Why Did Satoshi Decide to Use Secp256k1 Instead of Secp256r1?
dappworks.com
dappworks.com
I don't think it is a good argument, I invite every one to take a look at the DES S-Box constants. Many people believed that those were backdoor constants that the NSA planted into the algorithm as there was no explanation on how and why they were chosen. Many years later it turned out that they were picked carefully to protect against differential-linear attacks. An attack only the NSA knew back then. So they gave out safe S-Box constants, and all those who distrusted them and picked random/other S-Boxes were actually screwed, this is really ironic.
The bit about choosing parameters suggests that the NSA didn’t have a benevolent reason to choose those parameters, and the evidence of that algorithm being exploited in the wild suggests that the NSA may have chosen their parameters with that exploit in mind.
The NSA has a track record of never putting out Cryptography that could be broken by any other actor than the NSA itself.
If the only obstacle for others is "unknown Math" - then surely you can rule the script kiddies out, but I believe there are quite some other clever people with strong Math background around, who do not work exclusively for the NSA.
> Presumably it would have been caught sooner had the hack required a backdoor to be hidden in the source code and not some bytes that looked like a magic constant.
Have you seen what real life bugdoors look like?
Obviously the NSA couldn’t get people to use such a standard but they managed to slip something like that into Dual_EC and had success in getting people to use it.
Instead they seemingly wanted to exploit anyone who didn’t use their constants, I guess?
From "SEC 2: Recommended Elliptic Curve Domain Parameters":
"... one type being parameters associated with a Koblitz curve and the other type being parameters chosen verifiably at random"
"Verifiably random parameters offer some additional conservative features. These parameters are chosen from a seed using SHA-1 as specified in ANSI X9.62 [X9.62]. This process ensures that the parameters cannot be predetermined."
Parameters generated this way are called "nothing up your sleeve" numbers.
Yesterday I texted my coworker a suggestion to dockerize his yocto build so that it would work better in vagrant on a lambda server in the cloud. It's borderline these days, but he realized I was being facetious. He retorted with a serious comment about 500 lines of typescript to run 5 lines of bash.
"aes" is better than "aes is the best!" which is better than "aes123884586314745"
This generally narrows down the options to something were relatively little trickery is possible: keep in mind that the eg. hashes used to break some encryption would have to be very specific so that the algorithm isn't trivially broken to begin with.
The more important part about nothing-up-my-sleeve is really the justification for choosing a particular hash/number. If, let's say your algorithm needs a prime with at least 10 digits and you pick the first prime with 10 digits nobody asks questions. If you picked the 16th, then people would ask questions.
Similarly, if you can pick any arbitrary ten digit number and you pick the first 10 digits of pi, nobody will ask questions. If you picked the million'th to million-and-tenth digit of pi people would asks questions.
"meaningful" has to be understood more as "from a pool of constants that leave little room for (mallicious) adjustment". The abstracter the number, the higher the potentially used searchspace.
In this case the article is so poorly researched that even though it says fairly little it manages to make outright false claims about basic facts, e.g. "secp256k1 is a Koblitz curve which is defined in a characteristic 2 finite field, while secp256r1 is a prime field curve"-- which is false, secp256k1 uses a prime field.
Really people can mostly just speculate on the subject, or offer why they might have chosen it: Satoshi never said much about his choice-- he certainly never said in public that he was concerned with NSA tampered parameters.
I think it was a good choice at the time, esp. now after the expiration of the GLV patent. And the fact that there is no opportunity for NSA tampering scaremongering is a nice feature, but that's my opinion and I have no reason to believe it was Satoshi's.
Or perhaps to rephrase, are there are any trustworthy sites covering similar topics?
k curve
a = 0
b = 7
r curve a = FFFFFFFF 00000001 00000000 00000000 00000000 FFFFFFFF FFFFFFFF FFFFFFFC
b = 5AC635D8 AA3A93E7 B3EBBD55 769886BC 651D06B0 CC53B0F6 3BCE3C3E 27D2604B
[1]https://www.johndcook.com/blog/2018/08/21/a-tale-of-two-elli...Other examples are the 'mystery padding' in keccak vs sha3.
To say something glows means to suggest the US three letter agencies are interfering with it. If some cryptography glows, it means it's been compromised by US authorities. Glowies are the operators themselves.
Source: am cryptographer
My main familiarity with it is from imageboard culture, where (mostly) reactionaries use it to accuse each other of being feds.
Given that "glows in the dark" typically refers to fluorescence[1], where does the interference comes in?
https://www.urbandictionary.com/define.php?term=Glows%20in%2...
Terry is/was an HN native, too.
Upvoting all of his shadowbanned stuff that was half-way decent and lucid was a hobby of mine. It still makes me feel good to think about it.
Godspeed Terry.
There are millions of sob stories. I don't do as much as I could, but I do more than nothing to help people out. That one, Terry Davis, keeps me up at night sometimes.
1: https://en.wikipedia.org/wiki/Dual_EC_DRBG
2: https://en.wikipedia.org/wiki/Nothing-up-my-sleeve_number
https://www.reddit.com/r/lastimages/comments/2obp6s/last_kno...
Later the phrase was seen on a t-shirt in a candid photo of a very attractive Japanese woman posted to engrish.com, and went viral.
Then 4chan picked it up.
And now it’s here.
Now whenever someone is suspected of being an intelligence agency operator, people reply with pictures of a literal glowing person. Usually happens when someone spreads FUD about technology that's believed to be secure. It is assumed that these agencies are running psychological operations in online communites with the intent to dissuade the use of technology that could defeat them.
After it’s controversial debut on 4chan, Davis’s unsupported claim of selective unexplained human photoluminescence quickly became a meme in imageboard culture. Since imageboard culture is intersectional with software development culture, the terms have worked their way into defacto terminology among a subset of developers that work on things often thought of as adversarial at times to state interests, encrypted chat and cryptocurrency being among these.
The term has bled out some and finds spotty support among other developers in tangential contact. The future of the term is uncertain, as it’s use remains largely isolated despite being canonical since 2017.
But I think that NSA-level organization knows who Satoshi is. It's hard to imagine how one would be able to work on such a project, without any background that could be tracked.
https://satoshi.nakamotoinstitute.org/posts/bitcointalk/541/
Provided you're disciplined enough to properly containerize all ongoing sessions, of course. Careful planning is all it takes.
So not Windows?
I'm willing to believe that, but probably not in the way you intended. Obviously the actual truth is unknowable so I am not trying to promote any Theories here and am not fond of anyone who does. However I am willing to entertain reasonably-grounded heterodox speculation and hope you all will indulge me with the same :)
One thing I find very interesting about Bitcoin is how most people seem to automatically assume Satoshi is an individual person due to bearing the name of an individual. I Know Myself well enough to admit how much I love a good underdog story about a smart person-like-myself who's upsetting the status quo, Sticking It To The Man, and/or Raging Against the Machine like Snowden. Doubly so when The Man is the monetary system that hurt my family so badly in the 2008 crash, so I Want To Believe in the (2008) Bitcoin origin story and giving power back to the people. Has it? I guess for a few.
As you mentioned, Tor and cryptocurrency usage go hand-in-hand for certain people and certain classes of transactions. Tor is an admitted creation of the US intelligence community, ostensibly for deployed agents as a sort of bidirectional modern-day Numbers Station. I have to ask myself if that intelligence community would allow the continued existence of such a thing if it came to be used in ways that harmed the USA's agendas. Maybe it would be worth it for them, but again it is unknowable: https://www.bloomberg.com/news/articles/2014-01-23/tor-anony... (http://archive.today/WR9X1)
I know the value proposition of Bitcoin et al for me an an individual, but lately I've been thinking about plausible ways cryptocurrency could simultaneously create incentives/outcomes benefiting others. Cryptocurrency mining sure has done a good job eliminating public availability of general-purpose computing resources since miners will find and exploit them. That kind of thing helps push us all into the open arms of the Tier-1 Internet gatekeepers like AWS and Cloudflare and away from a distributed network where all peers could be equal. Even Github Actions got bitten by this: https://www.bleepingcomputer.com/news/security/github-action...
Privately-owned general-purpose computing seems to be under attack as well. There's no emotion more motivating than fear, and the constant news about CryptoLocker-style ransonware attacks could help manufacture consent for "trusted" computing platforms à la M1 Macs and Windows 11, even among techies who would usually be vehemently against those kind of creeping restrictions. I guess it's an acceptable compromise if it Keeps Me Safe. There wouldn't even be a need for an intelligence community to get their hands dirty since the monetary incentive makes crypto malware inevitable.
What if an intelligence community wanted to buy up a bunch of parallel computing hardware supply (e.g. GPUs) for years without everybody questioning it? Even I don't think twice about blaming miners for the out of control pricing and availability, but I've been reading articles since like 2013 about how ASIC miners spell the end for profitable GPU Bitcoin mining. Aaaany day now would be great. I guess it's all those other coins. Again, unknowable.
I'll stop here since this is rambling and probably too close to Theory territory, but I've been thinking about my assumptions a lot lately and these are a few of them.
You have to remember how obscure it was initially, and it's not like it involved terrorism or obviously a thread to national security.
I'd like to get a grasp on this from first principles. Thank you!
But... I think you need a more coherent goal than just "understand the math." You can superficially understand the math when guided, but without any reason to retain it I am not sure what you will gain from the experience.
This has been my experience with almost everything I ever learned about math, much of which I have unfortunately not retained.
Secp256k1's base field size is a 256-bit prime. What does he mean?
> secp256k1 has characteristic p, it is defined over the prime field ℤp. Some other curves in common use have characteristic 2, and are defined over a binary Galois field GF(2^n), but secp256k1 is not one of them.
Isn't this enough?
G = 02 79BE667E F9DCBBAC 55A06295 CE870B07 029BFCDB 2DCE28D9 59F2815B 16F81798
Is this choice beneficial for efficiency?
If the choice of G doesn't matter, why not choose it as having the smallest possible x coordinate?Many applications use a second generator H, which must be an unknown multiple of G. This is achieved by defining it as essentially SHA256(G).