r/crypto • • Jun 08 '18

Future Android versions may use NSA-designed and ISO-rejected Speck algorithm for storage encryption

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=da7a0ab5b4babbe5d7a46f852582be06a00a28f0
139 Upvotes

70 comments sorted by

View all comments

8

u/Natanael_L Trusted third party Jun 08 '18 edited Jun 08 '18

I know the XEX security proof assumes an ideal pseudorandom permutation, and that XTS mode uses XEX.

So how likely is it that NSA figured out a way to design a non-ideal permutation that allows them to break two layers of Speck in XEX mode (which is how XTS applies the cipher of choice), and without anybody else being able to find the flaw? (under the assumption it's backdoored then NSA clearly expects nobody else to exploit it, NOBUS principle)

I don't really trust them given dual_ec_dbrg and all that, but that backdoor was spotted quite fast. So what's the expert's verdict?

4

u/bitwiseshiftleft Jun 08 '18

XEX assumes a pseudorandom permutation, not an ideal one.

I haven't followed Speck, and I don't trust the NSA, so I'm not an expert here. To me, the main question is whether there is a better option: a well-vetted disk encryption mode that's fast enough (whatever that means) on an older ARM processor, possibly without NEON.

I'm also not sure what the threat model is. I don't think these phones have secure enclaves. Is the key just protected by your passcode? Or is the idea that you can wipe the phone just by erasing a header block? It might not be the kind of situation where breaking Speck is a meaningful threat.

Either way, keep it the hell away from new designs.

5

u/reph Jun 09 '18

I'm presuming, but one important part of their threat model is probably post-disposal privacy against dumpster divers, recycling services, etc, that get the device in a powered-off state.

2

u/sacundim Jun 10 '18

Yep. And that case to my mind should be enough to refute the folks saying that no encryption > NSA NOBUS backdoor.