. And in the beginning of the post, Berstein shows the results of his recent lawsuit to reveal more information about the internal NIST process: it seems that NIST and NSA met more often than previously thought.
My interpretation leans more towards NIST making an internal mistake in evaluating the algorithms, rather than NSA pushing its agenda. One could argue that Berstein is sour that his algorithm might not be picked, and is trying underhanded tactics. On the other hand, he does have excellent reputation, and convincingly argues that NIST made an important mistake and is not transparent enough.
[0] https://www.metzdowd.com/pipermail/cryptography/2016-March/0...
Why do you say this? The NSA has done this exact thing in the past[1], so why give them the benefit of the doubt this time?
Meanwhile, both NTRU and Kyber are lattice-based, and their designs came from honest attempts. To be an NSA effort, there would need to exist an exploitable flaw in Kyber, but not NTRU, known only to the NSA. And it's not like NTRU as a whole got disqualified; only the fastest variant did.
That's the problem with spy agencies, you never know what they are capable of. But if it was an NSA effort, it would be, by far, the most subtle one uncovered so far.
Changing rules on the fly and improperly applying said rules could be a way to select a weak option you can break while having stronger plausible deniability than what happened with Dual_EC_DRBG (which btw wasn’t actually confirmed until the Snowden leak). So here’s someone claiming NIST is being suspicious in how the algorithm selection happened. The rules really need to be set in stone at the beginning of the competition or before the phases at least. And you can’t pick diametrically opposed rule sets between phases (as happened if you read Bernstein’s letter), only tweaks.
This is not his style, for what it's worth, at least not for standalone long-form writing. His most influential cryptography writing is concise and lucid.
Kagi Universal Summarizer output for "Summary":
This web page discusses the selection of the Kyber and NTRU cryptosystems as the quantum-resistant digital signature algorithms by the National Institute of Standards and Technology (NIST). It analyzes NIST's claims about the security levels of Kyber-512 compared to AES-128. While NIST argued Kyber-512's security level is boosted enough by memory access costs to meet the AES-128 threshold, the text raises uncertainties around accurately modeling such costs and argues NTRU may have advantages in flexibility and performance. Overall, the page questions whether NIST fully justified selecting Kyber-512 over NTRU given the uncertainties in quantifying the security of lattice-based cryptosystems against future attacks.
Kagi Universal Summarizer output for "Key moments":
- There is debate around whether Kyber-512 provides adequate security compared to the AES-128 benchmark. NIST claims it meets this level factoring in memory access costs, but others argue the analysis is uncertain.
- NIST's analysis added 40 bits of estimated security to Kyber-512's post-quantum security level due to memory costs, bringing it above the AES-128 threshold. Critics question this calculation.
- NTRU provides greater flexibility than Kyber in supporting a wider range of security levels. At some levels it also has better performance and security than Kyber options.
- The security of lattice-based cryptosystems like Kyber and NTRU is not fully understood, and there is a risk of better attacks being discovered in the future.
- Standardizing a system like Kyber-512 that may have limited security margin could be reckless given lattice cryptanalysis uncertainties.
- Critics argue NIST has not clearly explained its security evaluations and claims about Kyber-512's margin above AES-128.
- Memory access costs are important to lattice security but are not fully quantified in their impact on Kyber versus classical attacks on AES.
- Removing Kyber-512 could make NTRU the strongest candidate given its flexibility at multiple security levels.
- One paper argued multi-ciphertext attacks on Kyber may be as difficult as single-ciphertext attacks.
- There are calls for NIST to be transparent about its analysis and decision making regarding Kyber-512.
anyways, it seems i cannot delete the comment, so would be great if a moderator or something could do it, thanks.
Re: style, this seems longer and more rambling than usual, but other stuff on his blog has been long, and his style with lots of background, asides, references, self-quotes seems pretty distinctive, isn't it?
But I'm sure you paid more attention to this than me.
In between a bunch of conspiratorial hinting, djb argues that KYBER-512 is weaker than NIST claims.
To make that argument, he points out a fairly egregious math mistake (the whole "2^40+2^40" bit) and then shows that NIST was inconsistent in applying the rules of the contest it refereed.
He also offers an explanation for why NIST would be so inconsistent about it, namely that they were influenced to pick KYBER, even if it wasn't the best candidate.
--
My personal takeaway was that he was both being a sore loser but also that KYBER-512 is weaker than it should be, weaker than it is claimed to be and that for some reason NIST still wanted it to win.
Makes me skeptical about KYBER-512 (but not larger sizes) and reinforces my worry that NIST can be influenced to pick less-than-optimal algorithms.
But then, I'm not a cryptographer and in the lucky situation where for any application I encounter, I can just go for KYBER-768 or 1024 or NTRU and just be fine - I don't have to understand this situation perfectly.
Hope you get some value from this outside perspective.
If anything, this reinforces my belief that KYBER is a good design. If this is the best he can come up with to try and discredit it, then it must be pretty solid.
What doesn't seem clear to me, and I'd appreciate if you could tell me why you think differently, is that KYBER-512 isn't as strong as it was targeted to be. I find djb's argument on this narrow point fairly convincing: KYBER-512 isn't as secure as AES-128 (by the methods used to measure "secure" in this competition).
Given that I already generally use AES-256, why shouldn't I treat this the same way as AES-128?
That is, "it's probably fine-ish, but if you have the power, just go one bigger".
But by all means feel free to go one bigger and pick KYBER-768, and I believe lots of people do recommend this. Obviously, there is a performance penalty (as there is when moving from AES 128 to 256), and for PQ schemes there is also more importantly also a big increase in the size of bytes on the wire when public keys have to be exchanged (e.g. in TLS) - in this case a jump from 800 bytes to 1,184 bytes (a 48% increase). (Compare this to ECC public keys which are typically around 32-65 bytes, depending on encoding).
It has also been pointed out to me that djb has been quietly ignoring another metric in which KYBER beats NTRU: implementation complexity.
Even accepting all other arguments about the tradeoffs between NTRU and KYBER (and I do take your point about size of keys being more important than CPU cycles), even then, KYBER is judged to have lower implementation complexity.
Having read about all the crypto libraries who produced broken output because they made a mistake in the implementation, that's something I immediately understand as a big benefit.
Again, thanks for the conversation and helping me understand!
I want to push back on this a little by linking this Twitter thread:
https://nitter.net/FiloSottile/status/1555669786826244096
It shows that there's a pattern of Bernstein and his associates threatening fellow cryptographers.
It's entirely possible to be a brilliant cryptographer and also a petty person, those things aren't mutually exclusive.
The tweets say DJB implied that scientists who submitted algorithms were bribed by the NSA. That's a complete misunderstanding of that DJB wrote: he argued that the NSA wouldn't need to bribe those scientists, because they hired the top experts in the field years ago, so it might be the case that they're so far ahead of what's being submitted that all they have to do is push NIST to pick an algorithm they know how to break.
Now, I have no knowledge of any of this, so I have no idea if DJB's argument is insanely paranoid like the author of the thread implies (with the GIF in the 3rd tweet). All I can see is that the author's claim is a gross mischaracterization of what DJB wrote.
Isn't paranoia an essential job requirement for cryptographers?
Paranoia: NSA bribes the independent reviewers and is backdooring the whole thing because everyone knows the military and intelligence services are two decades ahead of public research and we just don't know what the algorithm flaw is yet, but I'm telling you, they're keeping something behind!
I am not saying djb (or anyone) does the latter, example is given exaggerated for illustrative purposes only. The cryptographer's example is also exaggerated, as it does matter how algorithms are chosen and there's a measure of subjectivity involved. Still, I would not say that paranoia is the job of a cryptographer.
"When his schemes won’t get picked by NIST, people will think it’s because they are not backdoored, and will point at the FOIA lawsuit as evidence."
For example, one reference being used as evidence that djb is evil complains about being insulted that their employer (also djb's employer, presumed to be on djb's side) suggested seeing a company doctor after being on sick leave for a while. This is 100% standard practice in the Netherlands and the doctor is independent, not from the company themselves, and keeps things confidential. It's how we resolve the conflict where you can't just claim you're sick for unspecified reasons indefinitely and continue to expect money, but the employer isn't entitled to know your medical dossier either. This lets you have medical confidentiality and long-term sick leave where the employer can trust that appropriate action is being taken because they trust the impartial doctor to verify that. This is brought up as part of the conflict between djb, the author, and the university they work for. This isn't the only thing they allude to not knowing about while abuse was alleged to be allowed to happen by djb and others. I believe most of what is written, but at the same time, the problem is clearly being exacerbated by not using coworkers, friends, or even google/ddg to find out what legal system you've moved into. Djb even suggested they should take legal action, and HR offered arbitration, but the person declined both. So now the evidence amounts to their word on a blog and the alleged perpetrators faced zero consequences.
As much as such references serve to convince me of djb=evil, they also convince me there may be more to the story than one side.
Obviously I've just highlighted one thing here, there's a lot more he-said-she-said going on elsewhere in the threads that could give one pause in believing one side verbatim, even if they're likely right in spirit
I do believe he has increasingly argued in bad faith and alienated his peers to the point that they're (we're) unwilling to engage with him, which from the outside can look like his points are unrefutable.
If he's turned so crank-y that his peers simply no longer engage with him beyond the strictly necessary, then this all looks a bit different.
I'd still love to see some of his specific criticisms addressed, but that becomes a minor point...
Cranks and assholes occasionally are unfairly treated, but generally are fairly ignored - the effort of dealing with their claims aren't worth it.
As an outsider, "respected cryptographer makes a narrow technical claim and is brushed off by NIST" and "sore loser that no-one talks to complains that people aren't entertaining his latest complaint about the ref" are very different situations, from which I will take very different actions.
This is looking more and more like the latter!
Just to be sure, this is not how I see it at all. I'm relatively convinced that the thing isn't backdoored rather than buying into this particular conspiracy theory.
But yeah, in general that is a risk when one doesn't engage despite disagreeing
Designing curve25519 was, in terms of practical impact, an achievement I'd put in the same category as inventing RSA or Diffie-Hellman. Not because the ideas were new, but because they came together in a way that produces something that "just works" in practice, and you don't have to worry about invalid curve points and twist attacks and accidentally using the addition formula for a point doubling and many other things. The idea that instead of a framework where you can plug in your own parameter choices and some of them might be secure, you can just build a crypto library that does one thing well, was certainly new enough that no-one else seemed to be doing it at the time. The fact that when I need a key for real, most of the time I do `ssh-keygen -t ed25519` or the equivalent in other systems speaks for itself.
As does the fact that github has deprecated the ssh-dss key type and recommends ed25519 and the default: in the contest between Ed25519 and DSA/ECDSA for digital signatures, Bernstein wins hands down and NIST has egg on their face. Although I have no proof of malice, I haven't yet heard a rational explanation for just how badly ECDSA mangles the Schnorr protocol in exactly the way that means a lot of implementations end up with horrible security holes.
And then there's the Snowden leaks and DUAL_EC. "The NSA has interfered with crypto standards in the past, reliable leaks show it was part of their mission statement, and they could be doing so again." is to me a statement backed up by plausible evidence that's very far from the usual conspiracy theories. This is not faked-moon-landings territory.
And I should also say, there are a lot of ways of being evil that to my knowledge no-one has ever accused Bernstein of: as far as I know, he's never been accused of raping or sexually assaulting anyone, nor has he said anything particularly racist or pushed any far-right ideology. He has been accused of insulting and occasionally threatening people who disagree with him on technical matters, but he's not what we usually mean by "bad/evil person, avoid if possible".
I'd say he has a fairly spotless track record in cryptographic protocol design, and a fairly stained one in interacting with other humans. When he's pushing back against design decisions that actually are stupid/evil, that's an asset; in lots of other cases it's not.
I thought schnorr was under patent for a bit, so an open alternative was needed? Also ECDSA does allow for recovery of the public key from the signature, which can be useful.
> We disagree with his analysis,” says Dustin Moody at NIST. “It’s a question for which there isn’t scientific certainty and intelligent people can have different views. We respect Dan’s opinion, but don’t agree with what he says.
That's great for a PopSci article, but I(and many others, I'm sure) would like to see the details of this analysis hashed out. DJB had his chance at making this happen, and blew it. However, that doesn't mean his questions[0] should go unanswered.
[0]: specifically talking about the calculation of the Kyber-512 security level here. Not his more conspiratorial claims.
WTF is that? No, it's not a question where intelligent people can have different views. DJB is literally claiming the NSA is claiming something similar to "3 + 3 = 9". That claim is either correct or not.
There's a paywall in front of the article that I have no intention to deal with after seeing what's on the comments. But a phrase like (and I could find it before the paywall rits) this is absolutely dishonest.
Nit: DJB is claiming that NIST is doing that, not NSA.
> There's a paywall in front of the article
turning javascript off gets around the paywall.
https://en.m.wikipedia.org/wiki/Bernstein_v._United_States
Qmail https://en.m.wikipedia.org/wiki/Qmail
For key pairs that can be transferred, it's no different than the threat of password managers stealing your keys to the castle. You just have to trust the cloud and your entire hardware and software stack your password and passkey manager run on, and/or that nothing in that stack gets swapped out without you noticing.
Similarly, I've yet to see a hardware security key that you can verify doesn't have backdoors compiled or soldered in. All the cryptography in the world doesn't matter if a government/whoever can just pop your Yubikey in a machine that does whatever magic incantation is needed to dump your keys. That magic incantation can even be secured with strong cryptography to ensure only the US government/whoever can use it.
The Precursor is also open hardware and software.
If you trust any smartcard at all running a Javacard-compatible operating system, there's also https://github.com/BryanJacobs/FIDO2Applet .
And of course if you're truly paranoid you can get a FPGA and implement a hardware security key on that. The overall security posture would likely be weaker, but you could be confident, hopefully, that nobody has put some kind of backdoor into the hardware you designed yourself to run atop a generic array of logic gates.
Looks like the Solo HE lets you load your own firmware on to it, but it doesn't let you load your own signing or encryption key to ensure firmware updates are trusted. Apparently the Solo HE can be flashed once permanently by overwriting the bootloader, though.
The non-HE versions of the Solo 1 and 2 will load new firmware signed by Solokey.
Earlier this year I looked into this and remember finding out that it was either the Solo 1/2, Somu or one of the Nitrokey products that, while shipping with a secure element, didn't actually use the secure element.
If you think some company in the future will have the ability to somehow "steal" the contents of the device's flash, you'd still have to climb the mountain of explaining how they could then break the encryption the open-source software already - before they got hold of the key - applied to the flash contents.
Just to make sure this is clear, the security key at rest is not storing your credentials. It is storing AES256(key=<PIN>, value=<credential>). It is not storing the PIN.
You only need to trust the hardware to implement encryption correctly, which you can - of course - verify yourself. It's not realistic to say that the pre-encrypted values might be secretly stored somewhere else: there just isn't enough space on the device to do that.
Spy agencies, law enforcement, and criminals would all much prefer people use easily guessable and/or unsafely stored passwords. Those are both easier to discover, easier to brute force, and easier to intercept (specifically all you need to do is intercept a password once as it's definitionally not based on a single time exchange).
The NSA put out a known compromised elliptic curve encryption algorithm? Or are you referring to Dual_EC_DRBG, a probably compromised random number generator?
People are people and they come and go, but these NIST standards stay a long time.
Peoples Republic of United States.
Sounds the same.
And it's worth remembering that, even in the US there exist examples of people who pushed for real change to these systems, and ended up detained, dead or simply disappeared.
It might also be worthwhile to consider the following well known allegations: revolving door appointments between bureaucracy and companies that it interfaces with and regulates; compromise of politicians by various interest groups using bribery or blackmail; the effects of corporate lobbying and donations to distort the legislative and electoral processes; the powers of unelected career bureaucrats whose tenures often outlast elected officials.
It's important to recall that the US is not alone is allegedly suffering from these maladies, but that it might suffer from them ought be a cause for concern.
Such considerations seem to raise the question of whether the president (and associated democratic and elected apparatuses) are in some way figureheads designed to provide a focus and an outlet, but may also function to protect the overall system against substantial reforms.
Such a description may help explain why processes in democracies often stagnate.
The is not to say that the Chinese system is "better" in any sense (our first consideration indicates that perhaps all large governing systems must essentially be the same), but it might be more honest about what it is.
This gives rise to the sense that democracy, at least in part, may be a deception that usefully provides people the illusion of a voice for change, while at the same time protecting the governing system by ensuring people do not seek more disruptive methods to alter it.
Of course, the flipside is, without such less disruptive avenues, people are then without peaceful recourse. This means that in the Chinese system, the government knows it faces the threat of revolution, which, while it could be thought to function as a kind of guidance of, or check-and-balance on, its power, is also responded to by the system itself becoming more draconian and authoritarian, in order to protect itself, if that makes sense?
So in the US, the system protects itself with what may be described as a generally more peaceful and free society, with what be a somewhat deceptive democracy (of course more authoritarian exceptions are occasionally made to neutralize true rabble rousers), whereas in China, the system protects itself more overtly, with a generally more authoritarian and restrictive society, which is more open about what it is.
The point of this comparison is to foster more mutual understanding and less false-differences that fuel unnecessary divisions and distort discussions with fallacies, in an attempt to try to guide discussions along more productive directions, based on realities.
As Churchill said, "democracy is the worst form of government, except all others". Are there elements in democracies that entrench the status quo? Of course, especially in countries like the UK and the US with single member district, first past the post systems that favor huge parties that never change. Here we have a pretty complex party list based system that is often critiqued as "too difficult to understand for the average voter", but when people want to change who rules the country they have more than 1 viable choice of opposition. You may say, nah, it is not about the system of voting, duopoly is a feature of "mature" democracies that have been around for 400 years. To which I'll give an example of Poland where the lower chamber of parliament (Sejm) is voted for party lists proportionally and it always has a mix of many parties, and the upper chamber (Senat) that uses the classic "first past the post" system and in the senate 2 major parties(the biggest party and the current biggest opposition party) always get 95%+ of the seats.
Also, I think your points are very interesting but may benefit from some paragraphing for added clarity and coherence.
Another point of note is that, while interesting, it may be the case that no matter how much a government optimizes its electoral systems, it may still be subject to the other vulnerabilities listed above, which sadly might subsume any gains from such optimization.
Whose career got ruined actually? Johnny Depp is still making movies, Rammstein just announced a 2024 tour, JKR still is making millions upon millions every year with Harry Potter, Trump is likely to be the Republican candidate in 2024. "Cancel culture" isn't real.
but we've gotta update this now that the law will turn to software
(I don't actually believe that we shouldn't use NIST standards, but my point is that's a pretty weak argument for non Americans. )
For example, Satoshi Nakamoto chose a very interesting, lightly used elliptic curve secp256k1 for Bitcoin because for various reasons he was very confident it wasn’t backdoored, and obviously it has stood the test of time https://en.bitcoin.it/wiki/Secp256k1
We have plenty of standards in Europe too :-)
However, with cryptography historically the best crypto has been invented in the US and it made much more sense for allies to just use ready made solutions than to roll their own. Do countries on the US crypto exports ban lists have their own incompatible crypto? I dont know, they might, but they for sure don't share it as freely available standards.
ENIGMA?
By contrast, the US and British rotor machines were never cracked by the Axis powers in WW2, and the other two German rotor ciphers were less thoroughly cracked by the Allies.
They don't seem to mention these spiffy US and UK rotor cyphers; any pointers?
https://www.rfc-editor.org/rfc/rfc8891 (GOST Magma) is a russian standard block cipher.
https://www.gsma.com/aboutus/wp-content/uploads/2014/12/eea3... is a Chinese stream cipher.
https://datatracker.ietf.org/doc/html/draft-ribose-cfrg-sm4-... Chinese block cipher.
https://datatracker.ietf.org/doc/html/draft-oscca-cfrg-sm3-0... Chinese hash function.
https://datatracker.ietf.org/doc/html/rfc4269 (SEED) is from South Korea (aligned, but still worth a mention)
What kind of mental contortions do you have to go through to think like this? It comes off like gung-ho ignorance at best, and reeks of some of the most obvious american military propaganda I've ever read.
One of the annoying things about how Bernstein is communicating about this is that he is counting on his audience not knowing this.
The EU, UK and Australia are all bad for this in various ways, having key-disclosure laws or trying to ban e2e or whatever else. I don’t know about you but I don’t consider China or Russia to be valid places to look for un-backdoored crypto either.
It seems (to this non-American) like one of the least-worst options. Maybe we could trust a Scandinavian country or Switzerland?
(Yes, I have missed out huge swathes of the world, which I mostly know little about…)
I don't know, but I'd start with getting buy-in from any interested country with an emphasis on not too much from any one. Where it's physically located is irrelevant, the issue is the clear commitment to the interests of the american state.
These is somewhat better than not having such a system at all.
If nothing else, you get to benefit from public analysis and pick another of the algorithms that get proposed in the competition, even if it's not the NIST-blessed one.
I guess maybe with the advent of AI, you just have device to device communication with no man in the middle in the future?