This week, something reminded me of a weird experience I've had over the years.
I was probably intending to blog about it at some point, but it's a difficult topic to cover without sounding weirdly self-congratulatory, and I kind of hate that tone. I dunno, maybe it's from years of working in tech? :V
One of the hazards you'll face if you share any of my hobbies or interests is other people--well-meaning, honest, and usually very kind people--praising your apparent "intelligence".
This has also come up a few times indirectly, where friends would be like, "So I asked my [very technically respected] friend about you, and they said cryptography is only for mega-geniuses."
This sort of experience, however it manifests, makes me feel uncomfortable for many reasons.
Me: "All the so-called private messaging apps have inferior cryptography engineering and need to step up their game. It kind of sucks that Signal is the only game in town that has decent e2ee. We can do better. The community just has to have higher standards and stop settling for bad designs."
The NSA is handicapped by being a dual-mission agency. The same organisation is responsible for:
Making sure that the USA's signals are secure.
Making sure that no other country's signals are secure from the USA.
These are in obvious tension when the USA and everyone else are using the same off-the-shelf standards and implementations of those standards.
I'm generally happy that they now prioritise the former over the latter, if only because they now know that there is a good chance that any weakness that they put in will be exploited by the Chinese, but I'd be a lot more comfortable if they properly separated the two concerns.
I am still curious about Heartbleed because a lot of the US government was vulnerable and I know the NSA did some review of OpenSSL, so I don't know which of the following options was true:
They didn't bother to review a core piece of security-critical software that a lot of the government's security depended on (I have some evidence that it wasn't this one).
They did review it and missed a really important bug.
They did review it, found the bug, and made a staggeringly bad call about whether it was better to fix the bug or keep it as a thing to attack other people with.
None of these possibilities makes them look especially competent.
@drwho Orr is, apparently, generally positively regarded by my peers. Their email (but mostly the IETF thread that preceded it) just struck me the wrong way.
There are very intelligent and passionate engineers, cryptographers, and analysts that vehemently disagree with my conclusions about the Hybrid debate. That's okay!
But Bernstein summoned a mob of ill-informed people with messages designed to alarm them into action.
Every one of these agencies has a mission and a budget. To your or I, that budget might seem like "damn near infinite", but they still have constraints.
NSA has two missions. Everyone knows about SIGINT because of Snowden, but they also have a competing mission called COMINT.
You can, very loosely, map these two terms to "red team" and "blue team".
If NSA knew a top secret way to break ML-KEM and were fairly confident that no other country has thought of it, there is no way in hell the SIGINT people could get the COMINT people to agree on a plan to migrate the entire federal fucking government to use ML-KEM. It doesn't line up with their self-interest.
Like, I am NOT a fan of the NSA, in the same way that I'm not a fan of Meta, Palantir, and the data broker industry.
Surveillance is bad for society. Privacy is good for society. Using technology to undermine privacy and surveil people is a bad thing, actually. And while the official story is roughly that NSA only spies on other governments, and not innocent civilians, we have no way of knowing if that's true. And there's no way in hell I'll ever trust that.
So, like most cryptographers, I'm squarely in the "Fuck the NSA" camp. Just like I'm in the "Fuck the FSB" camp. And every other nation state's equivalent agency is on that list too.
But spy agencies aren't fucking magical. They can't violate information theory, physics, or causality.
They also aren't omniscient about mathematics, logic, or software vulnerabilities. If they were, they wouldn't have competition. And they can't wave a magic wand and get enthusiastic cooperation from international forums of cryptology experts. That's ridiculous.
He/him. Gay/demi dhole (Cuon Alpinus) furry.Blogger, programmer, security engineer, cryptography nerd. 30+Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16)I don't represent any company, individual, or community.