3 ms·
The basic intuition behind symmetric cryptography is that once your input bits are "thoroughly mixed", there's no way to un-mix them besides brute-force. On th
by s_tec 7y ago
The basic intuition behind symmetric cryptography is that once your input bits are "thoroughly mixed", there's no way to un-mix them besides brute-force.
On the other hand, we don't have a solid theory of computational complexity yet. Even basic questions like P = NP are still unanswered, so we have no idea what "thoroughly mixed" actually means, how to measure it, how to achieve it, or even if it exists.
Whatever it is, a single round of BLAKE certainly isn't "thoroughly mixed". Is 10 rounds enough? Nobody knows. On the other hand, we suspect that a thousand rounds are no better than a hundred - there's probably a plateau of "maximum entropy", and once you get there, extra mixing doesn't help.
So, since we don't actually know what we are doing, we pick a safety margin, like 1.4x or 2x, and just use that. It's all just guesswork until the theoretical side catches up, so your opinion is as good as mine. On the other hand, picking a safety margin of 1 seems rash. If you have practical attacks in the round before, you probably aren't anywhere near the plateau of maximum entropy!