my comment summarizing the #NSA’s #history of weakening #crypto, including #DES. Quote
on 02026-06-04#ebook of “American Cryptology during the Cold War, 1945-1989”, DOCID: 523696, REF ID: A523696, a declassified internal #NSA #history, including how they weakened #DES, declassified July 26, 02013. #crypto
Quote originally classified TOP SECRET UMBRA, from p.232 (p.240/271):
> (S CCO) The decision to get involved with NBS was hardly unanimous. From the SIGINT standpoint, a competent industry standard could spread into undesirable areas, like Third World government communications, narcotics traffickers, and international terrorism targets. But NSA had only recently discovered the large-scale Soviet pilfering of information from U.S. government and defense industry telephone communications. This argued the opposite case - that, as Frank Rowlett had contended since World War II, in the long run it was more important to secure one’s own communications than to exploit those of the enemy.
> (FOUO) Once that decision had been made, the debate turned to the issue of minimizing the damage. Narrowing the encryption problem to a single, influential algorithm might drive out competitors, and that would reduce the field that NSA had to be concerned about. Could a public encryption standard be made secure enough to protect against everything but a massive brute force attack, but weak enough to still permit an attack of some nature using very sophisticated (and expensive) techniques? NSA worked closely with IBM to strengthen the algorithm against all except brute force attacks and to strengthen substitution tables, called S-boxes. Conversely, NSA tried to convince IBM to reduce the length of the key from 64 to 48 bits. Ultimately, they compromised on a 56-bit key.
on 02026-06-04#crypto #history: Hellman and Merkle showed in 01977 that #DES #crypto could be broken for about US$5000 per key, already, at the time. #PDF #paper
on 02026-06-04#DJB’s outline of the #history of the #NSA’s involvement in weakening #crypto, including their reduction of #DES’s key length. #NIST #DSA #DualEC #SIGINT-enabling-project #NISTPQC #FOIA
on 02026-06-04