5 ms·
I'm interested in knowing why your post implies that its not useful. I would like to know if its worth reading as I've just added it to Read It Later. EDIT: Pl
by experiment0 14y ago
I'm interested in knowing why your post implies that its not useful. I would like to know if its worth reading as I've just added it to Read It Later.
EDIT: Please correct me if you didn't mean to come across that way, it's just the last comment on the blog:
> this post is just terrible. i don't understand why people feel the need to learn a tiny bit about a subject, and regurgitate their misunderstandings through blogging. please take it down, you are making the world a worse place.
has made me wary.
- tptacek 14y agoI'm asking seriously, not just to make a point.
- randartie 14y agoNot sure what your problem is with the article, it's a basic intro article. Clearly the people that find it useful are the people who do not know the material and don't need to deal with this on a regular basis.
- tptacek 14y agoSo I'm curious what you do with a basic understanding of, say, the RSA math.
- Mercury23 14y agoSome things are worth knowing just out of curiosity. I always found the RSA algorithm fascinating in its own right, despite the fact I have no intention of ever implementing it myself. I'm not a mathematician nor a computer scientist, but I find an appreciation of certain algorithms not unlike the appreciation of art. Pointless in a pragmatic sense, but intellectually satisfying. I can't speak for this article specifically though; I think there are better explanations out there, not to say that this one is bad. It is a difficult topic to explain after all, especially when you don't know the level of math background your audience has.
- dvanduzer 14y agoFor one thing, it's just plain wrong about Diffie-Hellman's susceptibility to a man-in-the-middle attack. The author claims there is a potential if an attacker obtains the intermediate values, but then later explains the problem as if the attacker had intercepted the private values (which are never exchanged). There is the potential for man-in-the-middle if the attacker intercepts and modifies the intermediate values during the exchange, but that is not mentioned here. It is, of course, vital to keep those privately generated values secret, and if an attacker learns those, then the communication isn't secure. Various communication protocols are vulnerable to brute force, or eavesdropping, or man-in-the-middle. Confusing these things and passing it off as an authoritative explanation is bad for everyone.
- jrockway 14y agoRealize the number theory is not useless and continue studying it.
- psykotic 14y agoWhat do you do with a basic understanding of limited-slip differentials, frequency modulation, the Maillard reaction, or any other number of subjects? If you're anything like me, what you do is take joy in understanding a little more about how stuff works, however superficially. And who knows when some grain of knowledge could be a useful inspiration in some seemingly unrelated area where you do have expertise? That happens more often than one might think, especially with mathematics. I get that you worry some well-meaning fool will read this and go implement their own botched RSA-based or DH-based cryptosystem. That concern is legitimate. By all means, post the customary warnings.
- caf 14y agoRight - I think it's part of the mindset of the hacker to assign intrinsic value to a basic understanding of how things work. From the Krebs Cycle to the lifecycle of a star, it's all interesting.
- sillysaurus 14y agoI personally love studying and thinking about Fully Homomorphic Encryption. It has the potential to revolutionize the world similar in flavor to the discovery of Public Key Encryption. In short: it allows you to perform computation on encrypted data. In other words, all programs are data, and now you can perform computation on encrypted data, so now it's impossible for anyone but the encryptor to know what computation is being done. It "hides the intent" of algorithms, just like Truecrypt hides the facts sitting in your passwords.txt file. The implications of this are enormous and a ton of fun to think about. Here's just one example of how the world might change: there's a nonzero chance that in less than a century most computer programs will be fundamentally impossible to reverse-engineer. The old metaphor "you can think of a program as a black box; input goes in, results come out" will become a law of nature, rather than a mere rule of thumb. Now add the fact that the output will probably be encrypted using today's techniques, and the result is striking: any program running on your computer will be free to vaccuum up any data it pleases, encrypt it, then surreptitiously transmit it to its owner. It will be impossible to know ahead of time whether any given program is malicious; the sole way of detecting maliciousness is reduced to (a) the program is reading files that it normally shouldn't be, like your browser history, and (b) a secure HTTP connection is active. So if you give your program a legitimate excuse for (b), such as "my program is a web browser, go ahead and use it" and a legitimate excuse for (a), such as "obviously my browser is going to read and write your history file", then suddenly you wind up in a situation where the browser could be secretly sending your entire history to some third party and it'll be fundamentally impossible for you to detect it's happening. FHE exists. It is coming; Gentry's thesis proved it can be done. The current problem is that the computational cost is probibitive (e.g. If we say that "right now the cost of computing a+b is N", then using Gentry's FHE the cost would be N^6, if I remember correctly; and that's true for every operation, so sub, mul, etc become N^6 more costly to compute) but work is underway to reduce that cost to something more palatable. This is, of course, completely useless to me and to my life. Working on this is unlikely to gain me any useful knowledge nor any applicable talent/experience. By extension, no economic value can be derived from this right now (probably not within our lifetime). So who cares about it? Well, the answer is obvious: few-to-no one. I just have fun doing it because I can; it makes me feel powerful that I can understand and apply this sort of knowledge a century before it becomes commonplace. So why have I been babbling about all of this? Well, I just wanted to thank you, because about 6 months ago you posted a comment along the lines of "the Diffie-Hellman protocol is actually pretty easy to understand", so I nonchalantly checked it out. It was amazing, and led me to devour a bunch of texts on RSA etc (leading to an understanding/appreciation of the RSA math) and eventually branching off into my current explorations of the mysterious world implied by FHE. And "Diffie-Hellman -> RSA -> scrypt -> FHE" just happened to be my path, which just happened to be "useless" (in the "hey I need to make rent" sense) but some other person might have easily gone "Diffie-Hellman -> RSA -> studying OpenSSL -> an ability to send and receive information in a way that's fundamentally impervious to any known attack (otherwise it would be fixed already, since the whole world uses OpenSSL) -> setting up a remote, untraceable C&C server for your Lua-based virus (a.k.a. Flame) -> influencing world events", which is presumably much more useful. So the answer to the underlying question of "why do this type of thing?" can, I think, be expressed roughly as "meh, it's either fun or useful depending on what kind of person you are and your goals, and by the way thanks for originally encouraging me to look into it."