Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…
> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…
NIST Elliptic Curves Seeds Bounty
31–40 of 102 posts
Re: NIST Elliptic Curves Seeds Bounty
#32Re: NIST Elliptic Curves Seeds Bounty
#33Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…
> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…
If you're convinced the P-curves must be backdoored, despite the computer science arguments that suggests they really couldn't have been, then you should comfort yourself in the knowledge that we're probably not going to find the seed strings any time soon; presumably Solinas tried pretty hard himself!
Re: NIST Elliptic Curves Seeds Bounty
#34Earlier quoted context omitted.
> if anyone does find them, that'll be a pretty devastating blow to the theory that the NIST P-curves were maliciously generated IDK, if I don't think that finding that a seed matches a hash of "Give Jerry a raise of $100000 dollars now!!!" is any evidence for that, because if I had a desire to generate malicious constants, and knew some unusual property that they must have to be weak, then nothing would prevent me f…
At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore. I think everybody sort of understands that people who don't work in cryptography are always going to have further layers of theory to add, the same way people waiting for the "Mother of All Short Squeezes" do with Direct Share Registration and…
Re: NIST Elliptic Curves Seeds Bounty
#35Earlier quoted context omitted.
At the point where we find an intelligible English string that generates the NIST P-curve seeds, nobody serious is going to take the seed provenance concerns seriously anymore. I think everybody sort of understands that people who don't work in cryptography are always going to have further layers of theory to add, the same way people waiting for the "Mother of All Short Squeezes" do with Direct Share Registration and…
I might be suspicious of “Give Jerry a $3263958374 raise,” but that would launch an interesting hunt as to what property they were exactly mining for.
Re: NIST Elliptic Curves Seeds Bounty
#36Re: NIST Elliptic Curves Seeds Bounty
#37Earlier quoted context omitted.
I might be suspicious of “Give Jerry a $3263958374 raise,” but that would launch an interesting hunt as to what property they were exactly mining for.
For the reason stated in the article, it's actually pretty likely that there's a counter in there somewhere. A 31-bit number like "3263958374" doesn't seem especially interesting cryptographically.
If you were evil and motivated you'd probably want to hide your variables in the innocent looking part, the simple English or the punctuation, instead.
Re: NIST Elliptic Curves Seeds Bounty
#38Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…
a true conspiracist doesn't believe everything he hears
Re: NIST Elliptic Curves Seeds Bounty
#39Earlier quoted context omitted.
What do you if pi doesn't create a nice curve?
You come up with a hopefully simple rule to try again. Like skip the first byte and try again. Assuming that you publish your definition of "a nice curve" then third parties can verify that you used the first offset in pi that worked.
Re: NIST Elliptic Curves Seeds Bounty
#40Some of the backstory here (it's the funniest fucking backstory ever): it's lately been circulating --- though I think this may have been somewhat common knowledge among practitioners, though definitely not to me --- that the "random" seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string "Give Jerry a raise". At the time, the "pass a strin…