3 ms·
Still though, in order for this to work you also need the specific key of one of their peers, so at the end of the day you still need a second preimage attack.
by ttybird 5y ago
Still though, in order for this to work you also need the specific key of one of their peers, so at the end of the day you still need a second preimage attack. And to be honest while I consider this as a silly decision on their part the fact that it can't be used as a targeted attack makes it relatively useless. Even tor until recently used 80-bit keys (which is much, much worse than the 128 that this app uses).
You previously claimed that this will cost an average of 2^64 key generations, but this is just to find two pks that cause collisions in the 128 bit output space - two pks which most likely are not used by any of their users (which are what, around 2^20 atm?) I would be interested in an updated estimate of how long such a collision would take when keeping this in mind.
- ttybird 5y agoTo be more specific, I personally estimate that it will take around 2^108 attempts on average to find one such key, which is much more difficult compared to an aes128 batch attack.