Comment by tptacek

3 years ago

The FOIA issue is 100% legitimate. NIST is required to comply with FOIA.

You don’t get it clearly. They’re playing dirty. At best the FOIA will receive a document made on the fly with nothing of value. The rules don’t apply to the NSA. You can do exactly nothing. But NIST, you can do something about - reject any standard they approve. It’s your choice what algorithm you use, and we know NIST will select a broken algorithm for the NSA, so just ignore their ‘standard’. The best solution is using layers of crypto, trusting no single algorithm.