3 ms·
nsa shill:everyone should use curve25519 hacker news:downvote to hell anyone who disagrees that off my chest. "protocol level" is the order of the bits. for e
by mSparks 10y ago
nsa shill:everyone should use curve25519
hacker news:downvote to hell anyone who disagrees
that off my chest.
"protocol level" is the order of the bits. for example the octets in the tcp protocol.
"rearranging the payload" in this case is moving around those octets. and while of course it would work, is a bit simplistic. (so yeah, yek not far off)
the "Best" solution imho is to chain more than one cipher together. "like truecrypt does". for example, if you are using a pre shared key, use that key to encrypt the dhe with a symmetric cipher and a nonce. or some other non trivial obfuscation.
but the point is valid, even simple obfuscation requires human intervention, which breaks mass surveillance en mass.
- loup-vaillant 10y agoSomething is nagging me for quite some time. DJB invented curve25519, which is advertised to offer 128 bits security. On the other hand, DJB also said 128 bits are not enough for symmetric crypto. https://cr.yp.to/snuffle/bruteforce-20050425.pdf https://cr.yp.to/snuffle/bruteforce-20050425.pdf This makes me a bit uneasy: would a parallel brute force search would be much more difficult for elliptic curves than it would for symmetric cyphers? Why? By the way, a similar problem arises with poly1305. I'm missing something.
- mSparks 10y agoI think what you are missing is the huge investment the "bad guys" have put into getting people to believe insecure communications are in fact secure.
- dtech 10y agoAfaik breaking a 128-bit ECC key does not require brute-forcing 2^128 keys but rather computing 1 difficult problem on a 128-bit input. Breaking e.g. AES key of n bits requires you to try 2^n combinations, but the actual computation per key is very fast. [1] https://crypto.stackexchange.com/questions/13249/why-can-ecc-key-sizes-be-smaller-than-rsa-keys-for-similar-security https://crypto.stackexchange.com/questions/13249/why-can-ecc...
- cesarb 10y agoWell, curve25519 uses 256-bit keys (actually, a few bits less than 256). The parallel brute force search should take time similar to that of a 256-bit symmetric cipher. The reason curve25519 has a security level of only 128 bits is that ECDLP takes time proportional to the square root, so half the number of bits (https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#Key_sizes https://en.wikipedia.org/wiki/Elliptic_curve_cryptography#Ke...). As for poly1305, it actually uses not one, but two separate 128-bit keys. The authentication tag computed using the first key is encrypted with the second key. For a brute force search, it should be as hard as breaking something with a single key of around 256 bits.
- Natanael_L 10y agoA batch attack on 128 bit symmetric lowers the total cost to below 2^128 computations to successfully decrypt messages. The cost approximately follows the birthday paradox math, and thus becomes cheaper at a slightly faster than linear rate given a higher volume of ciphertexts. A batch attack on asymmetric ECDSA like curve25519 costs MORE than 2^128, it just grows logarithmicly instead of linearly. That's why.
- CurtMonash 10y agoNobody is secure against their home country government, which has the power to both: -- Mount black bag attacks on your premises. -- Snoop the networks of internet service providers. On the other hand, most or all of the following are true of my keys-to-the-kingdom email account (the one from which most other passwords can be reset): -- It is very unlikely to be hacked by any information guesses of my password, social engineering of my "secret question" information, shenanigans with my mobile phone, etc. -- It is with a provider who seems less likely to get hacked than even Yahoo. -- It has security that would be hard to brute force. -- It has a unique password that I don't use on other, more vulnerable accounts. Even so, I assume that all my communications are available to the US government, at least by after-the-fact subpoena if not actually real time.
- mSparks 10y ago->Nobody is secure against their home country government, which has the power to both: -- Mount black bag attacks on your premises. -- Snoop the networks of internet service providers. Indeed, not even our governments are safe from the government. like when they forced backdoors in juniper routers, then used juniper routers in government facilities. resulting in widespread compromise of most if not all government facilities and the loss of billions of dollars r&d advantage. At least they put tons of effort into securing the voting system and didnt let a russian stooge get declared leader of the free world tho. so there is still some hope. for us tho. encrypted at rest, and intrusion detection generally good practice.