OSTVIK TRUST SERVICES PLATFORM ROOT PQ1 · TRANSITION STATUS Updated hourly · Monday · 12:00 p.m. ET
Transition packages available: All participating manufacturers
In-scope artifacts re-signed under PQ1: 2,338,000 of 2,400,000 (97.4%)
Signatures recorded in the PQ1 Transparency Log: 2,338,000
R2 distrust for PQ1-enabled devices: Day 10 · Wednesday · 6:00 a.m. ET
Signing is proceeding ahead of schedule. Every signature issued under PQ1 is available in the PQ1 Transparency Log.
nib › Issues › #4471 · Has anyone actually checked the math on this or are we all just trusting it Opened Sunday 14:12 UTC by kmuller-dev · 👍 611
kmuller-dev · Sunday 14:12 UTC Forty-one companies are going to sign everything with one library this week. I’m not saying anything is wrong. I am asking if anyone outside the maintainers has actually looked at the FN-DSA code in 4.2.1 recently. Not the paper, the code.
r0ckh0pper · Sunday 19:40 UTC +1
ipmhsu · Monday 03:15 UTC It has been through two audits, both are linked in the README. Nobody is going to re-audit it in a weekend. If you’ve found something, report it to security@ and not in an issue with 600 thumbs on it.
bvanleer · Monday 14:48 UTC Engineer at Corvane, we ship nib inside our HSMs. We have about 40,000 customer images to sign before Wednesday. Can a maintainer just confirm that 4.2.1 is the version we should keep signing with? Yes or no is fine. We have people asking.
the_last_prophet · Monday 15:30 UTC The key is the beast and the beast has ten horns. Ten days. Read Revelation 13.
bvanleer · Monday 16:05 UTC Anyone?
hlund · Monday 16:22 UTC Locking this. Security reports go to security@nib-project.org, as the README says. Please do not open new issues about 4.2.1 here. We read everything that comes to that address.
hlund locked this conversation · limited to collaborators
OSTVIK TRUST SERVICES PLATFORM ROOT PQ1 · TRANSITION STATUS Updated hourly · Monday · 1:00 p.m. ET
In-scope re-signing COMPLETE at 12:48 p.m. ET, four days ahead of schedule.
In-scope artifacts re-signed under PQ1: 2,400,000 of 2,400,000 (100%)
Signatures recorded in the PQ1 Transparency Log: 2,415,000
R2 distrust for PQ1-enabled devices: Day 10 · Wednesday · 6:00 a.m. ET
Signing under PQ1 continues for new and updated releases. Ostvik thanks the 41 participating organizations, and the engineers who worked through the weekend.
CROSSWIRE.NET › /openresearch/ › PQ1 — what if the new key is worse than the old one? 82 replies
#1 tallgrass1974 · 16:58 UTC everybody is cheering because the old lock is broken and they put a new lock on everything. who made the new lock. same 41 companies, same “government partners.” nobody asks if the new one has a door built in. the old one didnt need a door because they could just break it. the new one they cant break so they would NEED a door. think about it
#4 glassdark · 17:10 UTC The new one is a published standard. It’s in a FIPS document anyone can read. There’s no door.
#6 tallgrass1974 · 17:14 UTC ok so who typed it in
#14 dryfly_co · 18:20 UTC Okay, I did what tallgrass said, which I don’t usually do. Everybody signs with one library, nib, version 4.2.1. It’s open source. There’s an AUTHORS file that says who wrote each part.
#15 dryfly_co · 18:22 UTC From the AUTHORS file:
sampler: kolobok
Everything else in there has a real name.
#16 dryfly_co · 18:31 UTC The account named kolobok has no other projects, no email, no photo. It opened one pull request, years ago, and it was merged by hlund with a comment “Thanks, nice work.” hlund is still a maintainer. hlund is also the one who locked the issue asking if anybody checked the math, about two hours ago.
#17 tallgrass1974 · 18:33 UTC kolobok is a RUSSIAN fairy tale. there it is. wake up
#18 glassdark · 18:40 UTC It’s Ukrainian too. It’s a bread. My grandmother read it to me. Half of Eastern Europe has a kolobok.
#19 quark_soup · 18:52 UTC genuine question, what is a sampler and why would it matter who wrote it
#21 glassdark · 19:05 UTC To make a signature the scheme adds some randomness, so that the signatures don’t say anything about the key. The sampler is the part that makes the randomness. If it were wrong, every signature would give away a little bit of the key, and somebody with enough of them could work out the key.
#22 quark_soup · 19:06 UTC so is it wrong
#23 glassdark · 19:14 UTC No. Verification checks that every signature is short enough. If the randomness were off they’d fail. 2.4 million of them verified this weekend. That’s about as tested as code gets.
#24 dryfly_co · 19:20 UTC Then why lock the issue.
#25 glassdark · 19:22 UTC Because it had 600 thumbs and a guy quoting Revelation. They lock everything. I’d lock it.
#27 bvanleer · 19:48 UTC I’m the Corvane engineer in that issue. Nobody answered before they locked it, and I can’t wait on an inbox. We’re signing our 40,000 images on 4.2.1 tonight because that’s what everybody else signed with. After Wednesday at 6 a.m. anything that took the new root won’t take an update signed with the old one, so if something is wrong with 4.2.1 there’s nothing to fall back to. I would just like somebody to tell me there isn’t.
#31 pixelforensics · 20:47 UTC I pulled the transparency log. It’s huge. I’m going to run the signatures and see if anything looks generated.
#32 glassdark · 20:49 UTC They are all generated. That’s what a signature is.
#40 dryfly_co · 23:16 UTC I emailed security@nib-project.org and asked who kolobok is. Got an auto-reply that they’re receiving a high volume of messages.
#47 glassdark · 01:30 UTC Look, dryfly, you’re not crazy. If I’d found that AUTHORS line I’d be writing about it too. But the signatures verify. I’m going to bed.
#52 quietroom · 02:41 UTC Which pull request. Do you have the number.
OSTVIK TRUST SERVICES PLATFORM ROOT PQ1 · TRANSITION STATUS Updated hourly · Monday · 11:00 p.m. ET
In-scope artifacts re-signed under PQ1: 2,400,000 of 2,400,000 (100%)
Signatures recorded in the PQ1 Transparency Log: 2,431,000
R2 distrust for PQ1-enabled devices: Day 10 · Wednesday · 6:00 a.m. ET
Signing under PQ1 continues for new and updated releases.
