3 ms·
> The claim here is that the procedure used for choosing the SEED in the first step involved SHA-1 of some ASCII text with a counter. That's the story as much
by acqq 3y ago
> The claim here is that the procedure used for choosing the SEED in the first step involved SHA-1 of some ASCII text with a counter.
That's the story as much as I see it: there's a constant that doesn't appear to be "arbitrary" enough in a sense that there's a suspicion that it could be too "special" if nobody can recognize it, and nobody can show how that one was generated.
And as there's an official procedure to turn something to something "more random" that "something" appears to be still missing.
BTW I don't think that the "inefficiency" you see in the steps there changes anything.
- dfox 3y agoThe whole point of the procedure as designed is to make how the constant was selected irrelevant to the security of the resulting curve. Also you have to consider the historical context. The procedure was originally designed to generate parameters for cryptosystems that were very much built on the assumption that SHA-1 is secure hash. Any method to choose a weak SEED in a reasonably practical way involves either breaking SHA-1 (collision does not really help, you would need preimage) or the underlying ECC structure having some gaping security issue that only NSA knows about (ie. there being ridiculously many weak curves).
- acqq 3y agoAnd we come once again back to the start: _because_ there's an explicit algorithm right there in the standard which allows to start from something "not special" like the digits of Pi or even the ASCII strings of the beginning of the Declaration of Independence, why the completely opaque constants instead? Even if it's, as Filippo suggests, because "the counter has to be there because only one in every 192 to 521 hashes is actually good to make a curve out of", if the counter is a known part of the process of such a selection, all these details could still have been "open". At least, that's my understanding why there's still talk about it all, and this bounty: those who don't like the opaque constants argue: why aren't they "open", if really "irrelevant"? Now, if the bounty shows that the constants come from something like SHA-1("Jerry and Alice deserve a raise. 1398") then all this looks a little better, especially if it can be shown that that "1398" was the first integer that "worked" for the selected phrase, according to the publicly known criteria.