Live data from Hacker News

NIST Elliptic Curves Seeds Bounty

words.filippo.io

31–40 of 102 posts

Re: NIST Elliptic Curves Seeds Bounty

#31
post #3

Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…

> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…

Yeah but Jerry wouldn't have been incentived to do such a thing, would he?

Re: NIST Elliptic Curves Seeds Bounty

#33
post #3

Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…

> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…

At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore. I think everybody sort of understands that people who don't work in cryptography are always going to have further layers of theory to add, the same way people waiting for the "Mother of All Short Squeezes" do with Direct Share Registration and share votes and stuff. If the bounty program is successful, that's going to end the NIST curve "debate", such as it is.

If you're convinced the P-curves must be backdoored, despite the computer science arguments that suggests they really couldn't have been, then you should comfort yourself in the knowledge that we're probably not going to find the seed strings any time soon; presumably Solinas tried pretty hard himself!

Re: NIST Elliptic Curves Seeds Bounty

#34
post #33

Earlier quoted context omitted.

> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…

At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore. I think everybody sort of understands that people who don't work in cryptography are always going to have further layers of theory to add, the same way people waiting for the "Mother of All Short Squeezes" do with Direct Share Registration and…

I might be suspicious of “Give Jerry a $3263958374 raise,” but that would launch an interesting hunt as to what property they were exactly mining for.

Re: NIST Elliptic Curves Seeds Bounty

#35
post #33

Earlier quoted context omitted.

At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore. I think everybody sort of understands that people who don't work in cryptography are always going to have further layers of theory to add, the same way people waiting for the "Mother of All Short Squeezes" do with Direct Share Registration and…

I might be suspicious of “Give Jerry a $3263958374 raise,” but that would launch an interesting hunt as to what property they were exactly mining for.

For the reason stated in the article, it's actually pretty likely that there's a counter in there somewhere. A 31-bit number like "3263958374" doesn't seem especially interesting cryptographically.

Re: NIST Elliptic Curves Seeds Bounty

#37
post #35

Earlier quoted context omitted.

I might be suspicious of “Give Jerry a $3263958374 raise,” but that would launch an interesting hunt as to what property they were exactly mining for.

For the reason stated in the article, it's actually pretty likely that there's a counter in there somewhere. A 31-bit number like "3263958374" doesn't seem especially interesting cryptographically.

The counter is described as the minimum value that will fit the pattern and make the result a prime. So that should be easily checkable and not really add any free variables.

If you were evil and motivated you'd probably want to hide your variables in the innocent looking part, the simple English or the punctuation, instead.

Re: NIST Elliptic Curves Seeds Bounty

#38
post #3

Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…

a true conspiracist doesn't believe everything he hears

That's not true

Re: NIST Elliptic Curves Seeds Bounty

#39

Earlier quoted context omitted.

What do you if pi doesn't create a nice curve?

You come up with a hopefully simple rule to try again. Like skip the first byte and try again. Assuming that you publish your definition of "a nice curve" then third parties can verify that you used the first offset in pi that worked.

You could however test different schemes like this prior to announcing the scheme.

Re: NIST Elliptic Curves Seeds Bounty

#40
post #3

Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…

He kind of “lost his bitcoin” before bitcoin was invented
Post reply on HN