← Back to context

Comment by jMyles

5 hours ago

That's the opposite of what my gut is telling me.

Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.

Surely we can all agree that there's no way to reverse a modulus.

The risk isn't about reversing the hash, it's about finding a hash collision. If the hash is the only reference to your public key on chain, one does not need to reverse the hash, they just need produce a key pair who's public hash collides.

Currently that's a large brute force problem. But my gut is telling me is that finding a forward pass method of restraining private key generation such that we know what kind of public key hash to expect at the end, should be easier than cracking elliptic curves.

I guess depending on your outlook some might view that as "reversing" a hash, but it's not like you are getting the original input which is a impossible problem (unless there is a bunch of info you already know about the input).

I think I agree with you in spirit but I don't think "there's no way to reverse a modulus" is the right way to say this. Like that's in a sense what Coppersmith does? (Several attacks on RSA can be thought of as in some way "reversing a modulus").