NSA and IETF, Part 9
libroot
43 points
49 comments
August 15, 2026
Related Discussions
Found 5 related stories in 41.5ms across 4,128 title embeddings via pgvector HNSW
- RFC 8890 – The Internet is for End Users (2020) notarobot123 · 121 pts · July 30, 2026 · 55% similar
- Hooray for the Sockets Interface jruohonen · 19 pts · July 29, 2026 · 45% similar
- 21,000 MCP servers exposed: the protocol reaches a security inflection point Wpnx330 · 11 pts · August 16, 2026 · 44% similar
- An update on residential proxies and the scraper situation chmaynard · 146 pts · July 10, 2026 · 44% similar
- Show HN: We Implemented the IPv8 Internet-Draft in Linux, Libc, and BGP turborigby · 69 pts · August 14, 2026 · 43% similar
Discussion Highlights (6 comments)
jauntywundrkind
> I'm happy to report that 82 people spoke up on the TLS mailing list in unambiguous opposition to this spec during the voting period How many of them spoke before on this mailing list, in any capacity what so ever? I suspect this is 99% people who showed up because you organized a brigadging, because you incited people and told them to show up and be completely outraged. There's a >0% chance that DJB could be correct that there is some risk to this spec (which notably is not seeking recommendation status ! So WTF ?) The people approving and wanting this aren't fools, aren't lackies, aren't some great foe. There's little real opposition? Making up ghosts and enemies lurking in every corner, brigading people to show up in IETF meetings, who have never participated before, just to spread heat and anger you've programmed them for, is ignoble & indecent. All too recently: https://news.ycombinator.com/item?id=48760490 https://news.ycombinator.com/item?id=48811887
stackghost
It's never been clear to me why NSA's "blue team" directorates haven't been spun off into a separate agency. Sure, NSA strengthened the S-boxes in DES and SHA-1 but from the outside there's no way to know whether they're making DES stronger against differential cryptanalysis or whether they're introducing a DUAL_EC-style vulnerability. I'm sure there's a game-theoretic optimum choice when it comes to accepting proposals from the NSA vs rejecting them out of hand, but I'm not sure what that optimal choice is.
philodeon
I enjoyed the @tptacek cameo. I suspect tptacek didn’t.
ifh-hn
Can someone ELI5 what the issue is here? I feel like I'm missing a lot of nuance here. Are the NSA people attempting to weaken TLS by removing ECC?
alfiedotwtf
I thought this was going to be rehashing of the old NULL-cypher IPsec thread, but it’s a different thing. Maybe we should treat standards like we do a free market - let anyone implement what they choose then let people chose which to adopt, but the main thing is get government out of the entire process. If the government wants to standardise, that’s fine… just don’t make it an industry standard adopted by civilians. Let them have their weakened protocols will the market moves on
timschmidt
Brings to mind this lovely quote from the Snowden documents: “The road to developing this standard was smooth once the journey began... However, beginning the journey was a challenge in finesse ... After some behind-the-scenes finessing with the head of the Canadian national delegation and with C.S.E., the stage was set for N.S.A. to submit a rewrite of the draft ... Eventually, N.S.A. became the sole editor.” https://macleans.ca/society/technology/nsa-says-it-finessed-...