4 ms·
You're falling victim to the same misconception. It is not a contradiction to say both that a cryptographic scheme is provably secure and that its security reli
by swordswinger12 11y ago
You're falling victim to the same misconception. It is not a contradiction to say both that a cryptographic scheme is provably secure and that its security relies on a conjecture about the hardness of a computational problem.
- statictype 11y agoIf the conjecture turns out to be false, is the scheme still secure? If so - interesting, how does that work? If not - then doesn't that mean it's not probably secure?
- swordswinger12 11y agoEhhhh.... well, it's complicated. For most cryptosystems, the answer is no, because if you can solve the underlying problem efficiently you can break the security of the scheme as defined. It turns out that this isn't always a 'break' in the sense that most people understand it. For example, a 'break' might just mean the ciphertext is no longer indistinguishable from random noise, but it might be possible to prove meaningful security in a weakened model that doesn't require ciphertexts to look like random noise but, for example, requires that no bits of the plaintext are leaked with high probability. Cryptographers build schemes with very strong, conservative security guarantees for this exact reason.