[HN Gopher] Plagiarism as a patent amplifier: Understanding the ...
___________________________________________________________________
Plagiarism as a patent amplifier: Understanding the delayed rollout
of PQC
Author : rdpintqogeogsaa
Score : 28 points
Date : 2022-01-29 16:45 UTC (6 hours ago)
(HTM) web link (blog.cr.yp.to)
(TXT) w3m dump (blog.cr.yp.to)
| gjm11 wrote:
| Brief-ish TLDR (note: I am summarizing what Daniel Bernstein says
| in the linked article, and make no comment on its _correctness_ ;
| this is relevant because Bernstein makes some accusations about
| another academic) --
|
| Back in 2016, Google began an experiment with "post-quantum
| cryptography", deploying some cryptographic algorithms in Chrome
| and in Google's servers that should be resistant to attack by
| quantum computers. (Most present-day crypto would be very badly
| broken if non-toy quantum computing becomes practical.)
|
| But they shut it down after a few months, even though it seemed
| to be working well. They'd originally said that if it went well
| they'd find a better algorithm and switch to it in a couple of
| years. So what happened?
|
| Plausible answer: shortly after beginning this experiment they
| were contacted by a cryptography researcher (Jintai Ding) who
| holds a patent that allegedly covers the algorithm they were
| using. The easiest course of action when this happens is just to
| shut the thing down.
|
| So how come they didn't _know_ about this patent?
|
| Plausible answer: because _another_ cryptography researcher
| (Chris Peikert) deliberately and systematically misled the
| academic community in order to avoid them noticing Ding 's work
| -- because Ding did an important thing in 2012, and Peikert did
| essentially the _same_ thing in 2014, and Peikert wanted to take
| credit for inventing it. Peikert succeeded, everyone thinks he
| invented the relevant things first, and no one thought to check
| whether Ding might have patents on it.
|
| (I reiterate that I am summarizing Bernstein's claims, and I do
| not know whether they are right or not.)
|
| TLDR of the TLDR: according to Bernstein, a dishonest academic
| cryptographer went out of his way to deceive his colleagues into
| ignoring earlier work by another cryptographer, so as to get the
| credit for it himself, this led to an important patent being
| overlooked by Google, and this has been a completely unnecessary
| stumbling block in the way of getting post-quantum cryptography
| deployed, so that Peikert's (alleged) selfishness and dishonesty
| have made everyone's data much less safe against future quantum-
| computer-based attacks.
| Ar-Curunir wrote:
| I will note that DJB has a long-running beef with Chris
| Peikert, and seems generally opposed to lattice-based PQC. From
| my impression (as another academic cryptographer), Chris seems
| to be a genuine person, and not one to "deceive his
| colleagues"; he is also generally well-liked in the community.
| DJB, on the other hand, is known for being highly opinionated,
| and is a bit of an iconoclast in the cryptography community.
| [deleted]
| gjm11 wrote:
| _If_ the straightforwardly checkable claims in what DJB wrote
| are correct (which I have not checked) then I have trouble
| seeing how Peikert could be blameless, though he could
| certainly be less consciously and deliberately deceptive than
| DJB is representing him as.
|
| E.g., I think the following scenario is consistent with all
| DJB's straightforwardly checkable claims: Peikert _did_ see
| Ding 's 2012 paper, or at least its 2014 revision, but didn't
| read it carefully and didn't appreciate that it meant Ding
| had anticipated Peikert's innovations by 2 years; Peikert's
| subsequent writing on the subject is misleading but not
| intended to deceive.
|
| And, of course, if DJB is wrong on some of the
| straightforwardly checkable claims, all bets are off.
|
| DJB is opinionated and iconoclastic, for sure, but I wouldn't
| generally expect him to make claims that are flatly false.
| E.g., if he says that Ding (2012) does basically all the
| important things that Peikert (2014) does then I would expect
| that to be correct. But I don't know the Bernstein/Peikert
| history, and even generally reliable people can go badly
| wrong when it comes to people they really hate...
| upofadown wrote:
| >...large-scale attackers are already recording as much Internet
| traffic as they can. Do they throw the data away if it's
| encrypted with RSA-2048? Of course not. They keep it forever[1],
| hoping and expecting that someday they'll develop the ability to
| decrypt it, for example by building a quantum computer.
|
| The Forbes reference actually says that an oversight body allows
| the NSA to keep encrypted data forever, not that they actually
| do. There is so much encrypted data on the internet now that the
| NSA would have to use a significant amount of all the storage
| produced each year to keep a running archive of everything. A
| victory of sorts...
|
| [1]
| https://www.forbes.com/sites/andygreenberg/2013/06/20/leaked...
| kragen wrote:
| Like the Crypto AG affair, this is likely to be one of the major
| drivers of historical events in the next few decades.
|
| I haven't finished reading this post yet, and I don't know much
| about cryptography, so it is somewhat risky for me to be
| summarizing it; but my summary is that Google's planned rollout
| of post-quantum-resistant TLS was aborted in November 02016
| without explanation after only a few months rather than being
| continued for a few years as planned, apparently because it
| infringed a patent by Ding, even though it was based on a paper
| by Peikert that didn't credit Ding and thus didn't give any
| warning that a patent might be lying in wait. The plagiarism
| mentioned in the title is summarized just before the section "The
| concept of plagiarism":
|
| > _But 2012 Ding did reduce the LPR ciphertext size "nearly
| twofold", specifically replacing "one of the two ring elements"
| with "a binary string of the same dimension n", in the words of
| 2014 Peikert. The problem is that this isn't how 2014 Peikert was
| describing 2012 Ding; this was 2014 Peikert claiming this space
| reduction as something new, the result of an "innovation" in 2014
| Peikert._
|
| Though the post doesn't say this, the patent in question
| (https://patents.google.com/patent/US9246675B2) was filed in
| 02013 and issued in January 02016.
|
| Bernstein explains that one result of this delay in deployment is
| that a great deal of TLS traffic that has already been captured
| and archived will probably be decrypted when quantum computers
| become available. He doesn't mention this, but I think this
| includes ciphersuites that claim "perfect forward secrecy".
| formerly_proven wrote:
| > He doesn't mention this, but I think this includes
| ciphersuites that claim "perfect forward secrecy".
|
| Very much so, yes.
| kragen wrote:
| Thanks for the confirmation.
| boardwaalk wrote:
| Besides the alleged plagiarism of Peikert, it seems massively
| immoral of Ding to lay a patent landmine in something important
| as secure communications for the next century.
|
| At the same time, I wonder how much he asked for from Google and
| how open the algorithm would have been (/ if it could have been
| "bought out").
| formerly_proven wrote:
| I'm not sure what the point of tenured crypto researchers
| patenting their crypto is. The only thing it guarantees is that
| your crypto is barred from standards because crypto is so
| extremely widespread that collecting royalties is simply
| impossible. AES-OCB is a prime example of this. It was faster
| than GCM and not quite as brittle, so many people would've liked
| to use it - but it was patented. No one used it. It now has a
| non-commercial FOSS patent grant, which still means no one uses
| it.
| rdpintqogeogsaa wrote:
| Rogaway has abandoned his patents on OCB[0]. But by now, AES-
| GCM has hardware support and is ubiquitous. Nowadays, misuse
| resistance and resistance against partitioning oracle attacks
| are things you'd (also) expect from a modern AEAD design. AEGIS
| outperforms AES-OCB. The AEAD horse has already left the barn;
| there is no longer any point in closing the door.
|
| [0]
| https://mailarchive.ietf.org/arch/msg/cfrg/qLTveWOdTJcLn4HP3...
___________________________________________________________________
(page generated 2022-01-29 23:01 UTC)