5 ms·
Here’s a video of Craig Wright being called out by an actual expert and it’s hilarious https://youtu.be/0thnCDgRJfM https://youtu.be/0thnCDgRJfM. He clearly has
by Moodles 5y ago
Here’s a video of Craig Wright being called out by an actual expert and it’s hilarious https://youtu.be/0thnCDgRJfM https://youtu.be/0thnCDgRJfM. He clearly has no clue how ECDSA signatures work.
- m348e912 5y agoDoes anyone find the other guys claim more interesting? That you can derive private keys after just one transaction.
- aqme28 5y ago(edit: ignore me) Yeah that sounds like he mis-spoke. You can't get the private key from a signature, or the protocol is broken. Edit: I see. It's confusingly worded but that makes sense.
- drexlspivey 5y agoYou can recover a private key from two signatures if they reuse the same nonce. The nonce should be random and only used once as the name suggests
- marcan_42 5y agoAnd this is one of the reasons why ECDSA is a poor standard: it's too easy to accidentally screw it up, and it results in the worst possible kind of compromise (private key). There is a better way: make the nonce a hash of the message signature and the private key. That way you don't need any randomness, and the entire algorithm is deterministic. It is guaranteed (assuming the hash is good, but you need a good hash algorithm to sign things anyway) that no two messages will be signed with the same nonce, and that the nonce cannot be guessed without already having the private key. This is what EdDSA does.
- drexlspivey 5y agoMost modern wallets nowdays use deterministic nonces via RFC 6979. The newly introduced Schnorr signatures also do not have this weakness afaik.
- nullc 5y ago"ECDSA" isn't a concrete scheme that you can use in any case. To implement ECDSA one must pick a group where the discrete log is hard, choose a message hashing function, and choose a way to serialize the values. One can optionally choose a derandomized method for generating the nonces, e.g. RFC6979 which is the approach taken by most implementations created in the last 5 years or so. One could just as well implement something EdDSA compatible with insecure nonce generation and people have done so (for years the thing you got when you goggled for eddsa python was just such an implementation). It's good that the eddsa paper specifies more of the system, as people have made bad choices and ruined the security-- but even it fails to completely specify the system: the exact input handling isn't specified, which has resulted in security problems.
- marcan_42 5y agoWith "ECDSA" I meant the original NIST ECDSA standard. It is, objectively, a bad standard. ECDSA as originally specified required the use of random numbers in signature generation; the RFC6979 approach may interoperate just fine and be a better idea, but it is not FIPS 186-4 compliant. If you have to break standards compliance to avoid security pitfalls, the standard is bad. It's not just about specifying more of the standard either. EdDSA is designed to be harder to screw up an implementation of, by construction.
- nullc 5y agoRFC6979 has a fairly convoluted design (and poor performance, requiring 12 invocations of the compression function when implemented with sha2 for a 256-bit curve) specifically so that it is actually a FIPS compliant DRBG with its initialization parameters set in a particular standard permitted way, so as to result in a derandomized nonce. While I not a FIPS certification expert by any means, it was intended that implementations could implement RFC6979 without breaking the standard by simply using a standard allowed DRBG in the right way. > EdDSA is designed to be harder to screw up an implementation of, by construction. That's the marketing claim at least. It's debatable. Some of its choices make it easier to screw up, and widespread implementations of it have also been wrong in the varrious ways it was intended to address. It's a good idea to try, at least, for sure. I think nonce security in particular is not at all the best example since modern ECDSA implementations are secure against in that respect. I'm also aware of some systems which have had grave security flaws because they believed the EdDSA claim of a deterministic signature meant that it was a unique signature. The promotion of EdDSA itself as magic pixie dust creates vulnerabilities. There is just no replacement for understanding. :)
- nullc 5y ago> You can recover a private key from two signatures if they reuse the same nonce. You can, but you can also do a lot more than that. Thinking that this is the only attack is a common error, and precisely the one Wright was making in that recording. Two signatures with different messages and the same key and message is just a special case of the fact that if you write out the signing equation as a linear system with privkey and nonce being unknown, and the message and signatures being the knows if the resulting matrix is exactly determined or over-determined, then you can solve for the unknown values. It would also be the case that if you had two signatures with the same key and the nonces being any known multiple of each other that it's just as solvable. There are other attack approaches, for example if you have a set of signatures where you know the leading bits of the nonce you can also recover the keys by solving a hidden number problem. (If you only know the single leading bit it'll take a few hundred signatures). Cryptosystems are inherently fragile. The security assumptions of these schemes demand a uniformly random nonce. Deviation from the required property easily destroys security in practically exploitable ways. The person Wright was arguing with was pointing out that if Wright had the private keys in question -- turns out he didn't-- it wouldn't be impossible that he obtained them after observing a single insecurely generated signature. Wright drove the discussion down a tangent with an argument that one couldn't recover a key with a single signature-- a false claim, but even if it were true it wouldn't really have supported his case.
- marcan_42 5y agoIndeed; in general, if you know 1/n of the information in the nonces, you can recover the private key after n signatures. So even subtle biases in the random number generation can leak your key after a few transactions.
- Moodles 5y agoHe did not (he even said they've recovered 10,000+ private keys!). If a nonce is reused across different signatures or just known because randomness is bad, one can compromise the private key used in making the signature.
- nullc 5y agoIt doesn't even have to be known completely! Almost deviation in the expected properties of the nonce severely damages security.
- Moodles 5y agoHe's referring to the fact that with ECDSA signatures, if the randomness is bad on a single signature (i.e. you know the "k" value in the signature) then that is sufficient to reveal the private key used in making the signature. Similarly, if two signatures are made with the same nonce and private key, you can reveal the nonce and thus the private key. The maths is actually explained on the wiki page: https://en.wikipedia.org/wiki/Elliptic_Curve_Digital_Signature_Algorithm https://en.wikipedia.org/wiki/Elliptic_Curve_Digital_Signatu...
- marcan_42 5y agoHe's saying you can derive the private key from a single signature made using a known nonce value (the "bad random"). You can also derive the private key from two signatures made using the same nonce value. In both cases the solution just requires trivial algebra. That's what we did to get the PS3 signing keys. Accidentally became a bit of a citation in the ECDSA world for that one too; who knew Sony would unwittingly earn the title of "canonical example of how to screw up ECDSA in a consumer product"? :-) It's also how lots of Bitcoin have been taken away when transactions are signed using broken random number generators. These days people are running bots to spot those keypairs and automatically take the bitcoin.
- tombeak 5y agoCraig was Wright then, you can't derive the private key from a single transaction. Bitcoin would be broken if you could.
- _zooted 5y agoThat's awesome, thank you. The irony of "show me or you're bullshit" is amazing!
- Moodles 5y agoHe clearly knows he's talking to an actual expert who's calling him out, so he thinks faking getting angry and storming out is a good way for him to escape the situation.
- yeetaccount4 5y agoWhat else is an cornered scammer supposed to do to save face?
- nullc 5y agoIt worked, didn't it?
- neom 5y agoImagine saying your favourite thing in the world is education and then exacerbating yourself that much when the situation isn't going your way. My money is he loves being on stage "teaching" because he's in love with himself, not educating.