3 ms·
> How do we know, and be sure that this is true? Predicting the generator's output reduces to solving the discrete logarithm on elliptic curves, which is incre
by bren2013 12y ago
> How do we know, and be sure that this is true?
Predicting the generator's output reduces to solving the discrete logarithm on elliptic curves, which is incredibly hard unless you chose the private key.
Just like in any asymmetric crypto scheme, given only the public key, it's very difficult to find the private key.
(Actually doing it requires knowledge of how the generator works. I promise you it is easy given the private key, but you can go into its internals if you don't believe me.)
> Isn't it just trivial for someone to "recover" your data by pretent to be you by court order, NSL or other means?
Without a "golden key," somebody would have to ask you. With the "golden key," somebody would have to ask the organization in charge OR you.