5 ms·
Pseudorandom parameter selection of NIST P-curves, including secp256r1 has created much controversy within the cypherpunk community in the early 2000s. the theo
by bcaa7f3a8bbc 7y ago
Pseudorandom parameter selection of NIST P-curves, including secp256r1 has created much controversy within the cypherpunk community in the early 2000s. the theory is that the NSA discovered a class of secret curves with an unknown special weakness, and then bruteforced the random seed that would generate the weak curve. [0] On the other hand, secp256k1's parameters were not generated by random seeds. [1]
I think the important fact is not whether secp256r1 has a backdoor, but the decision of selecting secp256k1 by Satoshi Nakamoto for the use in Bitcoin. At the time, secp256k1 was the only widely-implemented non-P curve in various crypto libraries, and almost nobody used it at the time. It seems the entire decision of using secp256k1 was made to avoid secp256r1. This is another piece of evidence that Satoshi Nakamoto must have beee active in the 1990-2000 cypherpunk community, so that he was well-aware of those discussions. This should shed some light on his possible identity.
--
[0] DJB's paper how to manipulate curve standards [2] is DJB's attempt of creating the strongest argument for this claim. But even in his analysis, overall it's not too plausible, there's little evidence that such a class of secret curves exists and it required huge computation (2^80), it's on the edge of what was possible, but the pseudorandom parameter selection is certainly technically unfavorable as he demonstrated.
[1] https://safecurves.cr.yp.to/rigid.html https://safecurves.cr.yp.to/rigid.html
[2] https://eprint.iacr.org/2014/571.pdf https://eprint.iacr.org/2014/571.pdf
- pg_is_a_butt 7y ago> It seems the entire decision of using secp256k1 was made to avoid secp256r1. This is another piece of evidence that Satoshi Nakamoto must have beee active in the 1990-2000 cypherpunk community, so that he was well-aware of those discussions. This should shed some light on his possible identity. I was well aware of all that, at the time and now, without being active in the cypherpunk community. Granted, I was in college for a CS and math degree, but the cypherpunk community was pretty loud if you were listening at all.
- bcaa7f3a8bbc 7y agoYes, it's another way to interpret his choice. "Satoshi being a member of the Cypherpunk" is only one possibility. It's entirely possible that he wasn't active at all, and his familiarity of Cypherpunks was from his learning, not from the participation.
- pg_is_a_butt 7y agoIt's entirely possible one of us is Satoshi.
- sunstone 7y agokarma -50 and account created in 2013 :D pg_is_a_butt is my alter ego. I'm not worthy. (though my account was hell banned for a long time and I soldiered on regardless :) Ok I think it's our civic duty to follow pg_is_a_butt around and upvote his comments :D pg_is_a_butt 10k karma or bust!
- pg_is_a_butt 7y agoNo one here understands civic duty. They understand only imaginary money given to them to erode liberty.
- nonefromabove 7y ago"Evidence that Satoshi Nakamoto must have beee active in the 1990-2000 cypherpunk community, so that he was well-aware of those discussions. This should shed some light on his possible identity." I dont think so .... that's just noise. He might have just asked around and received advise from friends/colleagues or random stranger what should be avoided. You are reading too much into this. This sheds no light on possible identity. Only identity it sheds light on is how your mind works with tiny information and how you confuse noise for signal.
- BubRoss 7y agoYou are claiming it is noise with no reasoning behind it. If his friends or colleagues knew about this curve, wouldn't that imply they were part of the community.and this he was part of the community? I'm not sure why you would take such a strong position that amounts to 'nope just noise'.
- deleted 7y ago[deleted]
- bcaa7f3a8bbc 7y agoSometimes, people can make wrong assumptions by reading one's words alone. First, not everything is carefully worded, sometimes you choose the wrong words and didn't realize until someone responded. Also, not all context/information is necessarily expressed - for example, you know an argument, and you already know more information about your argument, you don't always write them down, because talking on a forum is not your exam. Another example is when you know an argument and its counterargument, and you talk about the argument, someone may come and say: "you are misguided, don't you know its counterargument"? Second, no tone, facial expression, or other social hints are preserved, when you talk about an argument casually, others may assume that you are serious. When I claimed that Satoshi was active in the cypherpunk group, I didn't say that I was also thinking about the citations in the original Bitcoin paper, specifically, Wei Dai's "b-money" or Adam Back's "Hashcash", both came from the infosec community of the late 90s, and they are something that a member of the cypherpunk group should be intimately familiar with. An additional piece of information about his avoidance of using secp256r1 curve fits into the narrative well, and they can be circumstantial evidence if you buy into it. Also, I wasn't being serious at all, I mentioned it simply because it's just an interesting idea related to the original article and other readers may find the idea interesting as well, and I used the phrase "shed some lights", which, according to Merriam-Webster, is a phrase that means, "to make it possible to understand or know more about something", not a bad choice. Unfortunately, I misused the word "evidence", a pretty strong word. I should have used "circumstantial evidence" or "hints". while I was typing the original comment, I was also thinking about the possibility that Satoshi wasn't an active cypherpunk in the 2000s but simply a follower who had read the mailing list archive after the group became inactive, but I didn't mention either. I was not writing a background check for Satoshi, there's enough good articles on the Web. When nonefromabove was replying my comment, nonefromabove, who was being unaware of anything of the above, must have deduced that I was fallen into the "connecting-the-dots" fallacy, or having a somewhat conspiracy theorist's attitude on Satoshi's identity, and I was being completely serious about it. Meanwhile, I was well-aware of the cognitive bias of overfitting data, and I was a fan of Nate Silver's The Signal and the Noise when his book came out. Nevertheless, I was told that I was "reading too much into this", and how "my mind works with tiny information and how I confuse noise for signal". Perhaps, to avoid misunderstanding like this, we may use a "confidence" label, inc. "almost certain, likely, possible, unlikely", and a "tone" label, inc. "joke, casual, argument, serious", and so on.
- truantbuick 7y agoI don't know specifically about secp256r1, but in general, I think there were already a lot of suspicions and most people were wary of any ECC curves NIST or NSA had chosen by 2008 when Bitcoin was developed. [1] In a purported email [2] (reasonably well attested to) from Satoshi Nakamato, he claimed > I didn't find anything to recommend a curve type so I just... picked one. [1] https://web.archive.org/web/20140621062515/http://archive.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1115 https://web.archive.org/web/20140621062515/http://archive.wi... [2] https://archive.is/lHHSk https://archive.is/lHHSk
- bcaa7f3a8bbc 7y agoInteresting, I didn't know the existence of the quote or the mail. So... if what Satoshi claimed is true, this choice was actually a pure coincidence and doesn't really have any significance, hmm. I don't know what to say - yet another strange coincidence in history I guess?