Hacker News new | ask | show | jobs
by natch 472 days ago
And chosen by NIST…
1 comments

And? Finish that thought.
You are tptacek; I believe you know exactly what I meant. But to indulge you, do you think we can know that the selection process is not comprised?
Explain what the compromised selection process does here. NIST doesn't control the submissions.
Seems pretty obvious no?

1. Pretend to be someone else and enter a backdoored algorithm. Or pressure someone to enter a backdoored algorithm for you. Or just give them the algorithm for the reward of being the winner.

2. Be NIST, and choose that algorithm.

You think someone is going to pretend to be Chris Peikert and submit a backdoored construction as him, and that's going to work?

This is the problem with all these modern NIST contest theories. They're not even movie plots. Your last bit, about them paying someone like Peikert off, isn't even coherent; they could do that with or without the contest.

> they could do that with or without the contest

Then why does the contest give you any more confidence that the selection isn't backdoored?

Your question presupposes a claim that the selection process is compromised. I'm not saying it is. I just wonder how we know it's not.

In NIST's position one could analyze the submissions for vulnerabilities to closely held (non-public) attacks, then select submissions having those vulnerabilities.