Hacker News new | ask | show | jobs
by tptacek 25 days ago
You're making my point for me. Nobody in the whole world is asking for you to take NIST's word for anything.

The problem here is that literally the only information you have to work with is Daniel Bernstein, a notorious standards crank. The names of the cryptographers vouching for Kyber don't mean anything to you. Peter Schwabe? Leo Ducas? Chris Peikert? You're not a cryptographer, who could reasonably expect you to know who those people are?

And Bernstein knows it, and plays it to the hilt.

But I already pointed this out. You keep bringing it back to NIST, but I keep telling you: if you simply let a panel of PQC contestants with credible affiliations vote on it, you'd have gotten the same outcome. So we're really just going around in circles here.

1 comments

My problem is with NIST, your problem is with DJB. Neither of us really want to defend either, (I assume, maybe you do want to defend one of them?) We just disagree which one is more likely to make the world worse.

I'm not taken in by the crazyness on either side, and while if pressed, it's obvious which side I would pick. I'm not so much picking a side, so much as complaining again, how we're letting a group with an earned reputation for being untrustworthy keep secrets about crypto. I hate the whole thing, but that's how little trust I have left in other people. The crazy guy is the on the side I hate less... but what to do?

edit:

> You're making my point for me. Nobody in the whole world is asking for you to take NIST's word for anything.

Literally everyone standardizing on Kyber is asking me to trust NIST, et al, and pay the additional overhead for setting up a TLS connection. I guess you could frame it as they're not asking, because I'm not being physically forced to interact with them... but then I try really hard not to engage with bad faith bait, when I'm able to resist.

No, nobody is asking you to trust NIST.
Did you really need me to specify rhetorically speaking? You weren't able to work out that on your own?
Nobody is even rhetorically asking you to trust NIST.
If you run a server using TLS, and that server select Kyber, does the security of the connection depend on Kyber being sound? If I need to trust the security of the connection. I have to trust the server, because the server trusts Kyber, that means I have to trust Kyber, because I have to trust the server.

> you don't have to trust the server

oh, sorry I should have realized this wasn't a conversation anymore

I don't even know who you're replying to anymore; who are you quoting? You get that you and I are the only people reading this, right? You're not going to convince me; you already opened this conversation up by acknowledging you're totally unfamiliar with the field you're commenting on.