4 ms·
Those interested in this topic might also find a couple other papers by Phil interesting: 1. Practice-Oriented Provable Security and the Social Construction of
by barathr 3y ago
Those interested in this topic might also find a couple other papers by Phil interesting:
1. Practice-Oriented Provable Security and the Social Construction of Cryptography: https://www.cs.ucdavis.edu/~rogaway/papers/cc.pdf https://www.cs.ucdavis.edu/~rogaway/papers/cc.pdf
2. An Obsession with Definitions (Section 5): https://books.google.com/books?id=SwOkDwAAQBAJ&lpg=PA18&ots=bMtIgWHprB&dq=%22I%20am%20constructing%20a%20definition%22%20rogaway&pg=PA17#v=onepage&q&f=false https://books.google.com/books?id=SwOkDwAAQBAJ&lpg=PA18&ots=...
- keepamovin 3y agoI thought about something related quite a lot. Developing a cryptographic hash^1 and some of the reactions were entirely dismissive. Hostile as if (not against me per se, but) almost against the idea of developing crypto outside of the Church. As if Scripture forbade such a blasphemy even being considered, or as if making new tech was a Denial of Service against the Priests who need to review every Miracle and Revelation for sanctified inclusion within the Cannon. Or whatever. I formed my thoughts into a deliberately indirect dissection of this, and now I repost here: Thanks for your input! I hadn't realized my post had made it to the subreddit since it was immediately removed, so it slipped my mind. Anyway, it's not really related to what you said, but I'll take your remarks as a starting point to have a riff / use as springboard for a thought that's been brewing: Hearing you say that seasoned cryptographers wouldn't even bat an eye at this surprised me. I'd thought those well-versed in this domain could glance at an idea, scan the smhasher results, and almost intuitively know whether there's potential there or not. I imagined they'd have a sort of gut feeling, something like "this holds promise" or "this won't cut it," directing their decision to delve further. So, why is it such a challenge for non-experts to make substantial contributions? It seems as though there's an unspoken rule prohibiting it. I suppose this isn't unique to cryptography; it probably exists in any specialized field, like bioinformatics. Yet, there's a distinction - when an outsider steps into a bioinformatics forum with innovative ideas and some groundwork, they're likely to find a receptive audience. But with cryptography, it feels closed off. It's as if only certain individuals are permitted to work on specific topics within established parameters, and only an elite few are qualified to assess this work. It's reminiscent of religious doctrine where deviation is considered heresy and swiftly dismissed. This leads me to question who's guiding the crypto field to limit creative contributions and why? Who stands to benefit from curbing the development of new algorithms and preventing their widespread adoption? Who might be disadvantaged by a sudden surge of new, potentially powerful crypto algorithms? It's a challenging balance to strike. Personally, I think the current system could be improved. As an impartial observer with no stake in the outcome, I see this as an intriguing creative outlet. I'm not advocating for a revolution and frankly, I'm not particularly concerned if things stay as they are. However, I do believe that when a field becomes too closed, we all stand to lose. Here's the intriguing part: while the field is theoretically open, in practice, it mimics a closed one, similar I suppose to the restrictions and veil of esoterica surrounding nuclear technology. But nobody openly discusses this closed-off nature, which only adds to the strangeness. I understand why it's structured this way, but I can't help thinking there could be a better approach. Given the diverse interests involved, it's challenging to identify what that might be. Surely, I can't be alone in thinking this way, right? 1: https://dosyago.github.io/rain/ https://dosyago.github.io/rain/
- msla 3y agoThe problem with developing your own cryptography is that it's easy to make something you can't crack but which has holes an experienced cryptographer could drive a bus through. A false sense of security is worse than no security at all. Plus, of course, most people who claim to have a Bold New Encryption Algorithm are selling the absolute worst kind of snakeoil, like XORing the input with a single fixed-length key over and over again, because they know most of their victims will be even less knowledgeable than they are. The outright frauds poison the make-your-own cryptography field for the honest ignoramuses. The field isn't closed off, either. It's just founded on mathematics that's beyond what the average untrained or semi-trained person reaches, especially the ones who feel entitled have Big Opinions on the subject. However, if some can't grasp the mathematical underpinnings of contemporary cryptography, their opinions of how cryptography ought to be done are worth less than nothing. Mathematics isn't a democracy, ignorance doesn't get a vote.
- russfink 3y agoWe call such a system “secure against the chosen cryptanalyst.”
- eru 3y agoOh, and even trained mathematicians have a hard time coming up with good new cryptographic primitives. Many of the candidates fail.
- deleted 3y ago[deleted]
- keepamovin 3y agoThis is the old Schneier textbook defense that anyone can make a cipher they themselves can’t break, therefore don’t try, yet doesn’t hold water here. Not that it’s not true when applied to a certain group of oil de serpenthe salesmen, or to noobs making toys, but it obfuscates the reality of outsider talent by unhelpfully conflating complete frauds with budding learners with enthusiastic amateurs with experienced amateurs. And reinforces the notion of a priest class, upon which amateurs, encountering the same, should abandon their labors and despair. It’s also a surprisingly hostile way to treat interested budding cryptanalysts and cryptographers. It is a kind of hazing designed not to forge bonds but verily to discourage. As in: We only want insiders creating crypto and there’s a reason for that; and in the main it’s not about protecting against flawed security; in fact, this reason is about protecting our ability to break. Protecting this crucial vital main and security mission of the high priests at the top of this hierarchy (who, nevertheless veil their faces in the shadows: the mages’ hood) is the reason for the weird, captured nature of this field. And because this little aphorism comes from The Book of Bruce, none dare question for fear of being tarred a heretic and cast out. Luckily, for me, an outsider has no such fear: being already on the outside. And hence is revealed a weakness of the little system of forced organization. Aside from that, such discouraging attitudes and aphorisms, obscure the fact that analyzing new primitives is difficult. And they conceal the truth that, it’s not so much that tech created by amateurs has no merit, it’s that it may. And this maybe, makes the job that much harder for the code breakers; the mages; The “surveillance state” that this posted HN article, under which I am adding this comment, rails against. The code mages would much rather everyone stick to a predefined set of spells that follow the designated parameters of good sense and civility, which i suspect coincides not a small amount with the technical exploitation window of the secret code breakers. Indeed some are secretly designed to be broken: one way designs, unbreakable, unless you possess the kernel, upon which a more elaborate design was scaffolded for release. The designer-in-secret retains the secret kernel. It seems I’ve had to be more direct than I’ve initially desired to explain my point. It’s hard to do cryptanalysis, and the experts who do it have limited resources, so they don’t want to have to deal with a deluge, so they architect an academic culture empowered with these cutsie aphorisms to further those ends, as well as capture, guide, curtail and direct the fields search from the shadows. Coercive funding withholding is but one means. The strongest is a culture and acolytes with a fanatical devotion to the orthodoxy that sustains this control. I understand the complexity of the balance that needs to be struck, but i think with these deceptively closed and captured fields, we all lose out. At least nuclear secrets is open about just how closed it is and why: it’s a weapon a small club of states wield, and no one else. Crypto in reality is the same. It’s a shield wielded by the state, not by the public. The public gets, not security nor privacy, but what the regulator deems them safe to have. This situation cannot be admitted because it dispels the illusion that the field is open and not captured. And also the illusion of privacy and security not being monopolized by the state. I’m not sure of the exact best balance, but I don’t think the current system is the best. Perhaps a better balance is crypto being more like nuclear secrets, where it’s open about how closed it actually is rather than deceptively, in the vein of the snake oil salesman, posturing a security that is not, in fact, delivered. If not ignored this notion will, unfortunately, provoke, understandably, furious reactions from both those who depend on the belief and the security, as well as those in the captured industry, who would rail against it, but cannot do so, thus turn their frustrated expression towards any who expose their embarrassing constraint. I have no vested interest either way, except in the good of everybody…and I think it’s high time for this discussion to be advanced in a better direction. Government transparency, and accountability depends on clarity with, and consideration towards, the public who depend on them.