Now that doesn't mean the NSA hasn't fiddled with C25519, but I'd be surprised if they mind-controlled (or extorted) Bernstein into publishing a compromised curve.
Now that doesn't mean the NSA hasn't fiddled with C25519, but I'd be surprised if they mind-controlled (or extorted) Bernstein into publishing a compromised curve.
(The NIST P-curves aren't backdoored.)
Unfortunately, we have no way to validate that the NSA did not grind the "seed" used to generate their parameters to search for curves which were strong or weak against some publicly unknown property which is only found in candidate curves at a one in a billion level.
This is a weakness in the methodology used to pick the parameters, somewhat lovingly mocked by the BADA55 curves: https://bada55.cr.yp.to/vr.html
It's not unreasonable for people to be concerned about this. Injecting intentional weaknesses into cryptosystems used by others was a fundamental objective for the NSA, which drove programs as significant as the CIA literally purchasing the at-the-time world largest manufacturer of encipher machines in order to ensure that it continued ship NSA designed intentionally weakened systems for decades ( https://www.washingtonpost.com/graphics/2020/world/national-... ). That was, of course, somewhat before the establishment of the relevant ECC standards-- but the cloud of operational secrecy prevents us from knowing that much about what NSA has been up to more recently.
The curve used in Bitcoin though isn't a NIST curve, and its generation procedure is about as close as you can get to rigid parameters without having rigid parameters as an explicit design goal.
a=0 (required for the endomorphism), field is 3 mod 4 for fast sqrt, increment field from 2^256-2^32-1024 (fast limb structure) until you find a prime field with a non-trivial cube root of unity (required for endomorphism) and until you can obtain a curve with prime order, set B to the lowest value that does. The result of that procedure is secp256k1. (you can actually drop some of the requirements above and still get the same parameters too, but I am pretty confident that this was their search criteria) -- so no high entropy "random" inputs.
I'd like to think we might be on the same page about Schneier and curves.
Agreed.
As I think we're both agreeing that it's a subject where well informed people could have a reasonable debate and disagreement, if you've got a reasonable link you'd suggest for the perspective you've taken it would be helpful to provide it (I provided the BADA55 curve page for that purpose)! (I could suggest one, but I'd prefer one you like!)
That's what I did, Bernstein could be compromised.
> He's not Satoshi.
I sat on a panel with him at an Arm conference, he's a great guy and easy to talk to and doesn't write anything like Satoshi: but I could care less if he is Satoshi. FWIW, I, too, think crypto currency is a huge scam.
How can you assert this?
Can you explain the coefficient choices?