← Back to context

Comment by notnullorvoid

3 hours ago

My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.

The point is they have less algebraic structure than things like elliptic curves. If you want "math resistant" properties, this is a good thing.

> My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.

Aren't hashes far less reliant on math tricks?

My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.

  • Yes. Symmetric cryptography doesn't generally rely on the existence of "trap doors", so there's no direct relationship in any sense between the inputs and the outputs. Huge portions of the cryptographic attack surface are foreclosed in these constructions.

That's the opposite of what my gut is telling me.

Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.

Surely we can all agree that there's no way to reverse a modulus.

  • I think I agree with you in spirit but I don't think "there's no way to reverse a modulus" is the right way to say this. Like that's in a sense what Coppersmith does? (Several attacks on RSA can be thought of as in some way "reversing a modulus").