3 ms·
Can anyone provide links or references to current techniques and methods for performing cryptanalysis against hash functions and prngs? I frequently find myself
by throwaway1492 5y ago
Can anyone provide links or references to current techniques and methods for performing cryptanalysis against hash functions and prngs? I frequently find myself trapped in a loop thinking a long the lines of “they’re just bits there has to be a pattern”. Border line obsessing on these things, blake2b in particular. Does anyone else have this problem?
- hinkley 5y agoIf encrypted data has a pattern, then it is leaking data. There are some famous examples of this with block cyphers. If the encrypted data is indistinguishable from white noise, then the CSPRNG you built on top of it can also be made indistinguishable.
- hinkley 5y agoNo comments, just downvotes. The ECB Penguin is an example of information - patterns - leaking out of encrypted data. This is a cryptographic failure mode and the solution is a better algorithm. https://blog.filippo.io/the-ecb-penguin/ https://blog.filippo.io/the-ecb-penguin/ Low entropy means predictability in the input versus the output. Properly encrypted data has high entropy, which is why you can’t compress it after encryption. Random number generators need to be high entropy, which is where the idea of CSPRNGs comes from.
- edoceo 5y agoStart looking at code in libsodium. Crypto is too hard for me and I just trust the libs - but I can read the code (sorta). The stuff in OpenSSL is crazy to me but libsodium I can almost understand. I feel like I can know it but not KNOW it.
- SAI_Peregrinus 5y agoMostly similar to block ciphers or permutations. Differential cryptanalysis is a good starting point. Usually one starts with a reduced-round version, often a single round. Break one round, then see if that can be extended to 2, etc, etc. The cryptanalysis of Meow Hash[1] is instructive, since it's a weak hash and actually vulnerable in full. There's also a good Differential propagation analysis of Keccak[1] paper, using a reduced-round Keccak. There's also Rotational cryptanalysis. Here's a paper on Keccak uses that technique.[3] It was first formally defined by Khovratovich and Nikolić.[4] [1] https://peter.website/meow-hash-cryptanalysis https://peter.website/meow-hash-cryptanalysis [2] https://eprint.iacr.org/2012/163.pdf https://eprint.iacr.org/2012/163.pdf [3] https://eprint.iacr.org/2012/546.pdf https://eprint.iacr.org/2012/546.pdf [4] https://www.iacr.org/archive/fse2010/61470339/61470339.pdf https://www.iacr.org/archive/fse2010/61470339/61470339.pdf