3 ms·
The seed itself was never claimed to be verifiably random. Instead, because it uses a (cryptographically secure) pseudo random generator to produce the curve pa
by Perseids 12y ago
The seed itself was never claimed to be verifiably random. Instead, because it uses a (cryptographically secure) pseudo random generator to produce the curve parameters out of a public seed, the curve parameters are said to be "verifiably random". Today, we have more strict requirements on curve rigidity in mind than at the time they released the curves. It's not really fair to claim that NIST acted in malice by not following best practices which only developed after its publication.
- TheLoneWolfling 12y agoWhich hash function was used?
- Perseids 12y agoApparently Sha1: http://csrc.nist.gov/groups/ST/toolkit/documents/dss/NISTReCur.pdf http://csrc.nist.gov/groups/ST/toolkit/documents/dss/NISTReC... - Appendix 4-7 Which is fine, given that even today Sha1's preimage resistance is not practically broken.
- MichaelGG 12y agoHow does hashing prevent anything? It just makes it a bit harder, as you've got to try a bunch of inputs and look for a desired output. Big deal, especially if they have plenty of time before publishing. It's not like it is hard at all to come up with a really truly random seed to use, one that would not allow such speculation.
- Perseids 12y agoIf you are looking for one specific output, this bunch of inputs is as large as 2^159 on average before you find the preimage (which is far too large to bruteforce with the meager earthly energy resources). The current fear regarding this curves is that the NSA might know how to break a large fraction of all curves, like every millionth curve. In that case, trying out seeds until you get one of those rare curves is feasible, but a truly random curve would be safe with 99.9999% probability. As we have don't trust anybody to generate these truly random curves, we a stuck with rigidity requirements as our best shot.