Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

NSA tries to weaken mlkem standardisation

The article alleges that the NSA attempted to weaken the standardization process of ML-KEM (a post-quantum cryptography algorithm) by proposing changes that would reduce its security. The author argues these efforts were aimed at making the cryptographic standard easier for the NSA to compromise.

Background

- Daniel J. Bernstein (djb) is a renowned cryptographer and long-time critic of government-influenced crypto standards. He maintains a blog on current events in cryptography. - ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) is the NIST-standardized post-quantum encryption algorithm, derived from the CRYSTALS-KYBER submission. It is central to the US government's effort to replace RSA and ECC before quantum computers break them. - The NSA has a history of intervening in cryptographic standards — most infamously through the Dual_EC_DRBG random-number generator backdoor revealed in 2013. Many cryptographers remain deeply suspicious of any last-minute NSA demands during standardization. - This post argues that the NSA is now pressuring the IETF (Internet Engineering Task Force, the open standards body that governs internet protocols such as TLS) to alter ML-KEM's implementation in ways that would weaken its security or introduce unnecessary complexity, repeating a pattern of "weaken the standard" tactics.