(in zero knowledge)
#realworldcrypto
-
-
Q: In the MPC it's broken into two parts, what prevents a malicious input in the second part? A: This will be caught later on in the protocol in the proof stage this will be caught, the two parties commit to their shares beforehand
#realworldcryptoPrikaži ovu nit -
-
Next up is the first symmetric crypto session, starting with Attacks only get better: The case of OCB2 by Tetsu Iwata
#realworldcryptoPrikaži ovu nit -
Prikaži ovu nit
-
-
No authenticity, allowing the ciphertext to be manipulated.
#REALWORLDCRYPTOpic.twitter.com/XwbeF4CX1L
Prikaži ovu nit -
Nonce changes for every* encryption operation *except when it doesn't , like when you ask the user to provide a nonce
#REALWORLDCRYPTOpic.twitter.com/twmxJ4qxUj
Prikaži ovu nit -
GCM, CCM are NIST-certified IETF ones include GCM, ChaCha20-Poly1305 CAESAR includes 6 more Some more in the ongoing NIST lightweight crypto competition
#realworldcryptoPrikaži ovu nit -
OCB includes 3 versions, nonce-based AE with AD with strong features, including proof of security
#realworldcryptopic.twitter.com/hZ9D7HyKXF
Prikaži ovu nit -
-
Result: authenticity attack on OCB2, not related to the underlying block cipher.
#realworldcryptopic.twitter.com/nRbwCXsRyi
Prikaži ovu nit -
> SJCL affected Free corgi pix to someone who collects metrics on real world usage of the SJCL in the wild.
#realworldcryptoPrikaži ovu nit -
If we encrypt the same message twice, the nonce will* be different and the ciphertext will be different. * CAVEAT EMPTOR
#realworldcryptoPrikaži ovu nit -
-
Simplest attack is a minimal forgery (existential forgery), adversary must know content of the message, it might not be that important but it's still not generated by the original sender.
#realworldcryptopic.twitter.com/X1ibibpXF3
Prikaži ovu nit -
On its own may not mean much, but can be leveraged into more powerful attacks.
#realworldcryptoPrikaži ovu nit -
Universal forgery: for any nonce and message (possibly chosen by the adversary), can compute ciphertext and tag that will be accepted as legit
#realworldcryptoPrikaži ovu nit
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
crypto as in 'cryptography'
operation is an elliptic curve group operation)
