4 ms·
I was super confused about this as well. Also, the way OP picked the length of the truncated salt was troubling to me: "Too small, and we improve the economic
by csense 2y ago
I was super confused about this as well.
Also, the way OP picked the length of the truncated salt was troubling to me: "Too small, and we improve the economics of precomputation. Too large, and we risk creating a reliably crib for distinct plaintext values" -- then went on to do a tricky computation to find the balance. The inputs of this computation seem to be some assumptions about the number of users on the network and the computing power available to adversaries -- both of which could be wrong, and/or conceivably change by orders of magnitude over a few years.
Past tense, because OP has changed the post (perhaps in response to your comment) and now says "In my earlier design, we needed to truncate the salt and rely on understanding the birthday bound to reason about its security. This is no longer the case, since each salt is randomized by the same random value used in key derivation."
I haven't read the changes in enough detail to say anything about the new design.
- some_furry 2y ago> (perhaps in response to your comment) Yes. > I was super confused about this as well. > I haven't read the changes in enough detail to say anything about the new design. Sorry about that, but the entire reason I decided to write these blog posts was to get feedback about different aspects of my proposal before I tag a release. In one bite, it's too easy to get distracted and miss details.