6 ms·
Cool demo, but this is only log2(43 quintillions) = 65 bit security. Kind of related is DiceKeys, with 192 bit security: https://www.crowdsupply.com/dicekeys/d
by ecesena 9mo ago
Cool demo, but this is only log2(43 quintillions) = 65 bit security.
Kind of related is DiceKeys, with 192 bit security: https://www.crowdsupply.com/dicekeys/dicekeys https://www.crowdsupply.com/dicekeys/dicekeys
- warkdarrior 9mo agoYeah, this explains why this cryptography paper was published in a ML conference. Any reasonable reviewer would reject this as not providing sufficient security.
- 0manrho 9mo agoIt's pretty upfront about being a novelty project done by a self-described non-crypto expert, and I don't see any assertions of it guaranteeing any degree of sufficiency/security or claiming any such NextBigThing(TM) hype. Just because a paper is published doesn't mean it wasn't done for fun/the hell of it.
- acorn221 9mo agoYeah this is bang on. I messaged my old supervisor from uni about turning CubeAuthn into a paper and she suggested I submit the paper to that conf.
- Terr_ 9mo ago192 bits? I must be missing something here, there are 25 unique dice that can be permuted, each can have six potential sides showing, and 4 potential orientations of the displayed face... So (25!)×(25×6×4) ? Isn't that more like only 93 bits? Well obviously harder to scan from a phone, I think a deck of playing cards would be easier to acquire and store. Shuffling 27 would give you 93 bits, shuffling the full 52 would be ~226.
- ecesena 9mo agoIt’s explained in the link. I actually misremembered, it’s 196 bits.
- deleted 9mo ago[deleted]
- Terr_ 9mo agoNever mind, with the benefit if sleep I see an error in my math. Still, I wonder if a similar thing could be done by shuffling a deck of cards, and then riffling the results past a good camera so that an app can recognize the sequence in order. Perhaps it would be vulnerable to common shuffling mistakes?