Boring Crypto (2015) [pdf]
cr.yp.to
cr.yp.to
But this isn't some C library; cryptography is intrinsically adversarial. And attackers outnumber defenders; you can make more money by breaking a cypher than by inventing one. Cracking libboring would be a major prize.
And I imagine libboring is never going to happen. There will always be new, unexpected attack channels. For example, I'd never have guessed (in advance) that instruction timing would be a viable way to attack a cypher.
But the primitives it offers are the same primitives offered by other kits; those are not immune to 'excitement' issues.
"Boring Crypto" as an ethos/concept that djb is invoking in these slides is indeed not related to this.
[0]: https://csrc.nist.gov/projects/cryptographic-module-validati...
Examples:
https://groups.google.com/forum/message/raw?msg=sci.crypt.re...
https://groups.google.com/forum/message/raw?msg=sci.crypt/FG...
The weird thing about the field of cryptography is this is not accepted, and is basically taboo: that the strongest designs are classified and the unclassified ones deliberately weakened.
It's this weird suspension of disbelief / faith in security that has been carefully created by the cryptanalysis actors, so that the public designs are breakable by the ones who hold the classified designs.
Those constructs are very likely to be safe.
It isn't enough, in my opinion, to just have mathematical proofs of safety because reading and understanding those proofs demands trust in an authority on them. To get the knowledge necessary to, without a doubt, verify the proof is not commonly accessible.
But people can hold a cryptocurrency for years and say "well, it's still there and spendable". It is an easy, easy target were that not the case. The Satoshi stash is a honeypot for when things break. Countless lost wallets are the honeypot for when things break. This is easy to audit and verify.
Then, we can know more expansive privacy crypto is functional based upon its availability to turn into USD. Can you turn Monero into USD on any regulated exchanges? You cannot. Because it protects your privacy. Can you store value in Monero long term? You can. This means it is very likely that the slew of crypto constructs involved in protecting privacy are functional, and that the crypto involved with creating, storing, and transferring value is functional.
Cryptocurrencies act as a real world validation mechanism for the active security auditing of these constructs. I would be hard pressed to use any crypto not used by a cryptocurrency with a market cap of at least $1 billion.
Maybe. Or maybe if enough of the right people are affected like the DAO hack, it will just get reversed.
Most DAO “hacks” fall into 3 classes 1. Poorly written contracts. There’s no accounting for bad programming 2. Malicious members who made back doors for themselves 3. Regular old social engineering attacks
Almost never is the fundamental blockchain technology exploited. If you could, you’d just take the billions in satoshi’s wallet and call it a day.
If you are a state actor trying to discredit or destroy cryptocurrencies, taking Satoshi's stash is the clear strategic target. You can simultaneously tank the value of the currency while also not exposing your method of breaking the crypto by taking his stash.
The fact that his stash remains is the clearest signal the crypto is not broken -- and the methods to create his wallet are the oldest / original ones when it comes to cryptocurrencies. A state-level actor would have absolutely moved his stash to easily create panic and remove competition against fiat currencies.
If a state actor can't do it, I highly doubt any other actor could. If some no-name independent researcher somehow figures out an exploit, then yes, it would be foolish to move Satoshi's stash. Better to target "dead" addresses that no one cares much about and won't have an impact -- these are wallets of people that have lost their keys who are not celebrities, so they wouldn't get any attention on them. You could take those funds and move them quietly so that you could make money.
Extremely unlikely possibility for a number of reasons, but anything is possible.
That said, I find that possibility highly unlikely. Cryptocurrencies are a direct and powerful threat to all existing power structures. If for example they were a material country, the west would have been at war with that country and would have dismantled them already long before they entered public discourse or understanding. They are a threat of that scale to banking and traditional power. They are more dangerous than terrorists, more dangerous than even nukes I would argue, so if you could control them / discredit them / invalidate them, even if it meant exposing some secret crypto vulnerabilities, you absolutely would.
That is to say, if you could break it you simply would, which would then crush the mechanism and they would no longer be an existential threat to traditional structures.
"established facts" supporting your argument exist. Further evidence may not rise to that level of veracity but exists.
I think there's a general distaste for disagreement lately; especially when one is disagreeing with "authority"