[HN Gopher] Plagiarism as a patent amplifier: Understanding the ...
       ___________________________________________________________________
        
       Plagiarism as a patent amplifier: Understanding the delayed rollout
       of PQC
        
       Author : rdpintqogeogsaa
       Score  : 28 points
       Date   : 2022-01-29 16:45 UTC (6 hours ago)
        
 (HTM) web link (blog.cr.yp.to)
 (TXT) w3m dump (blog.cr.yp.to)
        
       | gjm11 wrote:
       | Brief-ish TLDR (note: I am summarizing what Daniel Bernstein says
       | in the linked article, and make no comment on its _correctness_ ;
       | this is relevant because Bernstein makes some accusations about
       | another academic) --
       | 
       | Back in 2016, Google began an experiment with "post-quantum
       | cryptography", deploying some cryptographic algorithms in Chrome
       | and in Google's servers that should be resistant to attack by
       | quantum computers. (Most present-day crypto would be very badly
       | broken if non-toy quantum computing becomes practical.)
       | 
       | But they shut it down after a few months, even though it seemed
       | to be working well. They'd originally said that if it went well
       | they'd find a better algorithm and switch to it in a couple of
       | years. So what happened?
       | 
       | Plausible answer: shortly after beginning this experiment they
       | were contacted by a cryptography researcher (Jintai Ding) who
       | holds a patent that allegedly covers the algorithm they were
       | using. The easiest course of action when this happens is just to
       | shut the thing down.
       | 
       | So how come they didn't _know_ about this patent?
       | 
       | Plausible answer: because _another_ cryptography researcher
       | (Chris Peikert) deliberately and systematically misled the
       | academic community in order to avoid them noticing Ding 's work
       | -- because Ding did an important thing in 2012, and Peikert did
       | essentially the _same_ thing in 2014, and Peikert wanted to take
       | credit for inventing it. Peikert succeeded, everyone thinks he
       | invented the relevant things first, and no one thought to check
       | whether Ding might have patents on it.
       | 
       | (I reiterate that I am summarizing Bernstein's claims, and I do
       | not know whether they are right or not.)
       | 
       | TLDR of the TLDR: according to Bernstein, a dishonest academic
       | cryptographer went out of his way to deceive his colleagues into
       | ignoring earlier work by another cryptographer, so as to get the
       | credit for it himself, this led to an important patent being
       | overlooked by Google, and this has been a completely unnecessary
       | stumbling block in the way of getting post-quantum cryptography
       | deployed, so that Peikert's (alleged) selfishness and dishonesty
       | have made everyone's data much less safe against future quantum-
       | computer-based attacks.
        
         | Ar-Curunir wrote:
         | I will note that DJB has a long-running beef with Chris
         | Peikert, and seems generally opposed to lattice-based PQC. From
         | my impression (as another academic cryptographer), Chris seems
         | to be a genuine person, and not one to "deceive his
         | colleagues"; he is also generally well-liked in the community.
         | DJB, on the other hand, is known for being highly opinionated,
         | and is a bit of an iconoclast in the cryptography community.
        
           | [deleted]
        
           | gjm11 wrote:
           | _If_ the straightforwardly checkable claims in what DJB wrote
           | are correct (which I have not checked) then I have trouble
           | seeing how Peikert could be blameless, though he could
           | certainly be less consciously and deliberately deceptive than
           | DJB is representing him as.
           | 
           | E.g., I think the following scenario is consistent with all
           | DJB's straightforwardly checkable claims: Peikert _did_ see
           | Ding 's 2012 paper, or at least its 2014 revision, but didn't
           | read it carefully and didn't appreciate that it meant Ding
           | had anticipated Peikert's innovations by 2 years; Peikert's
           | subsequent writing on the subject is misleading but not
           | intended to deceive.
           | 
           | And, of course, if DJB is wrong on some of the
           | straightforwardly checkable claims, all bets are off.
           | 
           | DJB is opinionated and iconoclastic, for sure, but I wouldn't
           | generally expect him to make claims that are flatly false.
           | E.g., if he says that Ding (2012) does basically all the
           | important things that Peikert (2014) does then I would expect
           | that to be correct. But I don't know the Bernstein/Peikert
           | history, and even generally reliable people can go badly
           | wrong when it comes to people they really hate...
        
       | upofadown wrote:
       | >...large-scale attackers are already recording as much Internet
       | traffic as they can. Do they throw the data away if it's
       | encrypted with RSA-2048? Of course not. They keep it forever[1],
       | hoping and expecting that someday they'll develop the ability to
       | decrypt it, for example by building a quantum computer.
       | 
       | The Forbes reference actually says that an oversight body allows
       | the NSA to keep encrypted data forever, not that they actually
       | do. There is so much encrypted data on the internet now that the
       | NSA would have to use a significant amount of all the storage
       | produced each year to keep a running archive of everything. A
       | victory of sorts...
       | 
       | [1]
       | https://www.forbes.com/sites/andygreenberg/2013/06/20/leaked...
        
       | kragen wrote:
       | Like the Crypto AG affair, this is likely to be one of the major
       | drivers of historical events in the next few decades.
       | 
       | I haven't finished reading this post yet, and I don't know much
       | about cryptography, so it is somewhat risky for me to be
       | summarizing it; but my summary is that Google's planned rollout
       | of post-quantum-resistant TLS was aborted in November 02016
       | without explanation after only a few months rather than being
       | continued for a few years as planned, apparently because it
       | infringed a patent by Ding, even though it was based on a paper
       | by Peikert that didn't credit Ding and thus didn't give any
       | warning that a patent might be lying in wait. The plagiarism
       | mentioned in the title is summarized just before the section "The
       | concept of plagiarism":
       | 
       | > _But 2012 Ding did reduce the LPR ciphertext size "nearly
       | twofold", specifically replacing "one of the two ring elements"
       | with "a binary string of the same dimension n", in the words of
       | 2014 Peikert. The problem is that this isn't how 2014 Peikert was
       | describing 2012 Ding; this was 2014 Peikert claiming this space
       | reduction as something new, the result of an "innovation" in 2014
       | Peikert._
       | 
       | Though the post doesn't say this, the patent in question
       | (https://patents.google.com/patent/US9246675B2) was filed in
       | 02013 and issued in January 02016.
       | 
       | Bernstein explains that one result of this delay in deployment is
       | that a great deal of TLS traffic that has already been captured
       | and archived will probably be decrypted when quantum computers
       | become available. He doesn't mention this, but I think this
       | includes ciphersuites that claim "perfect forward secrecy".
        
         | formerly_proven wrote:
         | > He doesn't mention this, but I think this includes
         | ciphersuites that claim "perfect forward secrecy".
         | 
         | Very much so, yes.
        
           | kragen wrote:
           | Thanks for the confirmation.
        
       | boardwaalk wrote:
       | Besides the alleged plagiarism of Peikert, it seems massively
       | immoral of Ding to lay a patent landmine in something important
       | as secure communications for the next century.
       | 
       | At the same time, I wonder how much he asked for from Google and
       | how open the algorithm would have been (/ if it could have been
       | "bought out").
        
       | formerly_proven wrote:
       | I'm not sure what the point of tenured crypto researchers
       | patenting their crypto is. The only thing it guarantees is that
       | your crypto is barred from standards because crypto is so
       | extremely widespread that collecting royalties is simply
       | impossible. AES-OCB is a prime example of this. It was faster
       | than GCM and not quite as brittle, so many people would've liked
       | to use it - but it was patented. No one used it. It now has a
       | non-commercial FOSS patent grant, which still means no one uses
       | it.
        
         | rdpintqogeogsaa wrote:
         | Rogaway has abandoned his patents on OCB[0]. But by now, AES-
         | GCM has hardware support and is ubiquitous. Nowadays, misuse
         | resistance and resistance against partitioning oracle attacks
         | are things you'd (also) expect from a modern AEAD design. AEGIS
         | outperforms AES-OCB. The AEAD horse has already left the barn;
         | there is no longer any point in closing the door.
         | 
         | [0]
         | https://mailarchive.ietf.org/arch/msg/cfrg/qLTveWOdTJcLn4HP3...
        
       ___________________________________________________________________
       (page generated 2022-01-29 23:01 UTC)