Jon Callas wrote:

* We've been telling the world for years that they should avoid home-grown crypto, and 
that they should stick to well-trodden ground because it's dangerous out there. And they 
listened to us! But that means that when you talk about the virtues of Rabin-Miller, 
they're going to hear, "blah, blah, snake oil, blah," unless you have a really 
good story. The presumption today is that if you're not using the standard algorithms, 
you don't know what you're doing.


That looks like an innovation suppression strategy.

Not only this argument (i.e. forwarding a misconception that snake oil includes promising mathematical results that are not in the mainstream standards) inhibits the proven R-W digital signature scheme for new application contexts, it also signals an ideological objection to any new mathematical development. Weil pairings has been mentioned.

I believe the crypto implementation minefield evolved significantly from the overall scene when PGP grew up from mostly snake oil to a current standard. Look at how many multiple-precision arithmetic libraries and tools are available now to implement PK crypto. Do you further argue that anything besides OpenSSL is snake oil?

Can you identify significant mistakes (in systems in actual use) that can be traced (as in a root cause analysis) to errors in the mathematical formulation of a PK crypto scheme?

If the mathematical aspects of cryptography comes up with something useful, the risk inherent with the implementation minefield should not be used as a rationale for saying 'no thanks' in advance of a fuller analysis.

If I understand correctly the original request, the contemplated use of digital signatures is replacement of SHA fingerprints and user information in a version/revision control system, i.e. bare digital signatures applied to stored data. No predefined interoperability requirements. This looks like an opportunity to look at innovative signature schemes from the body of mathematical knowledge.

Regards,

--
- Thierry Moreau

CONNOTECH Experts-conseils inc.
9130 Place de Montgolfier
Montreal, QC, Canada H2M 2A1

Tel. +1-514-385-5691
_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography

Reply via email to