Mathematician warns NSA may be weakening next-gen encryption::Quantum computers may soon be able to crack encryption methods in use today, so plans are already under way to replace them with new, secure algorithms. Now it seems the US National Security Agency may be undermining that process

  • redcalcium@lemmy.institute
    link
    fedilink
    English
    arrow-up
    114
    ·
    edit-2
    9 months ago

    Daniel Bernstein (djb) is a well known and respected cryptography researcher so his claim carries a lot of weight. It’s also worth noting that NIST didn’t invent these post quantum encryption algorithm. Instead, they run a competition and select a winner. Djb’s algorithm got a second place, so people were wondering if he’s just being salty about it, though if NIST were really compromised, it’s not hard to imagine they’ll select a weaker algorithm as the winner instead. NIST has posted a response which might be worth a read.

    Edit: added links to djb’s original post

    • Shadow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      13
      ·
      edit-2
      9 months ago

      I wish I could understand that math in that thread.

      I have great respect for djb, but he was an ass here.

      • fmstrat@lemmy.nowsci.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        9 months ago

        The second link has replies that even say the OPs link contains conspiracy theory. The discussion there is better than all else, IMO.

        Note: not denying Dan’s claim as I’m not an expert here, just reiterating what I’m reading.

        • atzanteol@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          9 months ago

          Yeah - at the very list it shows that this is more “reasonable people disagreeing about a detail” than it is “OMG THE NSA IS DESTROYING CRYPTO!”

          • fmstrat@lemmy.nowsci.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 months ago

            I mean, DJB does mention NSA has more involvement over NIST than he expected, but that also doesn’t mean their would be collaboration.

            In my non-expert reading, NIST made it seem better than it was, DJB disagreed but overestimated how bad it was, and NIST “sort of” said “yea OK we may have bragged.”

            Either way, DJB is right to call out something being weaker than it should be. False confidence in encryption is about the worse thing that could happen in the digital age.

            • atzanteol@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              ·
              9 months ago

              Yeah - DJB definitely has a point to make and deserves to be listened to. But “Mathematician has questions about crypto complexity guidelines from NIST” isn’t click-baity enough.