메뉴
HN
Hacker News 22일 전

미국 국가안보국(NSA)과 IETF의 표준화 공정성 논란

IMP
8/10
핵심 요약

이 글은 양자 내성 암호(PQC) 및 하이브리드 암호화 표준을 둘러싼 미국 국가안보국(NSA)과 국제인터넷표준화기구(IETF)의 갈등과 표준화 과정의 문제점을 심도 있게 다루고 있습니다. 저자는 IETF가 NSA의 의도에 편승하여 하이브리드 암호화 도입을 방해하고, 반대 의견을 검열하는 등 공정성을 잃고 있다고 강하게 비판합니다. 보안 실무자들은 이 과정에서 발생할 수 있는 취약점 및 백도어 논란의 맥락을 이해하고 향후 암호학 표준의 신뢰성을 경계할 필요가 있습니다.

번역된 본문

cr.yp.to 블로그 보관 목록:

(Access-I 색인 페이지로 이동)

2026.07.06: NSA와 IETF, 제8부: 공정성. #양자내성암호 #하이브리드 #NSA #IETF #위험관리

2026.07.04: 버그는 발생하기 마련: 단독 양자내성암호(PQ)와 ECC+PQ를 비교하는 쉬운 방법. #양자내성암호 #버그 #취약점 #하이브리드

2026.07.02: 달라도 같은 표준: IETF가 자신들의 행동에 대한 책임을 회피하는 방법. #표준 #이중잣대

2026.06.30: 격자(Lattice) 위험의 이해: 마케팅과 현실 간의 많은 차이점들. #격자 #소프트웨어 #느슨함 #모듈 #점근선 #최악의경우

2026.06.19: EuroQCI 피드백: 유럽의 데이터 보안 투자를 개선하기 위한 간단한 아이디어. #양자키분배 #양자암호 #유럽양자통신인프라 #양자내성암호

2026.04.05: NSA와 IETF, 제7부: 표결 개표. #양자내성암호 #하이브리드 #NSA #IETF #투표

2026.02.21: NSA와 IETF, 제6부: 논쟁의 구조. #양자내성암호 #하이브리드 #NSA #IETF #차트

2026.02.19: NSA와 IETF, 제5부: 끊임없는 전투. #양자내성암호 #하이브리드 #NSA #IETF #최종호소

2025.11.23: NSA와 IETF, 제4부: 검열된 반대 의견의 사례. #양자내성암호 #하이브리드 #NSA #IETF #범위

2025.11.23: NSA와 IETF, 제3부: 현안을 회피하기. #양자내성암호 #하이브리드 #NSA #IETF #회피

2025.11.23: NSA와 IETF, 제2부: 부정부패는 계속된다. #양자내성암호 #하이브리드 #NSA #IETF #부패

2025.10.05: MODPOD: 반대 의견을 보호한다는 IETF의 방어책 붕괴. #IETF #이의제기 #검열 #하이브리드

2025.10.04: NSA와 IETF: 공격자가 단순히 취약해진 암호의 표준화를 돈으로 살 수 있는가? #양자내성암호 #하이브리드 #NSA #IETF #독점금지

2025.09.30: 은밀한 감시: 보이지 않는 것의 중요성. #마케팅 #은밀함 #NSA

2025.04.23: McEliece 표준화: 현재 상황 살펴보기 및 논리 분석. #NIST #ISO #배포 #성능 #보안

2025.01.18: 비행기 항공권만큼이나 비싼: 양자 컴퓨터가 작동하지 않을 것이라는 일부 주장 살펴보기. #양자 #에너지 #변수 #오류 #RSA #비밀

2024.10.28: 90년대의 죄악: 대량 감시에 대한 의문스러운 주장에 대한 의문 제기. #공격자 #정부 #기업 #감시 #암호전쟁

2024.08.03: Clang 대 Clang: 당신은 Clang을 화나게 하고 있다. Clang이 화났을 때의 당신의 마음은 어떨까. #컴파일러 #최적화 #버그 #타이밍 #보안 #코드스캔

2024.06.12: 참고문헌 키: [1], [2], [3]만큼이나 쉽습니다. #참고문헌 #인용 #비브텍(BibTeX) #투표조작 #논문작성

2024.01.02: 이중 암호화: 하이브리드 방식을 반대하는 NSA/GCHQ의 주장 분석. #NSA #정량화 #위험 #복잡성 #비용

2023.11.25: Kyber-512의 보안 분석을 망치는 또 다른 방법: 최근 블로그 게시물에 대한 반박. #NIST #불확실성 #오차범위 #정량화

2023.10.23: Kyber-512의 '게이트(Gate)' 수 줄이기: NIST의 계산과 모순되는, 첫 번째 원리에서 출발한 두 가지 알고리즘 분석. #XOR #팝카운트 #게이트 #메모리 #클러핑

2023.10.03: 올바르게 계산하지 못하는 능력: NIST의 Kyber-512 보안 수준 계산 폭로. #NIST #덧셈 #곱셈 #NTRU #Kyber #실패

2023.06.09: 터보 부스트: 보안 문제를 영속시키는 방법. #오버클러킹 #성능과장 #전력 #타이밍 #헤르츠플리드(Hertzbleed) #위험관리 #환경

2022.08.05: NSA, NIST 그리고 양자 내성 암호: 미국 정부를 상대로 한 두 번째 소송 발표. #NSA #NIST #DES #DSA #DualEC #신호정보지원프로젝트 #NIST_PQC #정보공개법(FOIA)

2022.01.29: 특허 증폭기로서의 표절: 양자 내성 암호의 지연된 출시 이해하기. #양자내성암호 #특허 #NTRU #LPR #딩 #파이커트 #뉴호프

2020.12.06: 잘못된 지표를 위한 최적화, 1부: Microsoft Word: Knauff와 Nejasmic의 "학술 연구 및 개발에 사용되는 문서 작성 시스템의 효율성 비교" 리뷰. #LaTeX #Word #효율성 #지표

2019.10.24: Minerva 공격에 대해 ECDSA보다 EdDSA가 더 잘 버틴 이유: 구현 실패를 성공적으로 예측하고 이로부터 보호하는 암호 시스템 설계자들. #ECDSA #EdDSA #HNP #LWE #블라이헨바허(Bleichenbacher)

원문 보기
원문 보기 (영어)
The cr.yp.to blog Older (Access-J): 2026.07.04: Bugs happen: The easy way to compare solo PQ to ECC+PQ. #pqcrypto #bugs #vulnerabilities #hybrids Table of contents (Access-I for index page) 2026.07.06: NSA and IETF, part 8: Fairness. #pqcrypto #hybrids #nsa #ietf #riskmanagement 2026.07.04: Bugs happen: The easy way to compare solo PQ to ECC+PQ. #pqcrypto #bugs #vulnerabilities #hybrids 2026.07.02: A standard by any other name: How IETF evades responsibility for its actions. #standards #doublespeak 2026.06.30: Understanding lattice risks: Many differences between marketing and reality. #lattices #software #looseness #modules #asymptotics #worstcase 2026.06.19: EuroQCI feedback: A simple idea for improving Europe's investments in data security. #qkd #quantumcrypto #euroqci #pqcrypto 2026.04.05: NSA and IETF, part 7: Counting votes. #pqcrypto #hybrids #nsa #ietf #voting 2026.02.21: NSA and IETF, part 6: The structure of the debate. #pqcrypto #hybrids #nsa #ietf #chart 2026.02.19: NSA and IETF, part 5: One battle after another. #pqcrypto #hybrids #nsa #ietf #lastcall 2025.11.23: NSA and IETF, part 4: An example of censored dissent. #pqcrypto #hybrids #nsa #ietf #scope 2025.11.23: NSA and IETF, part 3: Dodging the issues at hand. #pqcrypto #hybrids #nsa #ietf #dodging 2025.11.23: NSA and IETF, part 2: Corruption continues. #pqcrypto #hybrids #nsa #ietf #corruption 2025.10.05: MODPOD: The collapse of IETF's protections for dissent. #ietf #objections #censorship #hybrids 2025.10.04: NSA and IETF: Can an attacker simply purchase standardization of weakened cryptography? #pqcrypto #hybrids #nsa #ietf #antitrust 2025.09.30: Surreptitious surveillance: On the importance of not being seen. #marketing #stealth #nsa 2025.04.23: McEliece standardization: Looking at what's happening, and analyzing rationales. #nist #iso #deployment #performance #security 2025.01.18: As expensive as a plane flight: Looking at some claims that quantum computers won't work. #quantum #energy #variables #errors #rsa #secrecy 2024.10.28: The sins of the 90s: Questioning a puzzling claim about mass surveillance. #attackers #governments #corporations #surveillance #cryptowars 2024.08.03: Clang vs. Clang: You're making Clang angry. You wouldn't like Clang when it's angry. #compilers #optimization #bugs #timing #security #codescans 2024.06.12: Bibliography keys: It's as easy as [1], [2], [3]. #bibliographies #citations #bibtex #votemanipulation #paperwriting 2024.01.02: Double encryption: Analyzing the NSA/GCHQ arguments against hybrids. #nsa #quantification #risks #complexity #costs 2023.11.25: Another way to botch the security analysis of Kyber-512: Responding to a recent blog post. #nist #uncertainty #errorbars #quantification 2023.10.23: Reducing "gate" counts for Kyber-512: Two algorithm analyses, from first principles, contradicting NIST's calculation. #xor #popcount #gates #memory #clumping 2023.10.03: The inability to count correctly: Debunking NIST's calculation of the Kyber-512 security level. #nist #addition #multiplication #ntru #kyber #fiasco 2023.06.09: Turbo Boost: How to perpetuate security problems. #overclocking #performancehype #power #timing #hertzbleed #riskmanagement #environment 2022.08.05: NSA, NIST, and post-quantum cryptography: Announcing my second lawsuit against the U.S. government. #nsa #nist #des #dsa #dualec #sigintenablingproject #nistpqc #foia 2022.01.29: Plagiarism as a patent amplifier: Understanding the delayed rollout of post-quantum cryptography. #pqcrypto #patents #ntru #lpr #ding #peikert #newhope 2020.12.06: Optimizing for the wrong metric, part 1: Microsoft Word: Review of "An Efficiency Comparison of Document Preparation Systems Used in Academic Research and Development" by Knauff and Nejasmic. #latex #word #efficiency #metrics 2019.10.24: Why EdDSA held up better than ECDSA against Minerva: Cryptosystem designers successfully predicting, and protecting against, implementation failures. #ecdsa #eddsa #hnp #lwe #bleichenbacher #bkw 2019.04.30: An introduction to vectorization: Understanding one of the most important changes in the high-speed-software ecosystem. #vectorization #sse #avx #avx512 #antivectors 2017.11.05: Reconstructing ROCA: A case study of how quickly an attack can be developed from a limited disclosure. #infineon #roca #rsa 2017.10.17: Quantum algorithms to find collisions: Analysis of several algorithms for the collision problem, and for the related multi-target preimage problem. #collision #preimage #pqcrypto 2017.07.23: Fast-key-erasure random-number generators: An effort to clean up several messes simultaneously. #rng #forwardsecrecy #urandom #cascade #hmac #rekeying #proofs 2017.07.19: Benchmarking post-quantum cryptography: News regarding the SUPERCOP benchmarking system, and more recommendations to NIST. #benchmarking #supercop #nist #pqcrypto 2016.10.30: Some challenges in post-quantum standardization: My comments to NIST on the first draft of their call for submissions. #standardization #nist #pqcrypto 2016.06.07: The death of due process: A few notes on technology-fueled normalization of lynch mobs targeting both the accuser and the accused. #ethics #crime #punishment 2016.05.16: Security fraud in Europe's "Quantum Manifesto": How quantum cryptographers are stealing a quarter of a billion Euros from the European Commission. #qkd #quantumcrypto #quantummanifesto 2016.03.15: Thomas Jefferson and Apple versus the FBI: Can the government censor how-to books? What if some of the readers are criminals? What if the books can be understood by a computer? An introduction to freedom of speech for software publishers. #censorship #firstamendment #instructions #software #encryption 2015.11.20: Break a dozen secret keys, get a million more for free: Batch attacks are often much more cost-effective than single-target attacks. #batching #economics #keysizes #aes #ecc #rsa #dh #logjam 2015.03.14: The death of optimizing compilers: Abstract of my tutorial at ETAPS 2015. #etaps #compilers #cpuevolution #hotspots #optimization #domainspecific #returnofthejedi 2015.02.18: Follow-You Printing: How Equitrac's marketing department misrepresents and interferes with your work. #equitrac #followyouprinting #dilbert #officespaceprinter 2014.06.02: The Saber cluster: How we built a cluster capable of computing 3000000000000000000000 multiplications per year for just 50000 EUR. #nvidia #linux #howto 2014.05.17: Some small suggestions for the Intel instruction set: Low-cost changes to CPU architecture would make cryptography much safer and much faster. #constanttimecommitment #vmul53 #vcarry #pipelinedocumentation 2014.04.11: NIST's cryptographic standardization process: The first step towards improvement is to admit previous failures. #standardization #nist #des #dsa #dualec #nsa 2014.03.23: How to design an elliptic-curve signature system: There are many choices of elliptic-curve signature systems. The standard choice, ECDSA, is reasonable if you don't care about simplicity, speed, and security. #signatures #ecc #elgamal #schnorr #ecdsa #eddsa #ed25519 2014.02.13: A subfield-logarithm attack against ideal lattices: Computational algebraic number theory tackles lattice-based cryptography. 2014.02.05: Entropy Attacks! The conventional wisdom says that hash outputs can't be controlled; the conventional wisdom is simply wrong. 2026.07.06: NSA and IETF, part 8: Fairness. #pqcrypto #hybrids #nsa #ietf #riskmanagement Secret NSA documents showed that NSA pushed DES in the 1970s to "drive out competitors" while knowing that DES was "weak enough" to break; meanwhile NSA publicly claimed that it would use DES . NSA used export-law exceptions in the 1990s to entrench RC4 and RSA-512, causing security problems for decades . NSA in the 2000s sabotaged RNG standards and paid companies to deploy those . NSA by the 2010s had a quarter-billion-dollar-a-year budget to "covertly influence and/or overtly leverage" standards and other systems to make them "exploitable"