Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I recommend this video by Computerphile - He talks about how NIST may have been pressured into enforcing compromised (backdoored?) cryptography methods as a standard - Dual_EC_DRBG to be exact. He also gives a super cool/intuitive breakdown on how this came to be. It will definitely grow some food for thought.

https://www.youtube.com/watch?v=nybVFJVXbww



Small summary, courtesy of Wikipedia which makes a stronger claim than "may have been pressured":

> In September 2013, both The Guardian and The New York Times reported that NIST allowed the National Security Agency (NSA) to insert a cryptographically secure pseudorandom number generator called Dual EC DRBG into NIST standard SP 800-90 that had a kleptographic backdoor that the NSA can use to covertly predict the future outputs of this pseudorandom number generator. [...] the NSA worked covertly to get its own version of SP 800-90 approved for worldwide use in 2006. The whistle-blowing document states that "eventually, NSA became the sole editor".

https://en.wikipedia.org/wiki/National_Institute_of_Standard...


Dual EC was not the product of a contest. The NIST PQC algorithms are all designed by academic cryptographers, many of them not US nationals.


And chosen by NIST…


And? Finish that thought.


You are tptacek; I believe you know exactly what I meant. But to indulge you, do you think we can know that the selection process is not comprised?


Explain what the compromised selection process does here. NIST doesn't control the submissions.


Seems pretty obvious no?

1. Pretend to be someone else and enter a backdoored algorithm. Or pressure someone to enter a backdoored algorithm for you. Or just give them the algorithm for the reward of being the winner.

2. Be NIST, and choose that algorithm.


You think someone is going to pretend to be Chris Peikert and submit a backdoored construction as him, and that's going to work?

This is the problem with all these modern NIST contest theories. They're not even movie plots. Your last bit, about them paying someone like Peikert off, isn't even coherent; they could do that with or without the contest.


> they could do that with or without the contest

Then why does the contest give you any more confidence that the selection isn't backdoored?


It's not the contest so much as the reputation of the winning team and the reputations of all the teams who did cryptanalytic work. Wait, I guess that means it is the contest. Well, there's your answer.

People on threads like these are pretending NIST was a shadowy force making secret determinations, but the whole thing happens in the open, and NIST is essentially just proctoring.

A lot of this kind of thing is just people telling on themselves that they don't follow the field and don't trust any cryptography not done by one of the three cryptographers they've ever heard of.


>the reputation of the winning team and the reputations of all the teams who did cryptanalytic work

>NIST is essentially just proctoring

Well, there we go. These items are actually good information (to be verified of course). Way better information than questions that seem to miss the concern. Thank you.


Your question presupposes a claim that the selection process is compromised. I'm not saying it is. I just wonder how we know it's not.

In NIST's position one could analyze the submissions for vulnerabilities to closely held (non-public) attacks, then select submissions having those vulnerabilities.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: