https://weakdh.org/ really cute shit
- INRIA Rocquencourt never signed off on this, that's where louis pouzin worked. note how the paper puts that first and marks it with a
*
- every fact that breathlessly took up the first 2.5 pages (and the last 2.5 pages) was known since hellman announced the attack himself and how to fix it by selecting an appropriate prime, something which requires no additional computational cost to do:
The new algorithm is least efficient when
p = 2p' + 1, wherep’is also prime.
this has not been broken
- the rest of it is just all TLS and IPSec vulnerabilities, all of which will of course remain true for all other protocols. a great way to "reset" the IETF's backdoor counter
- identifies NIST DSA as insecure--does not identify NIST as a problem despite literally spending another 2.5 pages screaming breathlessly about the NSA
this may have something to do with the johns hopkins and microsoft researchers listed. i have also literally never heard of these INRIA people before or even these INRIA sites before
(except Rocquencourt, which was fake and made up and had no representatives in the paper despite being the first location listed. and they didn't list microsoft in the pdf either)
- actively does incredibly wrong shit with asymptotic complexity:> Without better parameter choices, we resort to extrapolating from asymptotic complexity.
the parameter choices were prescribed in 1978, two years after diffie-hellman was published, but sure, let's do some asymptotic complexity with evil debate bros who want to kill people, why not
For the number field sieve, the complexity is
exp (k + o(1))(log N )1/3 (log log N )2/3),
that's still Omega(e^k) which is exponential
where
Nis the integer to factor or the prime modulus for discrete log,
that's literally not how it works. the chinese remainder theorem approach doesn't work on RSA's n = pq modulus and RSA is literally just diffie-hellman but worse for the actual asymmetric crypto part
and
kis an algorithm-specific constant. This formula is inherently imprecise, since theo(1)in the exponent can hide polynomial factors.
and they're lying about what's wrong, since as above exp(k) is exponential. really cute shit. go to hell
there has been zero progress on anything besides the completely fallacious "probabilistic algorithms" which were the reason quantum computing was "invented"