This is just about the most boring point you can raise about a NIST competition. It's right there on the label: "NIST". We get it. People don't like NIST, because of BULLRUN.
The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will trust this contest for similar reasons. If you could get this cast of cryptographers not to submit to NIST contests, and instead submit to some other contest, we'd have something productive to talk about. But you can't, and so, when we talk about contest-based cryptography standards, you're going to end up back at NIST.
I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.
Meanwhile: pull up the authorship team on CRYSTALS-KYBER. Approximately 0% of credible cryptographers believe that NIST was somehow able to exert improper influence over this design.
> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.
Sorry if you think I'm trying to convince people of anything. I'm simply asking for alternatives to NIST itself, for my own personal and selfish reasons. I'm not arguing against other people trusting NIST, their competitions or anything like that. Just asking a question regarding alternatives.
I'm glad you and others answered. Someone even gave a proper alternative based in Germany, and for that I'm very happy. I'm sorry you feel like people are "relitigating the same points over and over again", I cannot steer the conversation any more than you can and I personally haven't seen any conversations on HN about alternatives to NIST, then obviously I wouldn't ask for it, if I already knew the answer.
You said "NIST worked together with NSA to allow/insert backdoors into cryptography". It's been pointed out a couple times now that neither NIST nor NSA designed these schemes; they were submitted by the highest-profile academic cryptography research teams in the world. You aren't being asked to trust NIST in any meaningful way.
The closest analog to NIST I can think of is ECRYPT and the eSTREAM contest. It produced interesting work and you could follow it in much the same way people followed these last two NIST competitions. But for PQ KEMs, it's likely that NIST's will be the "competition of record".
> You aren't being asked to trust NIST in any meaningful way
I understand that neither NIST nor NSA have designed these schemes, but isn't NIST the organization who picked these winning schemes after all? That's the impression I got, and my history of trusting what NIST picks, isn't the greatest, so I'd like to avoid that. I also understand that countless of people have reviewed the schemes as well, people from all around the world with different types of experience. It's still hard to shake off something that essentially boils down to a feeling: "trust".
Thank you for providing some alternatives in your final paragraph, for the uneducated plebs like myself.
About the worst thing you could say about the NIST competitions is that if NSA knows some horrible flaw in CRYSTAL-KYBER, they're not going to tell us about it. But that's true of any other contest anybody else runs, too.
Why would that be true in any alternate versions of these contests? I understand the enormous incentive mechanisms involved, and yet I cannot see this being obviously true.
Edit to add: if the authorship of the submitters is as above reproach as we are led to assume, why can that not be the case for the NIST decision panel itself?
It’s think it’s also an example of why NIST is so important. The subversion of the standard is a problem, but the real exploit using that subversion was the laziness and lack of skill that downstream practitioners demonstrated. People clicked next and installed that RSA BSAFE package without any configuration or reading of the manual.
Without NIST, you’d have Crypto AG — much worse. With NIST, you may have trust concerns, but ultimately the US government is protecting much of its own data as well as politically/economically critical data with NIST algorithms (aka FIPS 140-2).
Ultimately, I think the model in place with these competitions is probably the “best worst” option.
That first sentence is not a good way to sum up what happened. Dual EC isn't "weak"; it's pretty plainly a backdoor.
(I'm among an elite cadre† of cryptography-adjacents who felt it probably wasn't, but only because I thought it was too stupid to actually be used anywhere --- as soon as it was disclosed that (a) it was a default-yes algorithm in BSAFE and (b) big companies actually used BSAFE in important products, it was immediately clear what was going on).
The idea of Dual EC is essentially that your output is internal RNG state encrypted with a public key, leaving open the obvious question of "who has the private key?". I think we all know the answer to that now.
While I largely agree with you, and respect your opinion on these matters, the truth is that Dual EC was indeed a standard of the NIST, and therefore as a practical matter did get deployed by the public in whatever ill-informed manner for not having your elite cadre advice (yes, joking).
I appreciate the point about trust in the authorship of those presenting these algorithms, and I personally do accept it, but there's a lack of trust broadly (in the very community that these standards are intended for) in the process that your comments don't account for in this instance.
Nitpick: strictly speaking, it wasn't plainly a backdoor specifically, but plainly either a backdoor, or something deliberately designed to look backdoored, but with some unknown way for the NSA to 'reluctantly' declassify a proof that it wasn't backdoored in a attempt to discredit people who accused it of being backdoored (basically trying to recreate the DES S-box versus differential cryptanalysis thing). But smart money was on actually-a-backdoor.
> I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back.
In advance of what ? Not intended as a gotcha I'm genuinely interested.
I see past NIST competitions as a mixed bag in terms of whether what we got is important (e.g. AES) or not so much (e.g. SHA-3) but I don't see any cases where they made things worse. And the NIST competitions attract some attention whereas something more discrete like the CFRG PAKE selection process can be so quiet if you're not intimately involved you might not know the CFRG actually selected anything. If you build a new product with Serpent or Twofish inside it, that will attract questions about why not AES - does this happen if your product has SPAKE2?
It's not so much that NIST has chosen bad ciphers in their competitions, so much as that they've created institutional pressure against other totally reasonable constructions, which in turn make it harder for things like WireGuard to get adopted inside the USG. The ciphers are much less important than the protocols that use them.
The problem this argument has is that NIST competitions are legitimated by their participants. People trust NIST's hash competition because of who entered, and because the winning team has an unimpeachable record. For the most part, people will trust this contest for similar reasons. If you could get this cast of cryptographers not to submit to NIST contests, and instead submit to some other contest, we'd have something productive to talk about. But you can't, and so, when we talk about contest-based cryptography standards, you're going to end up back at NIST.
I don't like NIST for another, better reason: I think the whole enterprise of picking cryptography standards in advance is bankrupt, and holds the industry back. So I'm not a NIST fan either. But I don't see what's to be gained by derailing conversations about new cryptography so we can relitigate the same points over and over again.
Meanwhile: pull up the authorship team on CRYSTALS-KYBER. Approximately 0% of credible cryptographers believe that NIST was somehow able to exert improper influence over this design.