5 ms·
Nice list! One I’d add: one of my all-time favorite cryptography-related quotes is from Bruce Schneier‘s Applied Cryptography, talking about key length: > Thes
by seleniumBubbles 7y ago
Nice list! One I’d add: one of my all-time favorite cryptography-related quotes is from Bruce Schneier‘s Applied Cryptography, talking about key length:
> These numbers have nothing to do with the technology of the devices; they are the maximums that thermodynamics will allow. And they strongly imply that brute-force attacks against 256-bit keys will be infeasible until computers are built from something other than matter and occupy something other than space.
Full context: https://www.schneier.com/blog/archives/2009/09/the_doghouse_cr.html https://www.schneier.com/blog/archives/2009/09/the_doghouse_...
- tzs 7y agoThat argument only applies to irreversible computation. The errata for Applied Cryptography corrects this: > The section on "Thermodynamic Limitations" is not quite correct. It requires kT energy to set or clear a single bit because these are irreversible operations. However, complementing a bit is reversible and hence has no minimum required energy. It turns out that it is theoretically possible to do any computation in a reversible manner except for copying out the answer. At this theoretical level, energy requirements for exhaustive cryptanalysis are therefore linear in the key length, not exponential.
- the_Truth_ 7y agoReally, you get less bang for your buck than that, for the simple reason that cryptanalysis isn't about brute forcing at all. If you take some cypher text, and it is surely known to be a non-random value, for example, because you can tie the timing of a given point-to-point message to real world activities, say... insider trading. Well, fundamentally, we then know that the value of the text must be structured data, and not random, but human readable. That means you can work backwards from the space of structured data, instead of the full scope of random strings, in order to break the keys. Encryption is not as strong as it's purported to be, even without back doors, or less than random weaknesses built into the numerical roots of the scheme. To understand what I'm driving at, consider the challeng of an encrypted string consisting of 4 characters: $&@% If we know it's a word, then that limits the attack space to English words. So, let's say we have another length of text surely containing words, and encrypted with the same key. Well, now we only need to look at the keys that transform the first string into valid words, and then the intersection of keys that produce words for both strings, after that, it's down to context and deniability. And with that, your brute force space is much smaller, much more manageable. ...or at least, smaller than the premise of thermodynamic laws requiring the utilization of a dyson sphere to break a cypher text.