3 ms·
Here we have Léo Ducas testing Schnorr's new method in Sage: https://github.com/lducas/SchnorrGate https://github.com/lducas/SchnorrGate Apparently, "[t]his su
by paob 6y ago
Here we have Léo Ducas testing Schnorr's new method in Sage: https://github.com/lducas/SchnorrGate https://github.com/lducas/SchnorrGate
Apparently, "[t]his suggest that the approach may be sensible, but that not all short vectors give rise to factoring relations, and that obtaining a sufficient success rate requires much larger lattice dimension than claimed in [Sch21]."
- ianbooker 6y agoCP Schnorr is emeritus professor from Frankfurt university. He is respected for his work in cryptography. He has, pun intended, nothing to prove but still works and furthers research. Yes, claiming that "this breaks RSA" is bold, but this implementation shows that there is some advance in doing so in the paper. Therefore signaling that this is a "scandal" via the postfix "gate" seems just inappropriate. Apart from that kudos for the implementation to Ducas! Calling it the "Schnorr attack" would imply that the outcome of it is still uncertain. And it also would sound way cooler ;)
- paob 6y agoI recommend you contact Ducas to tell him about your concerns directly. I do not know him personally as I first heard about this from his public Twitter account: https://twitter.com/DucasLeo https://twitter.com/DucasLeo Just to make sure you get Ducas's main argument, I quote him here again: "Personal study (unfortunately, never written down cleanly) of this approach suggested me that this approach requires solving SVP in dimensions beyond reasonable, leading to a factorization algorithm much slower than the state of the art. My impression is that this is the consensus among experts having spent some time on it as well." So it seems like the conclusion is clear-cut contrary to what you were suggesting. Also wouldn't the name "Schnorr attack" lead to people thinking of attacks on Schnorr signatures instead?
- ianbooker 6y agoGood point on the signatures.