Live data from Hacker News

“Quantum-Safe” Crypto Hacked by 10-Year-Old PC

spectrum.ieee.org

51–60 of 187 posts

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#51
post #45

Earlier quoted context omitted.

My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they al…

Quantum safe crypto isn’t FUD, NIST’s steadfast refusal to specify a dual system, especially given their historical laundering of NSA back doors is super questionable, but there exist (at least one that I know of) crypto systems that have no exploitable bias. The problem is the impractically large key sizes. Afaict a lot of pqc work is trying to reduce the key sizes to something reasonable.

Horseshit. It's literally not NIST's job to design a "dual system"; the project was to standardize PQC constructions, not whole protocols. Everybody that deploys PQC anywhere is going to deploy "dual systems". This complaint is like claiming NIST is corrupt because they didn't standardize an authenticated key exchange along with SHA-3.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#53

What is the possibility that cryptowallets can succumb to these kinds of attacks? How is it possible that Satoshi's wallet has still, after so many years, not been hacked using a brute force mechanism?

I'm sure many people are trying. On a slightly related note - I wonder what the market effect would be on bitcoin (and possibly crypto as a whole) if anyone managed to transfer money out of the wallet, would it crash the currency?

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#55

What is the possibility that cryptowallets can succumb to these kinds of attacks? How is it possible that Satoshi's wallet has still, after so many years, not been hacked using a brute force mechanism?

I'm sure many people are trying. On a slightly related note - I wonder what the market effect would be on bitcoin (and possibly crypto as a whole) if anyone managed to transfer money out of the wallet, would it crash the currency?

You're sure many people are trying to deploy attacks on supersingular isogeny Diffie-Hellman against Bitcoin?

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#56
post #39
post #35

Earlier quoted context omitted.

He's wrong about the "cryptographic agility" stuff, at least the way he's framed it. But then, another place where I'd part company with him is about the urgency for getting PQC slotted into real-world systems.

Why do you think he's wrong? He's essentially saying IT systems need to be designed with the expectation that cryptographic algorithms will be attacked and may need to be replaced, as I understand it.

If by "crypto agility" one means "we should research diverse cryptographic primitives and constructions so that we can be ready if something we rely upon breaks", nobody disagrees with that. But that's not what Schneier means.

What he says instead is that "it’s vital that our systems be able to easily swap in new algorithms when required". That approach has a virtually unbroken track record of failure. It demands negotiation, which introduces bugs, and even after you get past that, it doesn't work: you literally always end up with downgrade attacks (see, for instance, the DNSSEC work at Black Hat this year). Sometimes those downgrade attacks introduce vulnerabilities for parties that would never have even attempted to use the legacy crypto.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#57
post #39
post #35

Earlier quoted context omitted.

He's wrong about the "cryptographic agility" stuff, at least the way he's framed it. But then, another place where I'd part company with him is about the urgency for getting PQC slotted into real-world systems.

Why do you think he's wrong? He's essentially saying IT systems need to be designed with the expectation that cryptographic algorithms will be attacked and may need to be replaced, as I understand it.

[deleted]

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#58
post #45

Earlier quoted context omitted.

My super cynical view is that the whole genre of "quantum safe" cryptography is being promoted to try and encourage adoption of weak encryption... Its felt like FUD based on FUD for a while. Not that I really trust traditional encryption that much either. There wouldn't be so much effort going into bridging air gapped systems if even traditional encryption could be trusted... Hate making cynical comments tho, they al…

Quantum safe crypto isn’t FUD, NIST’s steadfast refusal to specify a dual system, especially given their historical laundering of NSA back doors is super questionable, but there exist (at least one that I know of) crypto systems that have no exploitable bias. The problem is the impractically large key sizes. Afaict a lot of pqc work is trying to reduce the key sizes to something reasonable.

NIST/FIPS allows HMAC(salt, key) where salt can be anything, so a dual system is trivial: HMAC(PQ secret, conventional secret).

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#59
post #10

You KNOW they first had to do this in the normal way (large scale, distributed servers)..... and cracked it in like a second. Then for grins, the engineer HAD to say "I wonder if I could do this on my old Mac mini". And it worked. And for embarrassment of the original design, the story, and clickbait... they did it on that old machine

Mathematicians do not have funding for „large scale“. A 10-year old mid-range server is exactly the kind of system I would expect Magma to run on in the average case. Perhaps even just a desktop pc.

Source: worked with algebra researchers using Magma.

Re: “Quantum-Safe” Crypto Hacked by 10-Year-Old PC

#60
I think the beginning of the title lead me to believe it would say "10-Year-Old Kid" as I was hoping for some sort of "emperor has no clothes" situation, or brilliant amateur insight.

Yet I still think there's a good "look beyond your strengths" lesson here.

Post reply on HN