216 karma · joined March 24, 2012
A critical example is database search: searching through a database on n elements is normally done in O(log n), but it becomes O(n) when the search key is encrypted. This means that fully homomorphic Google search is fundamentally impractical, although the same cannot be said of fully homomorphic DNN inference.
Another point that the author glosses over a bit is that higher dimensional abelian varieties offer other instances of DH that are genuinely different from ECDH, and that are occasionally useful (mostly the case of Jacobians of hyperelliptic curves of genus 2). There isn't really a trick to make an arbitrary hyperelliptic curve DH/abelian variety DH instance a special case of ECDH: if anything, the relationship would be in the reverse direction.
The steganography stuff is the only actually novel contribution of the Elligator paper.
The moral "justification" of the definition is something like "algebraic geometry is precisely the study of such objects" or "we want definitions that are stable under ring base change, and this implies polynomials", etc., but we don't formally need to justify definitions.
[One could take a different route to defining those things, in which this becomes a theorem instead of a definition. For example one can define algebraic curves over a field k as contravariant functors from k-algebras to sets satisfying certain additional properties, and then maps of algebraic curves are natural transformations between those functors. The fact that they are given by polynomial equations is then a theorem. Just stating the "additional properties" for a curve is a rather daunting task, though, unfortunately.]
(The situation is different for pairing-friendly elliptic curves, of course, but that's a different kettle of fish).
For example, "expressing support for acts of terror" is an imprisonable offense, and it has been interpreted incredibly broadly by the courts, to the point that drunk people have been sent to prison for years over tasteless jokes. Similarly, simply browsing websites that are deemed in support of terrorism: a man from Chartres recently received a two-year sentence for the latter.
It's fair to say that the current climate is pretty Orwellian. But if you're not a brown person or a Muslim, you're not what prosecutors are after.
That's completely baffling to me so I'd be really curious to hear your reasons (or those of someone who shares that opinion, as there are others in the thread apparently).
When learning about an abstract notion, it has been my experience that having good examples in mind (in the sense that they are not too complex, but non-trivial enough to illustrate the relevant aspect of the notion at hand) is very helpful, if not essential, for comprehension. All the more so for very abstract subjects (e.g. back in grad school I was studying algebraic geometry, and you can't go very far in that subject trying to prove things about functors on the category of rings without examples in mind that connect the abstract nonsense to some actual geometric meaning).
Speaking of abstract nonsense, by the way, under the Curry-Howard isomorphism, publishing a library with type signatures but no worked out example is equivalent to publishing a mathematical paper consisting entirely of lemmas with no example of how to combine them to prove something interesting (in fact, it's worse, because the expressiveness of the Haskell type system obviously pales in comparison to the language of mathematical papers). I would almost certainly reject a paper like that if I received one for review, and I expect most referees would too.
On the other hand, what they are not is "unbiased" or "neutral". They are quite vocal about their political views. On most issues their stance is usually around the leftmost end of the French MSM Overton window, if that means anything. I happen to disagree with quite a few of these views, but I have a lot of respect both for their journalistic integrity and for the role they play within the French media.
This is also not true. It's usually journal editors who find reviewers. This is mostly unpaid work as well (publishers tend to chip in a bit for editorial board meetings, but that's about it).
Scientific publishers provide very, very little value to the scientific community. The reason why researchers want to publish in Journal X is that it has a good reputation, which is mostly a function of the editorial board's quality standards, and even more so, of Journal X's past publications (often dating back to way before Elsevier or whoever else actually acquired it).
Is that what he will be known as from now on? :)
On a more serious note, it's interesting to reread his poem _America_, which was certainly written more as an aspiration than a description at the time. However, this election makes you wonder whether the aspiration is even there anymore (from either side, if we're being honest).
| Centre of equal daughters, equal sons, | All, all alike endear’d, grown, ungrown, young or old, | Strong, ample, fair, enduring, capable, rich, | Perennial with the Earth, with Freedom, Law and Love, | A grand, sane, towering, seated Mother, | Chair’d in the adamant of Time.
With homomorphic encryption, Alice can send some secret data to Bob in encrypted form, and let Bob carry out computation on that encrypted data. However, the result of the computation remains encrypted, and only Alice's private key can decrypt the result.
By contrast, obfuscation allows Alice to give Bob a program that contains some secret information (such as cryptographic keys) in such a way that Bob can run it (without any further interaction with Alice) on any inputs of his choice, and get the result in the clear. However, he cannot learn anything about the hidden secret information other than what is revealed by the input-output pairs he has obtained.
It's not hard to see that obfuscation gives you homomorphic encryption for free (you can probably get a rough idea of how to do it based on the somewhat imprecise descriptions above), but we don't know how to go in the other direction. (Current obfuscation candidates do use fully homomorphic encryption under the hood, but they need to rely on much more than that).
This is a rapidly evolving field, though, so I'm cautiously hopeful that some genuinely novel ideas will emerge soon to overcome the current stumbling blocks.
We very often do. These days, though, cofactors of 2, 3, 4 or perhaps 8 are getting more common because people like to use curves with more efficient/easier to implement arithmetic (such as Montgomery curves or Edwards curves), and those curves always have nontrivial points of small order.
This doesn't really explain why older cryptographic standards mandating Weierstrass curves allow cofactors greater than 1, admittedly. The reason is probably that generating good elliptic curve parameters back then was very time-consuming, and so it may have made sense to allow people to stop when they hit a curve with almost-but-not-quite prime order.
Unrelatedly, a couple of errors in the OP:
* "in fact, these equations work in every field, finite or infinite (with the exception of \mathbb{F}_2 and \mathbb{F}_3, which are special cased)": all fields of characteristic 2 or 3 are special cases. There are many more than just those two, including infinite fields.
* "RSA’s discrete logarithm problem can be stated as follows: if we know a and b, what’s k such that b = a^k mod p?": RSA and discrete logs don't have much to do with each other. Perhaps you meant DSA? (not sure I would call the finite field DLP "DSA's DLP", though).
That's only one example for sure, and things may have been a bit different after Philippe Val left, but I don't think it's fair to say that Charlie was even-handed in the way it targeted its gushes of vitriol, and even less so that they were principled champions of freedom of speech. Like most French people across the whole political spectrum, they were stauch supporters of speech-they-agree-with.
None of this detracts from the horror of what has happened of course. I just thought I would mention that the popular "uncompromising beacon of freedom" narrative might be a bit too simplistic.
The situation is a bit different in the presence of point compression, in which case you're typically concerned with twist security, but the security of the NIST P-256 quadratic twist is pretty decent, so again this isn't a strong argument against it.
The two good reasons to choose something like Curve25519 over NIST P-256 are 1/ speed and 2/ the fact that it's somewhat simpler to obtain side-channel protected implementations. For SSH key exchange, it's pretty much a wash for most realistic settings (only a server that spends significant CPU time simply establishing SSH connections would care about the performance difference here).
Similarly, a majority of respondents of the Japanese General Social Survey think that "in case the husband's income is sufficient, it is better for the wife not to work". But economic realities make such lifestyle choices difficult. For example, when asked what level of household income would be sufficient for them to consider getting married, a plurality of Japanese women cite a figure of around ¥500k net per month [1], which is around the limit of the top quartile of household incomes, and way above what unmarried men typically make on their own.
As for (3), I'm not particularly interested in debating whether "Japan is a racist country", but getting Japanese citizenship is far from being impossible. In fact, the rejection rate of formally submitted naturalization applications is about 1% (consistent over at least the past decade, see e.g. [2]).
[0]: http://www2.ttcn.ne.jp/honkawa/2410.html [1]: http://jgss.daishodai.ac.jp/english/research/monographs/jgss... [2]: http://www.turning-japanese.info/2012/05/10-years-of-natural...
But careful approaches like RFC 6979 are very important for curves over random fields, like the Brainpool parameters.
[By the way, a more regular contributor of this site suggested that it would be appropriate for me to mention that I'm one of the authors of the OP.]
So RFC 6979 is fine, but k=HMAC-SHA-256(x,m) is not a secure choice for 256-bit elliptic curves over random base fields.