3 ms·
Published by Tesla? It's unwise to use cryptographic code written by engineers working 72 hour weeks at an "extremely hardcore" company. Here is the Gimli spe
by bugfix-66 4y ago
Published by Tesla?
It's unwise to use cryptographic code written by engineers working 72 hour weeks at an "extremely hardcore" company.
Here is the Gimli spec:
https://gimli.cr.yp.to/spec.html https://gimli.cr.yp.to/spec.html
Here is the attack illustrating weaknesses in the design:
https://eprint.iacr.org/2017/743 https://eprint.iacr.org/2017/743
Here is a statement from the Gimli team arguing that it is still secure despite the published 22-round attack:
https://gimli.cr.yp.to/statement.html https://gimli.cr.yp.to/statement.html
Finally, Hamburg's "attack" will not be feasible in the foreseeable future, even with quantum computers. Even if the "attack" were extended to the full 24 rounds, it would not contradict any security claims made in the Gimli paper.
Daniel J. Bernstein (djb) is a wizard, but use Gimli at your own risk.
- mananaysiempre 4y agoJudging from the statement (I haven’t the cryptographic kung fu to distil the paper myself), the attack seems to be more of an exploration of how vulnerable the (relatively new) ways the Gimli suite builds everything out of a single crypto core can be when used badly, not something applicable to the usage that’s actually specified. Or is that still concerning? (Plus it does seem worse than brute force from the numbers given, though I can’t judge whether that makes it uninteresting in general, either.)
- bugfix-66 4y agoYes, you clearly don't understand it. That's ok, but you probably shouldn't confuse the issue. Basically the attack shows that Gimli's speed and simplicity introduces exploitable flaws and reduces its security: Bernstein et al. have proposed a new permutation, Gimli, which aims to provide simple and performant implementations on a wide variety of platforms. One of the tricks used to make Gimli performant is that it processes data mostly in 96-bit columns, only occasionally swapping 32-bit words between them. Here we show that this trick is dangerous by presenting a distinguisher for reduced-round Gimli. https://eprint.iacr.org/2017/743 https://eprint.iacr.org/2017/743
- adrian_b 4y agoYet the attack, as very clearly stated at your link, does require much more computing resources and time than a standard brute force attack. So I can only agree with DJB that the attack, in its present form, is completely useless. At most, it can be argued that maybe someone will find a way to use the ideas from your link to conceive a new attack that is much more efficient. I do not find this more convincing than the threat that someone will find an efficient attack based on completely different ideas. Any more recent cryptographic algorithm is riskier than the older algorithms, because it is less understood. However Gimli is intended for slow microcontrollers, where the encrypted data cannot be very valuable, otherwise one would use a slightly more expensive CPU like Cortex-A55 (a few dollars instead of less than a dollar, for a MCU/MPU package), with standard cryptographic libraries. So the damage done by an attacker decrypting the MCU communication cannot be great, therefore it is an acceptable risk to use a less trusted algorithm, if that reduces a lot the hardware cost.
- krageon 4y agoSo the attack must be useless, but if it was not it wouldn't matter because the software doesn't have to be secure to begin with. That's not a great mindset through which to view cryptography.
- adrian_b 4y agoYou put in my mouth words that I have not said, so I will say more clearly: 1. That attack is useless. 2. Nevertheless, Gimli is relatively new and it is also designed for minimum cost, not for maximum security, so there is a risk that someone else could discover a real attack, a risk that is greater than for older algorithms like AES or Chacha. 3. There exists no practical 100% secure form of cryptography. Any choice of cryptographic algorithms is a compromise between the computational cost for the operations done for protecting data, e.g. encryption/decryption/signing/verifying and the computational cost for an attacker that tries to decrypt or forge the protected data. 4. The compromise must be chosen for each application depending on the implications of a successful attack. Some data is so important that it has to remain secret even 10 or 20 years in the future, other data is ephemeral and it does not matter if an attacker would succeed to decrypt it a week later. The correct mindset in cryptography, like in any other domain, is to choose the right tool for the job. If you want to use a $0.50 microcontroller, then you must use simpler cryptographic algorithms that can have an acceptable performance on such low-cost hardware. If you want to use algorithms that are harder to break, then you must accept to pay $5.00 for a more powerful device (at the latter price any decent device would have hardware implementations for standard algorithms like AES and SHA-256, so you would not have reasons to use anything less secure).
- deleted 4y ago[deleted]
- unwind 4y agoI should not be allowed into the same room as crypto development, and have certainly never tried to "attack" a crypto algorithm. Still, reading that, against 22.5 (of 24) rounds of the Gimli computation, the attack is claimed to need 2^129 bits of memory. That is 77,371,252,455,336,267,181,195,264 TB if math is right, which does seem to gently push that "attack" into a rather theoretical plane? Not sure what I'm missing, from your tone I would expect a smoking hole and this doesn't seem to be that.