4 ms·
"Theory and practice" was a poor choice of words on my part. The point is simply that there are assumed-hard problems and cryptographic constructions based on
by sdevlin 12y ago
"Theory and practice" was a poor choice of words on my part.
The point is simply that there are assumed-hard problems and cryptographic constructions based on them. If there is wiggle room between these things (as in RSA), it can severely undermine the strength of the system.
This is why proofs are valuable: if you can prove the cryptographic construct is reducible to the underlying problem†, you can focus your attention on the problem. I feel much better worrying about the practicality of quantum computers than whether there's a plaintext recovery attack that runs in a million queries.
† This isn't a panacea, unfortunately, as side channels are still a concern. Also: conformance of implementation to what has been proven.