3 ms·
I think the argument is something like: you could understand what invalid curve point attacks are, and once you did, you could look for them everywhere, and if
by munin 8y ago
I think the argument is something like: you could understand what invalid curve point attacks are, and once you did, you could look for them everywhere, and if you did that, you would have found this error as well.
The math behind invalid curve point attacks is pretty straightforward, it's some polynomials and points on the Cartesian plane. You saw this stuff in elementary school.
Then, someone needs to point out to you "oh check out what happens if you allow for invalid points" and now you have a pattern to go hunting for. Then it's luck - do you get to Bluetooth before someone else, or do you find something else, or do you just re-discover other peoples stuff?
Maybe it's elitist to say "the math is pretty straightforward" but you know what, it's a system of two variables and you can plot it. You need to know about division, multiplication, and modular variants. No monads, no tensors, no mixed Gaussians or method of moments or greek letters or 128 dimensional spheroids.
Maybe that kind of math makes your eyes glaze over but I am pretty confident that if you cleared your mind and sat down with pencil and paper and gave it an hours honest effort, you would come away with an understanding.
- tptacek 8y agoYou definitely didn't do the math for invalid curve attacks in grade school, since you also need CRT and the notion of group order. But I think your first sentence gives a great charitable interpretation of the title. A way I like to think about these things --- from the perspective of a vulnerability researcher, not a cryptographer or mathematician (I am neither of those) --- is that there is a very little bit of math you need to put some extra tools in your belt, and then the rest of it is programming; working through these kinds of exploits feels a lot like implementing heapsort or a spanning tree reduction for the first time feels like. I find that empowering, because while I can't bang out Kruskal's algorithm off the top of my head, I know if I sit down with it for 20-30 minutes I'll get it working. After a little bit of reading (an hour or two tops), same with this attack.
- barbecue_sauce 8y agoWhere did you go to elementary school?