NSA and IETF: The Fight for Fairness in Post-Quantum Cryptography

NSA and IETF: Fairness

I expose how the NSA has historically manipulated standards to weaken security, from DES to Dual_EC. Now, they are pushing the IETF to adopt solo ML-KEM, ignoring serious risks of software bugs and specification flaws. Despite objections from experts like Orr Dunkelman and Peter Gutmann, proponents try to silence dissent. I urge the community to reject this overtly NSA-driven push and demand fair, secure standards.

NSA by the 2010s had a quarter-billion-dollar-a-year budget to covertly influence and/or overtly leverage standards and other systems to make them exploitable while the consumer and other adversaries think that the systems security remains intact.
  1. tptacek

    The two most important things to understand about this kerfuffle:

    (1) MLKEM wasn't designed by NSA, but rather by a team of highly-regarded European academic cryptographers, including Bernstein's former collaborator Peter Schwabe; their submission, Kyber, was selected in an open competition in which Bernstein himself submitted a closely-related algorithm (and then contested the result, suing NIST for documents to clarify the selection.)

    (2) The RFC at issue documents the possibility of running TLS with pure MLKEM rather than in a hybrid configuration with ECDH. Hybrid TLS is already the mainstream, documented, standardized method for using PQC in a TLS connection. Bernstein is canvassing opposition to any documentation of the possibility of pure MLKEM in TLS.

    Every time Bernstein talks about NSA's sordid history, remember: nothing that's happening here has really anything to do with NSA. It would make more sense for Bernstein to be canvassing against SHA2, which NSA actually did design. But he can't do that, because normal people know enough about cryptography to understand how crazy a claim that is. Unfortunately, we can't yet say that about lattice cryptography, despite it being approximately as well-studied as ECC.

  2. yardstick

    DJB has orchestrated a vote rigging campaign against this WGLC, encouraging users to join the list and vote/express their opinion and providing the exact subject header to use. Have any other sides been saying, essentially, just join the group and say you’re for/against?

    He’s been moderated during the last call because of his email disclaimer/footnote, and apparently refuses to respond on list during this time. Seems like he’s playing a few steps ahead where he can (yet again) cry foul on the system and cry foul on vote rigging. Despite him being a key instigator. I’ve already seen at least one poster reference a RFC explaining how IETF consensus works and how its not a pure numbers game (5 for and 100 against can still be consensus, depending on the circumstances; the inverse also applies).

    What’s his next step if the authors publish as an information RFC? He can’t stop that, right?

  3. thomasdeleeuw

    France and Germany propose hybrid schemes as well:

    The german position:

    https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publicat...

    "The quantum-safe mechanisms recommended in this Technical Guideline are generally not yet trusted to the same extent as the established classical mechanisms, since they have not been as well studied with regard to side-channel resistance and implementation security. To ensure the long-term security of a key agreement, this Technical Guideline therefore recommends the use of a hybrid key agreement mechanism that combines a quantum-safe and a classical mechanism."

    The french position, also quoting the German position:

    https://cyber.gouv.fr/sites/default/files/document/follow_up...

    "As outlined in the previous position paper [1], ANSSI still strongly emphasizes the necessity of hybrid wherever post-quantum mitigation is needed both in the short and medium term. Indeed, even if the post-quantum algorithms have gained a lot of attention, they are still not mature enough to solely ensure the security"

  4. avidiax

    This post was pretty technical. Let's explain a couple of terms:

    ML-KEM -- Module-Lattice-Based Key-Encapsulation Mechanism

    ML-DSA -- Module-Lattice-Based Digital Signature Algorithm

    solo PQ -- Using post-quantum crypto on its own

    ECC+PQ -- Using post-quantum crypto as a layer on top of traditional elliptical curve cryptography (ECC)

    So what's at stake here, is that the PQ crypto is not proven yet, and had recent implementation vulnerabilities (Kyberslash 1 & 2).

    In the NSA's defense, combining cryptosystems also creates attack surfaces, timing problems, additional complexity, etc. Perhaps they know something we don't. They have sometimes acted to strengthen public cryptography, as with the DES S-boxes and differential cryptanalysis. Of course, they also weakened the key-space...

  5. jauntywundrkind

    Is there anything different about this DJB mailing list brigading than the other brigading he's done?

    Four days ago:

    https://news.ycombinator.com/item?id=48760490

  6. JumpCrisscross

    > Secret NSA documents showed that NSA pushed DES in the 1970s to "drive out competitors" while knowing that DES was "weak enough" to break; meanwhile NSA publicly claimed that it would use DES

    Is this true? The NSA pushed for weaker cryptography it could break versus stronger cryptography our adversaries couldn't?

  7. g-b-r

    To those who say that approving or not this RFC won't make any difference:

    «- Liaisons: We received liaison statements from multiple SDOs including O-RAN[2], IEEE 802.11[4] and from 3GPP[3] expressing support for the publication of draft-ietf-tls-mlkem as an RFC as they rely on the IETF to provide a stable normative reference»

    (https://mailarchive.ietf.org/arch/msg/tls/ol2otAvtdDrdz_xY0_...)

  8. anonym29

    Highly recommended reading for effectively understanding the behavior patterns of bad-faith participants in such exchanges: https://www.scribd.com/document/345154863/Guide-to-Forum-Spi...

    If the link goes down, the content is available in many other places across the web under the title "The Gentleman's Guide To Forum Spies (spooks, feds, etc.)"

More from this day

2026-07-07