5 ms·
I just learned about Milagro through this submission and only looked at a fraction of the docs but as someone who is not a cryptographer but put some effort int
by moby_click 10y ago
I just learned about Milagro through this submission and only looked at a fraction of the docs but as someone who is not a cryptographer but put some effort into understanding pairing based cryptograph, I find the documentation excellent so far.
> No, No you can't. A 4 digit pin is 14 bit security. Any system is only as secure as its weakest link.
As far as I understand it, the PIN is used to secure a secret key for a 128bit security cryptosystem against key compromise. Like password protection on ssh keys, this provides stronger security than unprotected keys but I think this PIN is actually part of an interactive proof to protect against offline attacks.
The downside of Identity Based Encryption is that you need a master secret key (aside: I think we shoud find a less loaded term like root secret key) to derive the client secrets. The DTA is a way to avoid a single authority in posession of this root secret through secret sharing. Sharing in secret sharing is not copying but splitting into shares. I'm not yet sure if it works like I think it works but I think they use secure multiparty computation to use a shared root secret to derive shares of the client secrets that the clients combine to obtain their secret. That would be really awesome and about the best we can do before more powerful cryptography (functional encryption, fully homomorphic encryption etc.) becomes practical.
- mSparks 10y agoExactly. its a password limited to 4 digits. And why? That gives you no more than 14 bit security even using a decent system like PBKDF2. Which i see no mention of. secrets are just that - secret. The only reason I know of that secrets need sharing is when you are running a key escrow system. Other than that secrets are locked away and used as rarely as possible. Never ever ever transmitted from machine to machine. Thats the key problem in crypto (pun intended). Stuff you transmit cant and wont stay secret.
- moby_click 10y agoHaving read a little further, I think offline attacks are possible and 4 digits alone are useless today but that still does not weaken the security level. You need a key, whether you choose to use a password or not. Correct me if I'm wrong but I don't see secret keys transmitted. The DTAs issue shares of the secret keys that are then combined. Also, transmitting secrets really is a motivating use case for cryptography.
- mSparks 10y agothey are creating a secret key by sending chunks of secret keys (with a mention of a blockchain database - not sure why). Or at least thats what i saw in the code comments. secret in cryptography has a very special meaning - it refers to the part of the communication process you dont want visible. encryption is actually mostly a solved problem. There are several good algorithms which are fine with no real problems. The problems are all in establishing keys. For that there are currently only two choices in use. ecdh. which all the standard curves appear to be backdoored. and rsa, which the russians reckon they have broken. the dta is just another key sharing scheme. needed. but not one that gives up on all the comsec we have gained so far. do you not find it dishonest that they claim for example, that the uk government is using it already, but then it turns put it doesn't actually exist beyond a few lines of poc code.
- chetanahuja 10y ago"ecdh. which all the standard curves appear to be backdoored" This is a pretty serious assertion to make as a throwaway comment. You're talking about the NIST sponsored constants suspected of being backdoored. ( https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG https://safecurves.cr.yp.to/ https://safecurves.cr.yp.to/ ) That's the reason Curve22519 (defined by djb, completely independent of any NIST involvement) has become popular and is being widely used as default in major ECDH implementations (https://en.wikipedia.org/wiki/Curve25519 https://en.wikipedia.org/wiki/Curve25519 ). As close to a "standard" as you'd find today that nobody believes to have known weaknesses or backdoors.
- mSparks 10y agoim mobile and traveling. tried to find my links to research but not in my mobile bookmarks. there is a great page somewhere that lists each curve --- edit you found it: https://safecurves.cr.yp.to https://safecurves.cr.yp.to for reference google (pdfs so cant get links from google mobile): security dangers of nist curves and also the reasoning behind the curve chosen for bitcoin. so edit 2: just, yes. but note the safecurves quote " The core problem is that if you implement the standard curves, chances are you're doing it wrong:"