news.volyx.in

Debunking NIST's calculation of the Kyber-512 security level (blog.cr.yp.to)

468 points by bumbledraven · 1056 days ago · 201 comments on HN

Article summary

The article discusses a potential error in NIST's calculation of the security level of the Kyber-512 cryptosystem, specifically a miscalculation involving the multiplication of costs that should have been added. The author suggests that this error may have been intentional, rather than a mistake, and criticizes NIST's review process for failing to catch it. The article also touches on the involvement of the NSA in the standardization process and the potential for backdoors in cryptographic standards. The author's goal is to highlight the importance of careful review and transparency in the development of cryptographic standards.

Main themes

  • Cryptographic standards
  • NIST and NSA involvement
  • Error in security calculation
  • Potential backdoors
  • Transparency and review
  • Academic cryptographers
  • Government influence and coercion

What commenters say

  • The NSA's involvement in the standardization process raises concerns about potential backdoors in cryptographic standards.
  • The error in NIST's calculation may have been intentional, rather than a mistake, and reflects a larger problem with the standardization process.
  • The use of flawed cryptographic standards can have serious consequences, including compromising the security of sensitive information.
  • The involvement of academic cryptographers in the standardization process does not necessarily guarantee the security of the resulting standards.
  • The NSA's ability to corrupt or influence academic cryptographers is a potential threat to the security of cryptographic standards.
  • The development of cryptographic standards should prioritize transparency and careful review to prevent errors and ensure security.
  • The potential for coercion or influence by government agencies is a concern in the development of cryptographic standards.
  • The security of cryptographic standards depends on the integrity of the standardization process, which can be compromised by errors, influence, or coercion.