Post
Raze   [OCTADE]
Raze [OCTADE] @8@star.octade.net

@Suiseiseki

The problem with modern computational cryptography is that it has no 'empirical' evidence of security. The fact that no one has publicly broken a cipher is not empirical evidence. It is absence of evidence being used as evidence.

If an adversary breaks a function or cryptosystem, he is not going to tell you. Thus using the lack of a public break as evidence is not scientific method.

The security models are based upon 'educated assumptions' within model A or B or C. Nobody has ever proven that a cryptosystem is secure. They are 'assumed' to be secure. Or, they are assumed to be hard in the average case.

Terry Ritter wrote a piece that explains this problem:

https://web.archive.org/web/20100626171435/https://eecs.wsu.edu/~holder/courses/cse4317/summ01/papers/ritter.pdf

In this old Usenet discussion thread, Terry Ritter debunks a lot of the magical thinking endemic in the 'cryptology community':

https://web.archive.org/web/20240922132730/http://www.ciphersbyritter.com/NEWS5/HERDART.HTM

NP-hardness proof is still an open problem. As far as I know, not a single cryptosystem has actually been proven to be NP-hard. Model assumptions using a supposed NP-hard function and proof are two different things.

As for no existing crypto surviving: Vernam's cipher (OTP) is provably information-theoretic secure if keys are not re-used. That avoids the NP-hard problem altogether as it is a different universe of math.

23 Sep 2026 · 14:14 · ActivityPub
View Raze [OCTADE]'s profile
star.octade.net • v0.0.6