The problem with modern computational cryptography is that it has no 'empirical' evidence of security. The fact that no one has publicly broken a cipher is not empirical evidence. It is absence of evidence being used as evidence.
If an adversary breaks a function or cryptosystem, he is not going to tell you. Thus using the lack of a public break as evidence is not scientific method.
The security models are based upon 'educated assumptions' within model A or B or C. Nobody has ever proven that a cryptosystem is secure. They are 'assumed' to be secure. Or, they are assumed to be hard in the average case.
Terry Ritter wrote a piece that explains this problem:
In this old Usenet discussion thread, Terry Ritter debunks a lot of the magical thinking endemic in the 'cryptology community':
https://web.archive.org/web/20240922132730/http://www.ciphersbyritter.com/NEWS5/HERDART.HTM
NP-hardness proof is still an open problem. As far as I know, not a single cryptosystem has actually been proven to be NP-hard. Model assumptions using a supposed NP-hard function and proof are two different things.
As for no existing crypto surviving: Vernam's cipher (OTP) is provably information-theoretic secure if keys are not re-used. That avoids the NP-hard problem altogether as it is a different universe of math.
#crypto #cryptography #cryptology #math #maths #ciphers #cybersecurity #encryption
Copy the post URL and paste it into the search field of your favourite Fediverse app to reply, repost, or like it.