4 ms·
No, I'm sorry, that's not how cryptography works. A 'skim' clarifies nothing - you need precise proofs to understand security. And yes, I'm aware they provide p
by swordswinger12 10y ago
No, I'm sorry, that's not how cryptography works. A 'skim' clarifies nothing - you need precise proofs to understand security. And yes, I'm aware they provide proofs in the extended report, but the adversarial model seems not to model a real attacker particularly well. Here's a concrete question affecting real-world security that is seemingly unaddressed: what does their scheme leak about the frequency of rule matches? Can an adversarial middlebox see that some rules are matched more frequently than others? Are there rule sets for which this frequency information allows the adversary to guess plaintexts?
- mindslight 10y ago"as much as needed" being my key phrase. The parties interested in the "benefits" of such a scheme are attackers (governments and ISPs). A scheme touting designed-in attacks just isn't that interesting otherwise. The old field of electronic payments is littered with papers detailing "secure" systems, but who's only novel contribution was a way of defeating security. They all went nowhere because to any organization that had the power to force adoption of such a scheme, preventing any encryption still offered the best value proposition.