[saag] Re: Attacking standardization

Nico Williams <[email protected]> Fri, 21 Nov 2025 23:39:58 -0600
Newsgroups gmane.ietf.saag
Message-ID <aSFMrr1CBAdepabH@ubby>
On Sat, Nov 22, 2025 at 04:33:33AM -0000, D. J. Bernstein wrote:
> Nico Williams writes:
> > I think DJB thought that by not
> > adopting it the work wouldn't get done.
> 
> See https://blog.cr.yp.to/20251004-weakened.html: "Surveillance agency
> NSA and its partner GCHQ are trying to have standards-development
> organizations endorse weakening ECC+PQ down to just PQ."
> 
> See also https://blog.cr.yp.to/20251004-weakened.html#options for why
> the endorsement matters from the attacker's perspective. The issue here
> is not the easy work of writing a spec; the issue is whether NSA can pay
> SDOs to _endorse_ the spec.

I've read those, and I'm quite aware, and I agree that it's more than
likely what is happening.  It's unfortunate that many customers don't
understand that "RFC" doesn't mean "Standard", and so on.  But the
reality is that the TLAs only really need the codepoints (which they can
camp on) and they can use their regulatory power to get what they want.
What we can do is have MTI alternatives and hope customers demand them.
And we can publish BCPs telling customers how to configure their devices
and software for robust security.  And we should definitely do those
things.

As to IETF processes, they're set up so that it's easy for an
adversarial TLA to mount this attack.  The issue here wasn't the TLS WG
chair -- it's deeper.  Addressing that is very difficult, and many won't
even think it is a problem.

Nico
-- 

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]