[HN Gopher] NIST Announces First Four Quantum-Resistant Cryptogr...
       ___________________________________________________________________
        
       NIST Announces First Four Quantum-Resistant Cryptographic
       Algorithms
        
       Author : dchest
       Score  : 79 points
       Date   : 2022-07-05 16:56 UTC (6 hours ago)
        
 (HTM) web link (www.nist.gov)
 (TXT) w3m dump (www.nist.gov)
        
       | gnabgib wrote:
       | Sort of a dupe of [NIST announces first PQC algorithms to be
       | standardized](https://news.ycombinator.com/item?id=31990276) (64
       | points, 23 comments) although this is probably a better link
        
       | matt321 wrote:
       | CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars
       | and star trek FYI to those who didn't know.
        
         | bwesterb wrote:
         | Kyber is lead by Crypto Jedi: https://cryptojedi.org/peter/ :)
        
           | dchest wrote:
           | Who also created another PQC algorithm (that didn't make it
           | past 2nd round) -- NewHope https://newhopecrypto.org/
        
         | capableweb wrote:
         | Kyber is a fictional thing, so I understand that it's a Star
         | Wars reference. But Dilithium is a real thing, so not sure why
         | that would be a Star Trek reference? Couldn't it just be a
         | reference to the real thing somehow?
        
           | camjw wrote:
           | Wikipedia says that Dilithium exists when Lithium is in the
           | gas phase i.e. not crystalline. So, CRYSTALS-Dilithium
           | presumably refers to Dilithium Crystals which are often
           | referred to in Star Trek.
        
           | burkaman wrote:
           | Dilithium is a real molecule, but dilithium crystals are a
           | fictional Star Trek thing.
           | https://en.wikipedia.org/wiki/Dilithium_(Star_Trek)
        
           | kemiller2002 wrote:
           | I would guess that since the other is a Star Wars reference
           | Dilithium is meant to be Star Trek. It follows the pattern,
           | and Dilithium is a famous reference for those who follow Star
           | Trek.
        
         | [deleted]
        
       | capableweb wrote:
       | Is there any alternative organizations like NIST but not-NIST?
       | 
       | That NIST worked together with NSA to allow/insert backdoors into
       | cryptography kind of left a sour taste in my mouth, and it's hard
       | to trust them again after that.
        
         | hannob wrote:
         | There's no need for one.
         | 
         | How NIST chose algorithms in the past was done in quite diverse
         | ways. Sometimes they merely said "this is a standard" and
         | people could comment and the comments were ignored. This is
         | basically what happened with Dual EC DRBG, whcih is the likely
         | example you're referring to.
         | 
         | However the way this standardization worked - and several
         | others before, like AES and SHA-3 - is that NIST made a public
         | competition. They basically asked everyone to submit proposals
         | and then asked everyone to find flaws in theses proposals.
         | 
         | These competitions have a very good reputation in the
         | cryptographic community. An algorithm like Dual EC where the
         | issues were quite obvious would've never survived such a
         | process.
         | 
         | The thing you should look at is the process, not the
         | organization.
        
           | mort96 wrote:
           | I don't understand cryptography enough to vet algorithms. I
           | need to trust an authority to tell me which algorithms to
           | use. I do not trust NIST as an authority. That's why it would
           | be nice to have an actually trustworthy authority which does
           | similar work to NIST.
           | 
           | EDIT: To more specifically address the process: If NIST
           | wanted to get people to trust a shady algorithm, they could
           | have some amazing cryptographers invent an algorithm which
           | stands up to scrutiny, but which has some extremely hard to
           | notice flaw which only they know about. They could then make
           | those cryptographers submit the algorithm to NIST, and, in a
           | seemingly fair way, pick the subtly broken algorithm as the
           | winner. I can't know whether this happened of course, and it
           | _probably_ didn 't, but we fundamentally have to trust that
           | NIST wouldn't do something like that... and we do know that
           | they would do, and indeed have done, something like that.
           | 
           | Maybe the process is such that this attack, and any other
           | kind of attack, is impossible. If that's the case, please do
           | cite something which goes into detail on that.
        
             | DennisP wrote:
             | NIST wouldn't get away with choosing an algorithm that has
             | been shown to have vulnerabilities, which is the only thing
             | it could do is come up with an algorithm with a subtle
             | unnoticed flaw. And that algorithm has to have performance
             | at least as good as the other algorithms in the contest.
             | 
             | But if it can come up with a competitive algorithm with a
             | subtle unnoticed flaw, than that attack would work almost
             | as well in a contest hosted by some other organization.
             | They wouldn't be able to guarantee the win, but they would
             | still have a good shot at it.
        
             | mabbo wrote:
             | What if those trustworthy organizations were to tell you:
             | "We trust this NIST competition result, and so should you"?
        
               | mort96 wrote:
               | Maybe, if their reasoning for trusting the NIST
               | competition result holds up to scrutiny. Do you have any
               | links to trustworthy organizations which wholly endorse
               | the results, with a detailed write-up as to why?
        
               | jvanderbot wrote:
               | I think we can revisit OP:
               | 
               | > However the way this standardization worked - and
               | several others before, like AES and SHA-3 - is that NIST
               | made a public competition. They basically asked everyone
               | to submit proposals and then asked everyone to find flaws
               | in theses proposals.
               | 
               | > These competitions have a very good reputation in the
               | cryptographic community.
               | 
               | A very brief google search provided citations to the
               | proposals and counter-attacks for your perusal.
               | 
               | https://en.wikipedia.org/wiki/NIST_Post-
               | Quantum_Cryptography...
        
             | giomasce wrote:
             | Who do you trust as an authority?
        
               | mort96 wrote:
               | I don't know, but organizations which haven't duped
               | people into using broken crypto before would be a good
               | start.
        
               | anfilt wrote:
               | Like if you dont like the US NIST standards there is the
               | Japanese CRYPTREC, and European NESSIE. Alot the same
               | algos as NIST though.
        
           | capableweb wrote:
           | > The thing you should look at is the process, not the
           | organization.
           | 
           | Then there shouldn't be a problem with another organization
           | hosting the contest than NIST? Since I'm probably not alone
           | in not being able to trust them anymore.
        
             | tptacek wrote:
             | There isn't a problem, except that nobody will take the
             | other organization's contest especially seriously, or write
             | its name into contracts.
        
         | gfaster wrote:
         | I can't imagine with the added scrutiny the internet has gotten
         | since then, especially from foreign governments, that NIST will
         | be able to get away with anything like that again.
         | 
         | But then again I may be completely ignorant as to the scope of
         | NSA meddling.
        
           | throw0101a wrote:
           | > [...] _that NIST will be able to get away with anything
           | like that again._
           | 
           | You say this like NIST was an accomplice (and not also a
           | victim).
        
             | capableweb wrote:
             | If someone pressures (with just words and no threats) you
             | into shooting another person, do you not at least partly
             | hold some of the blame yourself?
             | 
             | Not sure what consequences NSA told NIST would happen if
             | they said no, when they pressured them, but from the look
             | of things (https://harvardnsj.org/wp-
             | content/uploads/sites/13/2022/06/V...) it seems that NSA
             | just asked NIST nicely to make Dual_EC_DRBG a FIPS even as
             | it was weak, and NIST accepted that.
        
         | anotherrandom wrote:
         | Well, you could always look for when the Russians or Chinese
         | come out with their own and hope the NSA doesn't know those
         | backdoors.
         | 
         | Russia didn't develop Kuznyechik for nothing
        
         | throw0101a wrote:
         | > _Is there any alternative organizations like NIST but not-
         | NIST?_
         | 
         | Not especially if you're in the US and want to work with
         | government systems or be a sub-contractor to a company that
         | does. Otherwise pick an algorithm and have at it:
         | 
         | * https://xkcd.com/927/
         | 
         | > _That NIST worked together with NSA_ [...]
         | 
         | Did they? Or did the NSA lie to NIST?
         | 
         | * https://www.schneier.com/blog/archives/2022/06/on-the-
         | subver...
        
         | throwoutway wrote:
         | Wasn't it that NIST was unwittingly tricked into accepting the
         | NSA's expertise while the NSA maliciously provided that
         | expertise in bad faith?
         | 
         | And didn't they subsequently ban the NSA from their input once
         | the Snowden leaks were out?
         | 
         | So I don't think it's fair to disregard NIST completely. And
         | the international counterparts can compare & perform their own
         | due diligence
        
           | capableweb wrote:
           | > Wasn't it that NIST was unwittingly tricked into accepting
           | the NSA's expertise while the NSA maliciously provided that
           | expertise in bad faith?
           | 
           | Not sure if that's better or worse than them collaborating
           | directly.
           | 
           | Edit: from a paper linked in another comment:
           | 
           | > Researchers raised concerns to NIST about both possible
           | bias in the bits and a possible backdoor in Dual_EC_DRBG.
           | NIST examined the issue. NSA dismissed NIST's concerns,
           | responding that implementers could choose their own
           | parameters to handle concerns about possible backdoors. NSA
           | pressed NIST to standardize the algorithm, claiming that it
           | needed FIPS validation of agency devices running
           | Dual_EC_DRBG, and thus NIST approved Dual_EC_DRBG as one of
           | four possible standardized random-bit generators.
           | Dual_EC_DRBG remained a FIPS until shortly after the 2013
           | revelation of an NSA backdoor in a cryptographic algorithm.
           | 
           | https://harvardnsj.org/wp-
           | content/uploads/sites/13/2022/06/V...
           | 
           | So seems NIST and others were aware of the shortcomings of
           | Dual_EC_DRBG but was pressured by NSA to end up as a FIPS
           | anyway.
           | 
           | Either way, hard to start trusting NIST again after a fiasco
           | like that.
           | 
           | > And didn't they subsequently ban the NSA from their input
           | once the Snowden leaks were out?
           | 
           | AFAIK, NSA didn't submit anything for this competition, but
           | bunch of mathematicians from NSA have worked on helping NIST
           | with the overall process of the competition, including
           | reviewing the entries.
           | 
           | It wouldn't surprise me that if NSA found something, they
           | would withhold any findings if they could benefit from being
           | the only ones knowing about any holes. Although we all know
           | how that ends.
           | 
           | > And the international counterparts can compare & perform
           | their own due diligence
           | 
           | Yes, this is exactly what I'm asking for, the purpose of my
           | initial comment. Who are these international counterparts
           | that I can look to instead of NIST?
        
             | Terry_Roll wrote:
             | > It wouldn't surprise me that if NSA found something, they
             | would withhold any findings if they could benefit from
             | being the only ones knowing about any holes. Although we
             | all know how that ends.
             | 
             | I think you would be correct and do you know that ends?
        
         | Vecr wrote:
         | You could look at the German BSI Federal Office for Information
         | Security's documents, but you can't implement anything just by
         | reading them, and they won't teach you about various attacks or
         | other basic cryptographic principles.
        
         | tptacek wrote:
         | This is just about the most boring point you can raise about a
         | NIST competition. It's right there on the label: "NIST". We get
         | it. People don't like NIST, because of BULLRUN.
         | 
         | The problem this argument has is that NIST competitions are
         | legitimated by their participants. People trust NIST's hash
         | competition because of who entered, and because the winning
         | team has an unimpeachable record. For the most part, people
         | will trust this contest for similar reasons. If you could get
         | this cast of cryptographers _not_ to submit to NIST contests,
         | _and_ instead submit to some other contest, we 'd have
         | something productive to talk about. But you can't, and so, when
         | we talk about contest-based cryptography standards, you're
         | going to end up back at NIST.
         | 
         | I don't like NIST for another, better reason: I think the whole
         | enterprise of picking cryptography standards in advance is
         | bankrupt, and holds the industry back. So I'm not a NIST fan
         | either. But I don't see what's to be gained by derailing
         | conversations about new cryptography so we can relitigate the
         | same points over and over again.
         | 
         | Meanwhile: pull up the authorship team on CRYSTALS-KYBER.
         | Approximately 0% of credible cryptographers believe that NIST
         | was somehow able to exert improper influence over this design.
        
           | capableweb wrote:
           | > I don't like NIST for another, better reason: I think the
           | whole enterprise of picking cryptography standards in advance
           | is bankrupt, and holds the industry back. So I'm not a NIST
           | fan either. But I don't see what's to be gained by derailing
           | conversations about new cryptography so we can relitigate the
           | same points over and over again.
           | 
           | Sorry if you think I'm trying to convince people of anything.
           | I'm simply asking for alternatives to NIST itself, for my own
           | personal and selfish reasons. I'm not arguing against other
           | people trusting NIST, their competitions or anything like
           | that. Just asking a question regarding alternatives.
           | 
           | I'm glad you and others answered. Someone even gave a proper
           | alternative based in Germany, and for that I'm very happy.
           | I'm sorry you feel like people are "relitigating the same
           | points over and over again", I cannot steer the conversation
           | any more than you can and I personally haven't seen any
           | conversations on HN about alternatives to NIST, then
           | obviously I wouldn't ask for it, if I already knew the
           | answer.
        
             | tptacek wrote:
             | You said "NIST worked together with NSA to allow/insert
             | backdoors into cryptography". It's been pointed out a
             | couple times now that neither NIST nor NSA designed these
             | schemes; they were submitted by the highest-profile
             | academic cryptography research teams in the world. You
             | aren't being asked to trust NIST in any meaningful way.
             | 
             | The closest analog to NIST I can think of is ECRYPT and the
             | eSTREAM contest. It produced interesting work and you could
             | follow it in much the same way people followed these last
             | two NIST competitions. But for PQ KEMs, it's likely that
             | NIST's will be the "competition of record".
        
           | deelowe wrote:
           | They didn't say anything about NIST competitions.
        
         | burkaman wrote:
         | There's a recent paper on this topic if you're looking for a
         | very in-depth discussion: https://harvardnsj.org/wp-
         | content/uploads/sites/13/2022/06/V...
         | 
         | The conclusion is no, there is no alternative right now.
        
       | cubistack wrote:
       | Does 'quantum-resistant' also imply 'P=NP' resistant?
        
         | blendergeek wrote:
         | No. Public key cryptography is impossible if P=NP. What we are
         | left with is shared one-time-pads that can be arranged using
         | quantum key distribution.
         | 
         | I am not an expert so I will simply link the Wikipedia article
         | on Computational Complexity Theory as my "source".
         | 
         | https://en.m.wikipedia.org/wiki/Computational_complexity_the...
        
           | bwesterb wrote:
           | If there is an n^(100^100) algorithm that solves an NP-
           | complete problem, then P=NP, but public-key cryptography is
           | still safe because for any practical n it's still too hard to
           | break. There are also public-key systems that are based on
           | NP-complete problems that are easily broken, because n is
           | chosen too small.
        
       ___________________________________________________________________
       (page generated 2022-07-05 23:01 UTC)