Maybe I’m misreading, but they’re pulling straight out of SHA256 and then turning it into a scalar exponent in the range 1...groupOrder. If the order is prime that could be a problem.
-
-
If they actually ship this with 256 bit groups it’s not just broken, it’s catastrophically broken. You can decrypt and forge anything.
-
Change votes, collide Pedersen commitments, completely own the election. And if they don’t use properly-generated groups produced verifiable from a seed (as in FIPS 186) then there are other attacks a malicious election admin can pull off.
- Näytä vastaukset
Uusi keskustelu -
-
-
Thank you for your messages. There is a standard process to report observations. You can legally access the source code via http://www.post.ch/evoting-sourcecode …. You can then report your findings officially through GitLab. Swiss Post analyses all reported issues and gives feedback. (1/2)
Kiitos. Käytämme tätä aikajanasi parantamiseen. KumoaKumoa
-
-
-
You may have missed that q is 2047 bits wide in a productive environment, as stated in chapter 4.2.2 of the document Scytl sVote Protocol specifications. For testing purposes (unit tests), smaller values of p and q might be used. So the cryptography here is sound. ^lg (2/2)
-
How is it generated?
- Näytä vastaukset
Uusi keskustelu -
Lataaminen näyttää kestävän hetken.
Twitter saattaa olla ruuhkautunut tai ongelma on muuten hetkellinen. Yritä uudelleen tai käy Twitterin tilasivulla saadaksesi lisätietoja.