Re: Any truth to rumor that NSA had Public Key Crypto first?

From: Bernie Cosell (bernie_at_fantasyfarm.com)
Date: 09/29/04


Date: Wed, 29 Sep 2004 10:52:30 -0400

unruh@string.physics.ubc.ca (Bill Unruh) wrote:

} No, that is not what he says. He says that NIST asked for a public
} encryption standard. NSA probably did not want to give them a private one
} precisely because they did not want to reveal their state. They weakened
} DES by making the key short, and strengthened it with the Sbox design.
} Basically this meant only they had a chance of breaking it. (good Sbox so
} only exhaustive search works, short key so that they but not others could
} actually carry out exhaustive search.)

Perhaps I'm not understanding, quite, but I thought that shortening the key
*did*not* weaken DES. Giving DES a much longer key than they actually did
would have been *false*security*, since there are brute-force techniques
[that I assume NSA knew even if we civilians didn't at the time] for
cracking it that ran only at what, 2^52 or the like..

I guess what I'm saying is that if there are two paths of attack on a
ciphersystem and one is of a particular difficulty it adds NO security to
the ciphersystem to make the _other_ one extremely strong. If your back
door is a screen door, it doesn't make any difference how many locks you
put on the front door...

  /Bernie\

-- 
Bernie Cosell                     Fantasy Farm Fibers
bernie@fantasyfarm.com            Pearisburg, VA
    -->  Too many people, too few sheep  <--          


Relevant Pages

  • Re: Wikipedia "Cryptography" reaches Featured Article status
    ... NSA has characterized DES as one of their biggest ... If NSA had always before used to force their algorithms into silicon ... chips with special "coating", that would clearly tell that NSA did not ...
    (sci.crypt)
  • Re: Wikipedia "Cryptography" reaches Featured Article status
    ... a mistake. ... The introduction of DES is considered to have been a catalyst for the ... NSA has characterized DES as one of their biggest ... Certainly the unkeyed Initial Permutation and Final Permutation make no sense for security or for software, but IIRC, it allows hardware registers to be filled in parallel (or something. ...
    (sci.crypt)
  • Re: Wikipedia "Cryptography" reaches Featured Article status
    ... So DES was a mistake because it was followed by research? ... Or because the NSA was not able to predict the future very well? ... NBS standardization process and the algorithm ended up being ...
    (sci.crypt)
  • Re: Wikipedia "Cryptography" reaches Featured Article status
    ... the explosion of academic research into crypto that followed the DES ... publication, as described in both the quote itself and in the NIST ... Or because the NSA was not able to predict the future very well? ... of DES lead to an explosion of published public sector crypto research. ...
    (sci.crypt)
  • Re: Wikipedia "Cryptography" reaches Featured Article status
    ... The controversy over DES eventually subsided, but in late 1985 NSA ... then isn't it a consequence of the reduced key ... of its major elements except the criteria for S-box design have been ...
    (sci.crypt)