Live data from Hacker News

“This destroys the RSA cryptosystem”

eprint.iacr.org

151–152 of 152 posts

Re: “This destroys the RSA cryptosystem”

#151
post #55

It looks like someone read the paper and came to the conclusion that this shortens the expected lifespan of RSA and submitted the paper to IACR. I doubt it was Schnorr himself who decided to make the sensationalist claim. The final theorem in the paper is where the polynomial time claim is states. Can't quote it here because it would make no sense in isolation, but the math is readable and the claims should be indepe…

If you've been following Schnorr's work, his pathway for the last decade can be summed up as thus:

* 2011, retires from work at RSA foundation

* 2015, publishes first version of this paper, stating, "This is a WIP".

* 2017, 2018, 2019: Publishes updates of this paper, still stating "This is a WIP". Paper mostly ignorred.

* 2021: Publishes this final update. Removes "WIP" marking. Adds sentence (verifiable in original paper), "This destroys RSA cryptosystems".

Whether or not it's true, the level of dismissal here is kinda insane. This guy has credibility up the wazoo. The paper is dense and beyond my understanding. But this guy ain't some crackpot, this isn't some out-of-nowhere change: He's been clear about his intent and goals for nearly a decade, and now he says it's achieved.

Re: “This destroys the RSA cryptosystem”

#152

Earlier quoted context omitted.

Again, no matter how secure you make the cryptography, the weakpoint is the key. Why would someone "tweak" a key, provide it to a "big commercial company" (who for some reason doesn't generate their own key?), instead of just keeping a copy of the key?

> Why would someone "tweak" a key To make it look, at least to outsiders (be that users or researchers) like you are providing actually strong crypto. Leaking a key might not be as trivial as some people would imagine, with proper security policies in place. You are indeed right, in that the key is usually the weak point. But there are several ways in which that can be true, with rather different consequences. If a p…

With proper security policies in place, creating a flawed key would also "not be as trivial as some people would imagine". The issue which you claimed is that one can not determine whether or not the other party is following proper security policies - which is true no matter what.
Post reply on HN