[HN Gopher] NIST Announces First Four Quantum-Resistant Cryptogr...
___________________________________________________________________
NIST Announces First Four Quantum-Resistant Cryptographic
Algorithms
Author : dchest
Score : 79 points
Date : 2022-07-05 16:56 UTC (6 hours ago)
(HTM) web link (www.nist.gov)
(TXT) w3m dump (www.nist.gov)
| gnabgib wrote:
| Sort of a dupe of [NIST announces first PQC algorithms to be
| standardized](https://news.ycombinator.com/item?id=31990276) (64
| points, 23 comments) although this is probably a better link
| matt321 wrote:
| CRYSTALS-Kyber and CRYSTALS-Dilithium are references to star wars
| and star trek FYI to those who didn't know.
| bwesterb wrote:
| Kyber is lead by Crypto Jedi: https://cryptojedi.org/peter/ :)
| dchest wrote:
| Who also created another PQC algorithm (that didn't make it
| past 2nd round) -- NewHope https://newhopecrypto.org/
| capableweb wrote:
| Kyber is a fictional thing, so I understand that it's a Star
| Wars reference. But Dilithium is a real thing, so not sure why
| that would be a Star Trek reference? Couldn't it just be a
| reference to the real thing somehow?
| camjw wrote:
| Wikipedia says that Dilithium exists when Lithium is in the
| gas phase i.e. not crystalline. So, CRYSTALS-Dilithium
| presumably refers to Dilithium Crystals which are often
| referred to in Star Trek.
| burkaman wrote:
| Dilithium is a real molecule, but dilithium crystals are a
| fictional Star Trek thing.
| https://en.wikipedia.org/wiki/Dilithium_(Star_Trek)
| kemiller2002 wrote:
| I would guess that since the other is a Star Wars reference
| Dilithium is meant to be Star Trek. It follows the pattern,
| and Dilithium is a famous reference for those who follow Star
| Trek.
| [deleted]
| capableweb wrote:
| Is there any alternative organizations like NIST but not-NIST?
|
| That NIST worked together with NSA to allow/insert backdoors into
| cryptography kind of left a sour taste in my mouth, and it's hard
| to trust them again after that.
| hannob wrote:
| There's no need for one.
|
| How NIST chose algorithms in the past was done in quite diverse
| ways. Sometimes they merely said "this is a standard" and
| people could comment and the comments were ignored. This is
| basically what happened with Dual EC DRBG, whcih is the likely
| example you're referring to.
|
| However the way this standardization worked - and several
| others before, like AES and SHA-3 - is that NIST made a public
| competition. They basically asked everyone to submit proposals
| and then asked everyone to find flaws in theses proposals.
|
| These competitions have a very good reputation in the
| cryptographic community. An algorithm like Dual EC where the
| issues were quite obvious would've never survived such a
| process.
|
| The thing you should look at is the process, not the
| organization.
| mort96 wrote:
| I don't understand cryptography enough to vet algorithms. I
| need to trust an authority to tell me which algorithms to
| use. I do not trust NIST as an authority. That's why it would
| be nice to have an actually trustworthy authority which does
| similar work to NIST.
|
| EDIT: To more specifically address the process: If NIST
| wanted to get people to trust a shady algorithm, they could
| have some amazing cryptographers invent an algorithm which
| stands up to scrutiny, but which has some extremely hard to
| notice flaw which only they know about. They could then make
| those cryptographers submit the algorithm to NIST, and, in a
| seemingly fair way, pick the subtly broken algorithm as the
| winner. I can't know whether this happened of course, and it
| _probably_ didn 't, but we fundamentally have to trust that
| NIST wouldn't do something like that... and we do know that
| they would do, and indeed have done, something like that.
|
| Maybe the process is such that this attack, and any other
| kind of attack, is impossible. If that's the case, please do
| cite something which goes into detail on that.
| DennisP wrote:
| NIST wouldn't get away with choosing an algorithm that has
| been shown to have vulnerabilities, which is the only thing
| it could do is come up with an algorithm with a subtle
| unnoticed flaw. And that algorithm has to have performance
| at least as good as the other algorithms in the contest.
|
| But if it can come up with a competitive algorithm with a
| subtle unnoticed flaw, than that attack would work almost
| as well in a contest hosted by some other organization.
| They wouldn't be able to guarantee the win, but they would
| still have a good shot at it.
| mabbo wrote:
| What if those trustworthy organizations were to tell you:
| "We trust this NIST competition result, and so should you"?
| mort96 wrote:
| Maybe, if their reasoning for trusting the NIST
| competition result holds up to scrutiny. Do you have any
| links to trustworthy organizations which wholly endorse
| the results, with a detailed write-up as to why?
| jvanderbot wrote:
| I think we can revisit OP:
|
| > However the way this standardization worked - and
| several others before, like AES and SHA-3 - is that NIST
| made a public competition. They basically asked everyone
| to submit proposals and then asked everyone to find flaws
| in theses proposals.
|
| > These competitions have a very good reputation in the
| cryptographic community.
|
| A very brief google search provided citations to the
| proposals and counter-attacks for your perusal.
|
| https://en.wikipedia.org/wiki/NIST_Post-
| Quantum_Cryptography...
| giomasce wrote:
| Who do you trust as an authority?
| mort96 wrote:
| I don't know, but organizations which haven't duped
| people into using broken crypto before would be a good
| start.
| anfilt wrote:
| Like if you dont like the US NIST standards there is the
| Japanese CRYPTREC, and European NESSIE. Alot the same
| algos as NIST though.
| capableweb wrote:
| > The thing you should look at is the process, not the
| organization.
|
| Then there shouldn't be a problem with another organization
| hosting the contest than NIST? Since I'm probably not alone
| in not being able to trust them anymore.
| tptacek wrote:
| There isn't a problem, except that nobody will take the
| other organization's contest especially seriously, or write
| its name into contracts.
| gfaster wrote:
| I can't imagine with the added scrutiny the internet has gotten
| since then, especially from foreign governments, that NIST will
| be able to get away with anything like that again.
|
| But then again I may be completely ignorant as to the scope of
| NSA meddling.
| throw0101a wrote:
| > [...] _that NIST will be able to get away with anything
| like that again._
|
| You say this like NIST was an accomplice (and not also a
| victim).
| capableweb wrote:
| If someone pressures (with just words and no threats) you
| into shooting another person, do you not at least partly
| hold some of the blame yourself?
|
| Not sure what consequences NSA told NIST would happen if
| they said no, when they pressured them, but from the look
| of things (https://harvardnsj.org/wp-
| content/uploads/sites/13/2022/06/V...) it seems that NSA
| just asked NIST nicely to make Dual_EC_DRBG a FIPS even as
| it was weak, and NIST accepted that.
| anotherrandom wrote:
| Well, you could always look for when the Russians or Chinese
| come out with their own and hope the NSA doesn't know those
| backdoors.
|
| Russia didn't develop Kuznyechik for nothing
| throw0101a wrote:
| > _Is there any alternative organizations like NIST but not-
| NIST?_
|
| Not especially if you're in the US and want to work with
| government systems or be a sub-contractor to a company that
| does. Otherwise pick an algorithm and have at it:
|
| * https://xkcd.com/927/
|
| > _That NIST worked together with NSA_ [...]
|
| Did they? Or did the NSA lie to NIST?
|
| * https://www.schneier.com/blog/archives/2022/06/on-the-
| subver...
| throwoutway wrote:
| Wasn't it that NIST was unwittingly tricked into accepting the
| NSA's expertise while the NSA maliciously provided that
| expertise in bad faith?
|
| And didn't they subsequently ban the NSA from their input once
| the Snowden leaks were out?
|
| So I don't think it's fair to disregard NIST completely. And
| the international counterparts can compare & perform their own
| due diligence
| capableweb wrote:
| > Wasn't it that NIST was unwittingly tricked into accepting
| the NSA's expertise while the NSA maliciously provided that
| expertise in bad faith?
|
| Not sure if that's better or worse than them collaborating
| directly.
|
| Edit: from a paper linked in another comment:
|
| > Researchers raised concerns to NIST about both possible
| bias in the bits and a possible backdoor in Dual_EC_DRBG.
| NIST examined the issue. NSA dismissed NIST's concerns,
| responding that implementers could choose their own
| parameters to handle concerns about possible backdoors. NSA
| pressed NIST to standardize the algorithm, claiming that it
| needed FIPS validation of agency devices running
| Dual_EC_DRBG, and thus NIST approved Dual_EC_DRBG as one of
| four possible standardized random-bit generators.
| Dual_EC_DRBG remained a FIPS until shortly after the 2013
| revelation of an NSA backdoor in a cryptographic algorithm.
|
| https://harvardnsj.org/wp-
| content/uploads/sites/13/2022/06/V...
|
| So seems NIST and others were aware of the shortcomings of
| Dual_EC_DRBG but was pressured by NSA to end up as a FIPS
| anyway.
|
| Either way, hard to start trusting NIST again after a fiasco
| like that.
|
| > And didn't they subsequently ban the NSA from their input
| once the Snowden leaks were out?
|
| AFAIK, NSA didn't submit anything for this competition, but
| bunch of mathematicians from NSA have worked on helping NIST
| with the overall process of the competition, including
| reviewing the entries.
|
| It wouldn't surprise me that if NSA found something, they
| would withhold any findings if they could benefit from being
| the only ones knowing about any holes. Although we all know
| how that ends.
|
| > And the international counterparts can compare & perform
| their own due diligence
|
| Yes, this is exactly what I'm asking for, the purpose of my
| initial comment. Who are these international counterparts
| that I can look to instead of NIST?
| Terry_Roll wrote:
| > It wouldn't surprise me that if NSA found something, they
| would withhold any findings if they could benefit from
| being the only ones knowing about any holes. Although we
| all know how that ends.
|
| I think you would be correct and do you know that ends?
| Vecr wrote:
| You could look at the German BSI Federal Office for Information
| Security's documents, but you can't implement anything just by
| reading them, and they won't teach you about various attacks or
| other basic cryptographic principles.
| tptacek wrote:
| This is just about the most boring point you can raise about a
| NIST competition. It's right there on the label: "NIST". We get
| it. People don't like NIST, because of BULLRUN.
|
| The problem this argument has is that NIST competitions are
| legitimated by their participants. People trust NIST's hash
| competition because of who entered, and because the winning
| team has an unimpeachable record. For the most part, people
| will trust this contest for similar reasons. If you could get
| this cast of cryptographers _not_ to submit to NIST contests,
| _and_ instead submit to some other contest, we 'd have
| something productive to talk about. But you can't, and so, when
| we talk about contest-based cryptography standards, you're
| going to end up back at NIST.
|
| I don't like NIST for another, better reason: I think the whole
| enterprise of picking cryptography standards in advance is
| bankrupt, and holds the industry back. So I'm not a NIST fan
| either. But I don't see what's to be gained by derailing
| conversations about new cryptography so we can relitigate the
| same points over and over again.
|
| Meanwhile: pull up the authorship team on CRYSTALS-KYBER.
| Approximately 0% of credible cryptographers believe that NIST
| was somehow able to exert improper influence over this design.
| capableweb wrote:
| > I don't like NIST for another, better reason: I think the
| whole enterprise of picking cryptography standards in advance
| is bankrupt, and holds the industry back. So I'm not a NIST
| fan either. But I don't see what's to be gained by derailing
| conversations about new cryptography so we can relitigate the
| same points over and over again.
|
| Sorry if you think I'm trying to convince people of anything.
| I'm simply asking for alternatives to NIST itself, for my own
| personal and selfish reasons. I'm not arguing against other
| people trusting NIST, their competitions or anything like
| that. Just asking a question regarding alternatives.
|
| I'm glad you and others answered. Someone even gave a proper
| alternative based in Germany, and for that I'm very happy.
| I'm sorry you feel like people are "relitigating the same
| points over and over again", I cannot steer the conversation
| any more than you can and I personally haven't seen any
| conversations on HN about alternatives to NIST, then
| obviously I wouldn't ask for it, if I already knew the
| answer.
| tptacek wrote:
| You said "NIST worked together with NSA to allow/insert
| backdoors into cryptography". It's been pointed out a
| couple times now that neither NIST nor NSA designed these
| schemes; they were submitted by the highest-profile
| academic cryptography research teams in the world. You
| aren't being asked to trust NIST in any meaningful way.
|
| The closest analog to NIST I can think of is ECRYPT and the
| eSTREAM contest. It produced interesting work and you could
| follow it in much the same way people followed these last
| two NIST competitions. But for PQ KEMs, it's likely that
| NIST's will be the "competition of record".
| deelowe wrote:
| They didn't say anything about NIST competitions.
| burkaman wrote:
| There's a recent paper on this topic if you're looking for a
| very in-depth discussion: https://harvardnsj.org/wp-
| content/uploads/sites/13/2022/06/V...
|
| The conclusion is no, there is no alternative right now.
| cubistack wrote:
| Does 'quantum-resistant' also imply 'P=NP' resistant?
| blendergeek wrote:
| No. Public key cryptography is impossible if P=NP. What we are
| left with is shared one-time-pads that can be arranged using
| quantum key distribution.
|
| I am not an expert so I will simply link the Wikipedia article
| on Computational Complexity Theory as my "source".
|
| https://en.m.wikipedia.org/wiki/Computational_complexity_the...
| bwesterb wrote:
| If there is an n^(100^100) algorithm that solves an NP-
| complete problem, then P=NP, but public-key cryptography is
| still safe because for any practical n it's still too hard to
| break. There are also public-key systems that are based on
| NP-complete problems that are easily broken, because n is
| chosen too small.
___________________________________________________________________
(page generated 2022-07-05 23:01 UTC)