i still don't get why people use elliptic curves instead of diffie-hellman since you can use it for public keys too. the index calculus cryptanalytic method appears to apply for the usage of F_q where q = pn for some prime p. it appears that if q is a large prime and q - 1 is divisible by a large prime, that covers the two biggest error cases
https://cr.yp.to/papers/safecurves-20240809.pdf if you read section 10 and onwards there are just an incredible number of problems arising from elliptic curves not using integer bit strings as points where it becomes incredibly hard to tell whether anything is a legitimate point and that seems like a huge problem
and furthermore the index calculus method is not very well evaluated + it seems to apply to elliptic curves anyway
The literature has many more examples of complications stemming from the interface gap between [bit] strings and elements of E(F_p)
this sounds like a bad protocol
Efficient bijections are known for some elliptic curves.
this is definitely not making the case
so because elliptic curve bullshit is confusing as shit the blockchain boys broke the foundational assertion against double-spending
As an illustration of the second complication, the Monero blockchain announced in 2017 [166] that it had patched a vulnerability allowing each coin to be spent 8 times. Monero used Curve25519, which has cofactor 8, so there are 8 points T ∈ E(Fp ) such that 8T is the neutral element; Monero’s security analysis was expecting a point P to be in the order-l group, but the software was accepting P + T as a separate expenditure for each of the 8 points T.
literally not a good protocol
at the end of this djb paper he essentially says yeah you can trigger arbitrary incorrect behavior due to the incredibly complex encoding between integer bit strings and elliptic curve points and nobody knows how to fix it