<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1f2v97kt6qhpp6eey57fvtf8yw29rh02nz6rc4zvt2306l6s9nl9swsvzp8.rss" />
  <link href="https://nostr.ae/npub1f2v97kt6qhpp6eey57fvtf8yw29rh02nz6rc4zvt2306l6s9nl9swsvzp8" />
  <id>https://nostr.ae/npub1f2v97kt6qhpp6eey57fvtf8yw29rh02nz6rc4zvt2306l6s9nl9swsvzp8</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsdu59sc5llfw5yu0agk34q8fahhv7j9k9tc78djaw7y4pns69zcqgzyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0uklfns58</id>
    
      <title type="html">📅 Original date posted:2018-01-18 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdu59sc5llfw5yu0agk34q8fahhv7j9k9tc78djaw7y4pns69zcqgzyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0uklfns58" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd8r2e57gjcl3r53p4mpxcs332fy2kzzc58r43cajzqeq6700rl5sx34aa7&#39;&gt;nevent1q…4aa7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2018-01-18&lt;br/&gt;📝 Original message:&amp;gt; If being secure against partial share leakage is really part of your&lt;br/&gt;&amp;gt; threat model the current proposal is gratuitously insecure against it.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t think that is true. Shared secret is an input of KDF which&lt;br/&gt;should prevent this kind of attack.&lt;br/&gt;&lt;br/&gt;&amp;gt; If partial share disclosure were an actual concern, I would recommend&lt;br/&gt;&amp;gt; that after sharing and before encoding for transmission (e.g. before&lt;br/&gt;&amp;gt; applying check values and word encoding to the share) the individual&lt;br/&gt;&amp;gt; shares be passed through a large block unkeyed cryptographic&lt;br/&gt;&amp;gt; permutation.  Under reasonable-ish assumptions about the difficulty of&lt;br/&gt;&amp;gt; inverting the permutation with partial knowledge, this transformation&lt;br/&gt;&amp;gt; would prevent attacks from leaks of partial share information.&lt;br/&gt;&lt;br/&gt;Actually, we&amp;#39;ve been considering something like that. We concluded that&lt;br/&gt;it is to much &amp;#34;rolling your own crypto&amp;#34;. Instead of diffusion layer we&lt;br/&gt;decided to apply KDF on the shared secret.
    </content>
    <updated>2023-06-07T18:09:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx6dcse8q0400ttm8k8p94rtyc5prfmyz3yh9tw4n9lzul6g924jszyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0ukrn6ddm</id>
    
      <title type="html">📅 Original date posted:2018-01-22 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx6dcse8q0400ttm8k8p94rtyc5prfmyz3yh9tw4n9lzul6g924jszyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0ukrn6ddm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsramn9uz29fgj8zxuvl2qj4vhxaxv23rtpmytmn28fw24sh5j593c3suazu&#39;&gt;nevent1q…uazu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2018-01-22&lt;br/&gt;📝 Original message:&amp;gt; &lt;br/&gt;&amp;gt; My post provided a concrete example. I&amp;#39;d be happy to answer any&lt;br/&gt;&amp;gt; questions about it, but otherwise I&amp;#39;m not sure how to make it more&lt;br/&gt;&amp;gt; clear.&lt;br/&gt;&lt;br/&gt;My apologies, I didn&amp;#39;t read it carefully. You are absolutely right. Our&lt;br/&gt;scheme doesn&amp;#39;t protect against the scenario.&lt;br/&gt;&lt;br/&gt;&amp;gt; Quite the opposite-- a large block cipher is a standard&lt;br/&gt;&amp;gt; construction&lt;br/&gt;&lt;br/&gt;I&amp;#39;m happy to hear it. Nevertheless, I didn&amp;#39;t find any standartisation or&lt;br/&gt;implementation of the CMC mode (excluding the paper).&lt;br/&gt;&lt;br/&gt;Do you have some experience with other modes (such as HCTR, HEH)?
    </content>
    <updated>2023-06-07T18:09:34Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsglnazdrz5p7fz3uwchla94w53dcjqnn8kvcs6q4w2lph8ay65crszyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0ukpeq7sg</id>
    
      <title type="html">📅 Original date posted:2018-01-18 📝 Original message:Thank ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsglnazdrz5p7fz3uwchla94w53dcjqnn8kvcs6q4w2lph8ay65crszyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0ukpeq7sg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqvxxj7qe6r6e8e9r4kpgw9f9ghrmv523nvcfc04k2ula0haz3g0sfst04l&#39;&gt;nevent1q…t04l&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2018-01-18&lt;br/&gt;📝 Original message:Thank you for your comments, Gregory and Russell!&lt;br/&gt;&lt;br/&gt;Gregory, thank you for you explanation of perfect secrecy, there is no&lt;br/&gt;need for that, however. I&amp;#39;m professional mathematician and cryptographer.&lt;br/&gt;&lt;br/&gt;&amp;gt; I read the above&lt;br/&gt;&amp;gt; as &amp;#34;these are similar because they are based on math&amp;#34;...&lt;br/&gt;They are based on algebra (group and commutative ring theory), which is&lt;br/&gt;a great similarity. RSA and SHA, for example, are based on completely&lt;br/&gt;distinct parts of mathematics.&lt;br/&gt;&lt;br/&gt;&amp;gt; Complicated does not mean secure. And from an information theoretic&lt;br/&gt;&amp;gt; perspective the hash does almost nothing (other then some small&lt;br/&gt;&amp;gt; destruction of entropy due to its lack of perfect uniformity which is&lt;br/&gt;&amp;gt; information theoretically equivalent to using a smaller perfect code).&lt;br/&gt;&amp;gt; using error correcting codes and truncated hash functions create&lt;br/&gt;identical amounts of information theoretic redundancy&lt;br/&gt;I agree, see my last note in the previous mail. Adding redundancy by a&lt;br/&gt;hash function is more secure than adding redundancy by a linear&lt;br/&gt;relations. Just my opinion.&lt;br/&gt;&lt;br/&gt;I see the difference between RSA and SSS you mentioned and I understand&lt;br/&gt;your arguments about perfect secrecy. Just two comments:&lt;br/&gt;  (1) Our proposal doesn&amp;#39;t use SSS for the whole secret, but it divides&lt;br/&gt;the secret into bytes and uses SSS for every byte separately. This&lt;br/&gt;scheme is weaker because to reconstruct n-th byte it suffices to have&lt;br/&gt;n-th bytes from k shares.&lt;br/&gt;  (2) SSS is information-theoretic secure if you know k-1 or less&lt;br/&gt;shares, where k is the threshold. But the proof doesn&amp;#39;t hold if you know&lt;br/&gt;for example a small part of every share.&lt;br/&gt;&lt;br/&gt;&amp;gt; It is of no use to apply the precautionary principle against&lt;br/&gt;impossible attacks, especially at the cost of losing the useful&lt;br/&gt;properties of a real error correcting codes that would provide actual&lt;br/&gt;guarantees against likely errors.&lt;br/&gt;The discussion isn&amp;#39;t about mathematics or about security proofs but&lt;br/&gt;about cryptographic scheme design. In our use case you cannot assume&lt;br/&gt;that all premises of security proof theorems (including SSS&amp;#39;s perfect&lt;br/&gt;secrecy) hold true (see the comment above).&lt;br/&gt;&lt;br/&gt;In my opinion, to make a cryptographic scheme more robust it&amp;#39;s better to&lt;br/&gt;stick to general &amp;#34;intuitive&amp;#34; principles. Of course you have to consider&lt;br/&gt;the advantages and disadvantages of this approach. That&amp;#39;s why we&lt;br/&gt;disclosed our draft and welcome all comments.&lt;br/&gt;&lt;br/&gt;&amp;gt; The discussion of using a proper code was primarily related to the&lt;br/&gt;&amp;gt; outer check value which protects the shares themselves and is sitting&lt;br/&gt;&amp;gt; unprotected in plaintext&lt;br/&gt;OK then. I was defending the hash in the inner check value.
    </content>
    <updated>2023-06-07T18:09:33Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9qagkvt835ddskg6udcvmyc7uacrxqu065v9s7mrhuch8jwuawmczyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0uk2c055k</id>
    
      <title type="html">📅 Original date posted:2018-01-17 📝 Original message:The ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9qagkvt835ddskg6udcvmyc7uacrxqu065v9s7mrhuch8jwuawmczyp9fsh6e0gzuy8t8yjne93dyu3eg5waa2vtg0z5f3d29ltl2qk0uk2c055k" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspwq8wqw0hdc3c6hp25qfml3l3662cg9cm8f5wra889q78h9u3vpc8apqfs&#39;&gt;nevent1q…pqfs&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2018-01-17&lt;br/&gt;📝 Original message:The entropy argument is as follows:&lt;br/&gt;&lt;br/&gt;There is a rule of thumb which says it is safer plaintext to have low&lt;br/&gt;redundancy, see&lt;br/&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Redundancy_(information_theory)&#34;&gt;https://en.wikipedia.org/wiki/Redundancy_(information_theory)&lt;/a&gt;, i. e.&lt;br/&gt;it&amp;#39;s better to encrypt random or compressed data than natural language.&lt;br/&gt;This rule is based on Shannon&amp;#39;s information theory which means that a&lt;br/&gt;breach of the rule usually doesn&amp;#39;t induce a vulnerability (there is no&lt;br/&gt;known generic attack). This rule is application of a precautionary&lt;br/&gt;principle.&lt;br/&gt;&lt;br/&gt;Nevertheless, here are some examples of cryptographic attacks which may&lt;br/&gt;be considered as a consequence of the breach of the rule:&lt;br/&gt;  * Related Message Attack by Coppersmith, Franklin, Patarin, Reiter&lt;br/&gt;(&lt;a href=&#34;https://pdfs.semanticscholar.org/899a/4fdc048102471875e24f7fecb3fb8998d754.pdf&#34;&gt;https://pdfs.semanticscholar.org/899a/4fdc048102471875e24f7fecb3fb8998d754.pdf&lt;/a&gt;)&lt;br/&gt;- given RSA ciphertext of two plaintexts x and a*x &#43; b, where a, b are&lt;br/&gt;known, it&amp;#39;s possible to effectively compute x provided public exponent&lt;br/&gt;is three. From the informaton-theoretic point of view the second message&lt;br/&gt;is redundant, because it&amp;#39;s determined by the first one. Which means that&lt;br/&gt;relative redundancy of both messages is at least one half.&lt;br/&gt;  * Stereotyped Messages by Coppersmith&lt;br/&gt;(&lt;a href=&#34;https://www.di.ens.fr/~fouque/ens-rennes/coppersmith.pdf&#34;&gt;https://www.di.ens.fr/~fouque/ens-rennes/coppersmith.pdf&lt;/a&gt;, section 7) -&lt;br/&gt;given RSA ciphertext and (1-1/e) fraction of plaintext (where e is&lt;br/&gt;public exponent), it&amp;#39;s possible to effectively compute x. Message is&lt;br/&gt;highly redundant, because only 1/e of the message is unknown. Relative&lt;br/&gt;redundancy of the message is at least (1-1/e).&lt;br/&gt;&lt;br/&gt;Consider a few notes:&lt;br/&gt;  * Nowadays there exists more complicated variants of mentioned attacks&lt;br/&gt;which have weaker premisses.&lt;br/&gt;  * There is a considerable similarity between RSA and SSS. Both schemes&lt;br/&gt;are algebraically-based (rather than boolean function based).&lt;br/&gt;  * CRCs (and error-correcting codes generally) introduce redundancy&lt;br/&gt;into the message. Moreover the redundancy is induced by a linear&lt;br/&gt;relationship among message (compare with the premise of the Related&lt;br/&gt;Message Attack).&lt;br/&gt;  * Related Message Attack wouldn&amp;#39;t be possible if you had two&lt;br/&gt;plaintexts x and hash(x). The relationship between messages has to be&lt;br/&gt;(algebraically) uncomplicated. From the information-theoretic point of&lt;br/&gt;view the situation is the same, but from the practical point of view it&lt;br/&gt;is completely different.&lt;br/&gt;&lt;br/&gt;To sum it up, there is a precautionary principle which tells us not to&lt;br/&gt;increase redundancy of a message unless it is introduced in a&lt;br/&gt;complicated way (for example by a hash function). That&amp;#39;s why we use SHA&lt;br/&gt;rather than CRC. One more reason why we stick to the principle is that&lt;br/&gt;there&amp;#39;s no randomisation in our scheme (such as padding or&lt;br/&gt;initialisation vector). We understood advantages of error-correctings&lt;br/&gt;codes over hash functions (minimal codewords distance property,&lt;br/&gt;performance) and we considered it thoroughly.&lt;br/&gt;&lt;br/&gt;Ondřej Vejpustek
    </content>
    <updated>2023-06-07T18:09:31Z</updated>
  </entry>

</feed>