None
EN
How to prove false statements? (Part 1)
['Matthew Green', "I'M A Cryptographer", "Professor At Johns Hopkins University. I'Ve Designed", 'Analyzed Cryptographic Systems Used In Wireless Networks', 'Payment Systems', 'Digital Content Protection Platforms. In My Research I Look At The Various Ways Cryptography Can Be Used To Promote User Privacy.']
A Few Thoughts on Cryptographic Engineering
From a theoretical perspective, any scheme “proven secure” in the random oracle model ceases to be provably secure the instant you replace the random oracle with a real (concrete) hash function like SHA-3. So I can run that program on some other proofs as input — and then I can use the proof system to prove that I ran that program correctly. In the best case, this type of attack might simply move the scary backdoor code out from the cryptographic proving system, and into the modular “application programs” that can be fed into the proving system You still need to make sure the scheme implementation doesn’t have silly backdoors — like special code that breaks everything if you know the code for SHA-2.