4 ms·
This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - ht
by throwaway654329 4y ago
This is an epic result. One of the authors, Ward Beullens, also recently broke the Rainbow signature scheme: “Breaking Rainbow Takes a Weekend on a Laptop” - https://eprint.iacr.org/2022/214 https://eprint.iacr.org/2022/214
He is on a roll at breaking post-quantum candidates and he and his coauthors will hopefully keep going. That this guy is able to do this kind of work in the open is a public good. Note that he has broken schemes after NIST has declared the systems safe enough to advance to the next round. This is really embarrassing for NIST. Do they really not have the capacity for doing this kind of research? One or two people can only do so much, no? One can only imagine what is being done in private.
Thanks for working in public Ward! You’re doing a better job at cryptanalysis than NIST can do with a team of people who do this as a full time job! You deserve a medal, along with other cryptanalysts who work in public and release results in public.
It’s a little sad that he uses Magma for his attacks since it isn’t Free Software but it’s not so important. The result is what is important.
Already as of today one group using SIKE is now considering switching to CSIDH: https://forum.xx.network/t/paper-an-efficient-key-recovery-attack-on-sidh-preliminary-version-affects-xx-messenger-quantum-security/6835 https://forum.xx.network/t/paper-an-efficient-key-recovery-a...
This underscores a recently reiterated point from djb on the NIST post-quantum mailing list: we should not have confidence in the security of these post-quantum schemes.
These kinds of breaks are a strong argument for the use of hybrid constructions such as ECC or even more conservative systems. Note that NSA opposes hybrid constructions and is pushing for post-quantum schemes to be deployed without hybrid protections.
SIKE, like Rainbow, both supposedly post-quantum have turned out to be less secure than currently deployed contemporary systems. They are neither post-quantum nor currently secure. Very impressive results!
- TontonNestor 4y agoWard Beullens is not an author of this paper.
- throwaway654329 4y agoOh wow, I completely made a mistake here. Ward is amazing, but I should have properly credited Wouter Castryck and Thomas Decru for this paper. Embarrassing. I wish I could edit my comment now, the shame will last forever.