4 ms·
Has anyone tried to use this to create a distributed cloud? If storage and certain types of computation could be encrypted, anyone could sell their spare comput
by CephalopodMD 8y ago
Has anyone tried to use this to create a distributed cloud? If storage and certain types of computation could be encrypted, anyone could sell their spare computation power without trust issues.
- UncleMeat 8y agoSomewhat Homomorphic Encryption unfortunately only works for a pretty limited set of workloads and FHE is still mind bogglingly slow so a general purpose cloud for arbitrary computation isn't going to be a thing any time soon.
- CiPHPerCoder 8y agoAlso, by itself, homomorphic encryption doesn't protect against chosen-ciphertext attacks, which makes it very unattractive for 99.9% of real world crypto use-cases. https://tonyarcieri.com/all-the-crypto-code-youve-ever-written-is-probably-broken https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt... In my experience, a lot of teams also reach for FHE to solve problems that are easily and securely solved without it (i.e. searchable encryption): https://github.com/paragonie/ciphersweet https://github.com/paragonie/ciphersweet That being said, there is the 0.01% problem space where FHE makes perfect sense (mostly in the realm of encrypted databases and machine learning). For those systems, if the database can ever be considered adversarial (your threat model may rule this out, most applications' do not), a simple construction involving HMAC, a secure digital signature algorithm, and an append-only ledger can protect the application that reads from the database against chosen-ciphertext attacks. https://paragonie.com/blog/2017/12/assuring-ciphertext-integrity-for-homomorphic-cryptosystems https://paragonie.com/blog/2017/12/assuring-ciphertext-integ...
- Ar-Curunir 8y agoWhy does lack of CCA security make FHE unattractive? The entire point of FHE is to allow malleability of ciphertexts.
- CiPHPerCoder 8y agoCCAs have historically been useful for defeating the confidentiality guarantees of cryptography protocols. BB'98, Vaudenay '02, the iMessage attack, etc. Selling "encryption, but not IND-CCA3" to a lot of (clueful, at least) companies is almost impossible. If you read the linked article, it discusses a way to hack it in.
- deleted 8y ago[deleted]