40 ms·
So if I understand this correctly: the community accepted those mysterious strings of unknown origin while it would’ve been trivial to replace them with differe
by rollulus 3y ago
So if I understand this correctly: the community accepted those mysterious strings of unknown origin while it would’ve been trivial to replace them with different strings with a known origin, by providing another but known input to the hash?
- mike_hearn 3y agoYou understand the situation correctly, hence why it's kind of disastrous. The phrases "so close" and "you had one job" seem relevant here. Unfortunately, as far as I know this would be the only case related to the NSA and cryptographic standards where someone has alleged incompetence. Normally the stories run the other way. Doubly problematic: NIST is known to have been compromised and putting backdoors into elliptic curve related standards, the fact that this mechanism didn't create trust was pointed out immediately, and neither NIST nor the NSA did anything to address the concern. Just like with Dual_EC_DRBG. Triply problematic: the NSA explicitly told people in 2015 not to upgrade past the NIST curves to other curves, because quantum computers will soon be good enough to break ECC entirely and so everyone should switch to post-quantum crypto instead (which is new and still experimental widely used etc). If ECC worked fine, QC was far off and you wanted to keep people on the NIST curves for as long as possible this is exactly what you would say. The cryptography community has not exactly covered itself in glory over this situation. It's been nearly 25 years now. There are newer curves that don't have this problem, why are the NIST curves still being used by anything? Where is the effort to phase them out, like there was with SHA1? This article even seems to be advertising them.
- tptacek 3y agoSHA1 was phased out, for another NIST standard, because it was known to be weak (in the sense of a likely cryptographic break --- which happened --- not in the sense of needing to be more careful using it). That's not the case with the P-curves; short of a QC attack that will break all modern curves, it's unlikely the P-curves are going to be broken.