Hacker Newsnew | past | comments | ask | show | jobs | submit | philodeon's commentslogin

No, the original claim was by me. And I gave you a plausible story. You just didn’t want to hear it.

https://news.ycombinator.com/item?id=48820336


This is a link to a comment from 38 days ago.


I enjoyed the @tptacek cameo. I suspect tptacek didn’t.


He didn't publicly call me an NSA shill, so I got off pretty easy. Obviously, I stand by what I said. I think it would be an understatement to suggest support for what Bernstein is arguing is a minority cause among cryptographers.


The argument from Roberto Avanzi is reasonable: "as a codesigner of ML-KEM myself I would not trust using it exclusively: what if it gets broken mathematically and in the classical computational model (I.e. non-quantum)? Hybrid is better, and the additional time used by ECC is not significant."


A majority (but not a large majority) of cryptography engineers would use hybrids at this point, and hybrids are largely the default design for any mainstream deployment. Bernstein argument isn't "use hybrids, not pure MLKEM"; it's "MLKEM is so dangerous there shouldn't even be an informational standard saying how to use it". That's a problem, because there are non-mainstream deployment environments where you can't use hybrids.

Obviously, Bernstein is counting on you not following that level of nuance; he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

For clarity: I am not a cryptographer; I'm a vulnerability researcher who does some cryptography work and for several reasons I talk to a lot of academic cryptographers and cryptography engineers. You could not pay me to design a PQC transport protocol for you.


Yes, the argument is MLKEM is so dangerous that it shouldn't be used alone. Even its codesigner says so. Why is it so hard to accept?

Take a look at the crypto from the 80's and 90's. They are considered bad jokes nowadays, badly designed and easily breakable. Why would the first-generation PQC algorithms be any different? Of course they're going to be broken and ridiculed in 20 years, in ways you cannot comprehend yet


I feel like what's most likely happening here, given your initial argument, is that you just learned that this is a debate about whether it should be forbidden to even document a particular MLKEM configuration, and you're now working backwards to the proposition that Bernstein is right.

To that I will only add that lattice cryptography is of approximately the same vintage as elliptic curve (both started in the late 1990s) and MLKEM is past the level of maturity relative to lattices that 25519 was relative to the original P-curves. (Correct me where I'm wrong here --- this is off the top of my head). This isn't "the first generation" of anything.

Just another nuance I think Bernstein is counting on you, the real audience for these posts, not having any intuition for.


That's a weak ad hominem deflection. Readers be the judge.


In addition to noticing that your argument had moved goalposts (the part you claim is an ad hominem, but is not) I also responded substantively to a factual claim you made, and you're pretending otherwise.


You did not in fact respond substantively.


I haven’t read much of the for or against, so it’s certainly possible there’s a whole hidden web of ulterior motives at play here that I’m unaware of (rather than just “there’s a lot of pre-existing bad blood I’m unaware of, which is why both sides are snippy and pedantic”), but I feel compelled to object to this “nuance” point you make. The argument I see being made is “there is NSA pressure to document standalone MLKEM, so that there can be NSA pressure to adopt standalone MLKEM”, which seems fairly straightforward and without nuance to me.


Just so we're clear, you're acknowledging that this argument hinges on the idea that documenting pure MLKEM is dangerous because, once it's documented in an (informational, optional) RFC, but only if it's documented in an RFC, NSA will pressure people to adopt it.


You're working real hard here to misunderstand his point and ignore historically relevant actions by NSA which have weakened and introduced attack vectors into previous standards, facilitating their adoption by orgs worldwide.


Absolutely, that’s more or less exactly what I took away from it.


> A majority (but not a large majority) of cryptography engineers would use hybrids at this point

Actually, based on the WGLC, or the three of them rather, it's pretty clear that Ph.D cryptographers significantly prefer hybrid over pure ML-KEM.

> he'd much rather you believe he's arguing for hybrids against people who are trying to exterminate hybrids.

The brigade by the NSA (6+ votes or more if you include NSA contractors), the AD being former NSA and the moderation of Dr. Bernstein for a footnote seems pretty fair and balanced </sic>.

Meanwhile, the lead of the EU PQC program, professors from several universities, Ph.Ds and, additionally, legendary cryptographers all expressed significant concern and even stronger opposition to the publishing of the draft.

Finally, the chairs refused to share their methodology in determining consensus when asked by several Professors and Ph.Ds.


The legendary cryptographer that isn't Orr Dunkelman that you're referring to would be...?

What's noteworthy about the last list of sponsors of his position that Dan Bernstein posted was how few of them were cryptographers.


> Orr Dunkelman

The great Dr. Orr Dunkelman was admirably vocal in his opposition to the publishing of this draft.


That's why I brought him up. Now, because you used the plural, I'd like to know the other "legendary cryptographer" to which your comment refers.


I'm confused by your messages linked by DJB. You say that better cryptographers would not choose hybrids, which seems to say that you should indeed think that hybrids are not a good choice. Then you say you are not such a good cryptographer and would choose a hybrid. But if you know that more senior cryptographers think they are not the right choice then why choose them anyways? Or am I misreading "cryptography-literate" here?

Can you explain a bit more regarding your statement that DJB's POV on the matter has no broad support amongst his peers? I'm not in the field but Bernstein seemed like a highly respected member with a long track record in the crypto community, at least from the outside. Do you think the community is wrong or is it DJB who's wrong and why? There's also a good chance that I totally missed the argument being made.


I can think of several academic cryptographers (or rather, practitioners with doctorates) who think the hybrid/pure thing is silly. I didn't claim that a majority oppose hybrids. The point of the message he snipped from the HN thread is that pure MLKEM is not considered an unserious design by actual cryptographers (people on the HN thread --- generally not cryptographers, like me --- think it is). Cryptography engineers tend to default to hybrids.

Downthread we develop more clarity about what it is Bernstein is actually in an argument about. It isn't hybrids vs. pure!


I can think of academic practitioners with doctorates who had wildly disastrous opinions about their field of expertise too:

Peter Duesberg, a Ph.D. in molecular biology / retrovirology who taught at Berkley and was a member of the National Academy, who maintained that HIV does not cause AIDS and that antiretroviral drugs do more harm than good.

Walter Freeman, M.D. academic neurologist and first chair of neurology at George Washington University who believed that severing frontal-lobe connections could stabilize personality and stop pathological cycles of thought.

Charles B. Davenport, Ph.D. in biology, geneticist and founder of the Eugenics Record Office.

Henry H. Goddard, Ph.D. in psychology, intelligence-testing researcher and later professor of abnormal psychology who believed intellectual disability, poverty, prostitution, and criminality constituted a hereditary family type.

Clarence Cook Little, Harvard Ph.D., mammalian geneticist and prominent cancer researcher who insisted for years that the evidence did not establish a causal relationship between smoking and lung cancer.

Fun game. We could laugh at all of them, and your examples too, if not for the damage they caused.


Are you a cryptographer?

I am. I literally hold six patents around secure key generation and management. I stand by DJB's points.


The cryptographers in charge of major web browsers, TLS libraries, and programming language standard libraries do not stand by DJB’s points.


Amazing. Six patents! I sign literally everything I write here with my own name, so it's pretty easy to find out my background.


Dunno if there’s patents behind thy name, just ideas/vibe ideas.


[flagged]


[flagged]


[flagged]


I have no idea what the fuck you're talking about here but nobody "lost a grad school spot" to Jacob Appelbaum.

It is true that I was once a Bernstein stan. He's generally been nothing but nice to me. But then I met other cryptographers.


Quoting https://archive.fo/3QWJF#selection-801.0-805.168

“Als Appelbaum im September 2015 an der Technischen Universität Eindhoven ein Doktorandenprogramm beginnt, ist auch sie interessiert. Für Appelbaum ist die Universitätsstelle in Eindhoven auch eine existentielle Stütze, falls er, nach den Vorwürfen im März in Valencia, seine Arbeit beim Tor-Projekt nicht fortsetzen kann. Lovecruft versucht schließlich, bei den selben Professoren wie Appelbaum angenommen zu werden. Am Ende wird ihr das nicht gelingen. Ein anderer Mensch wird jedoch das Büro beziehen, das direkt neben Appelbaums liegt. Es ist der Lebenspartner von Isis Agora Lovecruft oder einer ihrer Lebenspartner, das ist nicht klar. Dieser Mann wird später Arbeiten von Appelbaum bewerten, deren Ergebnisse für dessen Vorankommen in der Universität wichtig sind. Im Januar 2016, kurz nachdem sie an der Universität in Eindhoven abgelehnt wird, beteiligt sich Isis Agora Lovecruft daran, Geschichten zu sammeln über Jacob Appelbaum.”


The person this is about is not an acquaintance of mine. I have no idea if they applied or didn't apply. The person I've spoken to --- am acquainted with (though not personal friends with) is Henry de Valence, who obviously did not lose a spot in Bernstein's lab to Appelbaum.

These are all incredibly creepy and inappropriate accusations for you to be making. They're also wildly against the site guidelines.


Henry de Valence is the person mentioned in that quote as having moved in next door to Appelbaum, as documented by djb:

https://eindhoven.cr.yp.to/false-statements-by-henry-de-vale...



Yes, the plagiarism has been amply demonstrated.

https://ncofnas.com/p/dei-fraud-and-cover-up-at-cambridge


wow, thanks.

that side-by-side view was just crushing.

Instead, if he had gone the route of translate(english->spanish->vietnamese->arabic->english), he could have 1) beat plagiarism 2) gotten few more ideas of how to extend the original thesis to new directions;


Anyone who tries to unironically complain about “DEI” in the headline does not deserve a read. It is just a dog whistle at this point.


Robert Dingwall, an emeritus professor of social sciences at two universities in Nottingham, recommended an impartial investigation, stating: "In the current climate, it is difficult to comment on allegations of plagiarism against a prominent minority scholar without seeming to take sides" on diversity, equity, and inclusion (DEI) policies.

DEI is the singular reason why so many knew the truth about Arday, but refused to do anything about it. It would be heretical to do anything about it.


Practically, I don't think this ends up being true.

It's like asking Fox news to report something bad about republicans, or CNN to report something bad about democrats. Only the "opposition" will expose the dirtier truths. If you're strongly aligned with a "side", and you avoid listening to the "opposition", you're guaranteed to miss out on truth.

Get your news from a wide variety of sources, because they all have very intentional blind spots.


The article has at least a dozen side by side highlighted examples of plagiarism. The title is irrelevant.


More like it is a well established concern, that moderates on both sides of the political spectrum agree that it was overdone in a way that didn't exactly promote meritocracy.


Is this what nu-tolerance looks like?


And just a few years later, Apple shipped an iTunes 2 installer that could wipe your external hard drives.


DJB wrote a short history of NSA’s malicious meddling in the cryptography we all use, based on a declassified internal history of the NSA.

https://blog.cr.yp.to/20220805-nsa.html


> pure ML-KEM is much more "proven" than people are discussing. The core hardness assumption dates back to 2005, and has been intensely studied (the paper introducing it got a cryptography version of a Nobel prize (Godel prize), as did several follow-up works only achievable using that hardness assumption.

The inventor of the lobotomy won a Nobel Prize in Medicine for it.


huh. I really wouldn't want the Nobel Prize committee in medicine doing cryptographic work then. good thing your comment has nothing to do with cryptography then :)


It's brilliant! There's no such thing as time!


> Incorrect. My argument is that they aren't the same entity.

Your mind is going to be blown when you learn about proxy organizations and cut-outs.


NIST does a lot of things that have nothing to do with computer security!

Would you indict NIST MEP https://www.nist.gov/mep/about-nist-mep as being an NSA project without evidence?


The Godfather Part 2 demonstrated overwhelmingly that a good part of Vito Corleone’s ill-gotten gains went to strengthening his community. The Italians in his neighborhood adored him.


What does a work of fiction have to do with whether two distinct government entities are the same thing or not?

That's beyond moving goalposts. Just take the L, dude.


I was making the point that if you have subverted the NIST to do your bidding in what appears to be a neutral way, obviously you’re going to have some feel-good projects in your portfolio. Otherwise, the folks that the Soviets called “useful idiots” wouldn’t have anything to point to to exonerate them.


You're all over the place except where the discussion was actually taking place.


Ok, let me be clear: the NIST is a proxy organization for the NSA. The declassified internal history of the NSA makes it clear that they were subverting the NIST back when they were still called the National Bureau of Standards.

Just because NIST engages in some wholesome activities doesn’t mean that their core purpose isn’t to do the bidding of the NSA.


> Just because NIST engages in some wholesome activities doesn’t mean that their core purpose isn’t to do the bidding of the NSA.

Their core purpose is to recommend standards that everyone can use, and anyone who wants to work with the US government is expected to follow. They have to pick standards for everything, but can't have experts in everything on staff, so are required to defer to other experts willing to help. The NSA took advantage of them. I find the idea that NIST wants to be a lackey to the NSA, stupid. It's ignorance and incompetence that lead NIST to getting duped by the NSA. The problem is, not getting dupe is literally, their *only* job.

It's like hiring a firefighter to protect you and then they set your house on fire; it doesn't matter so much why you don't have a house anymore... you just sure a hell are never letting him near anything important every again.

You're allowed to treat gross incompetence as equivalent to intentional malice, without needing to make something up about how it was intentional.


I’ve tried to submit code that removed old drivers from the kernel build in some distros, and they were universally rejected.

Everyone is afraid of breaking users until Torvalds says it’s ok.


Not only are there a vast amount of modules you’ll never need, the distros build and distribute most of them.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: