Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those interested in this topic might also find a couple other papers by Phil interesting:

1. Practice-Oriented Provable Security and the Social Construction of Cryptography: https://www.cs.ucdavis.edu/~rogaway/papers/cc.pdf

2. An Obsession with Definitions (Section 5): https://books.google.com/books?id=SwOkDwAAQBAJ&lpg=PA18&ots=...



I thought about something related quite a lot. Developing a cryptographic hash^1 and some of the reactions were entirely dismissive. Hostile as if (not against me per se, but) almost against the idea of developing crypto outside of the Church. As if Scripture forbade such a blasphemy even being considered, or as if making new tech was a Denial of Service against the Priests who need to review every Miracle and Revelation for sanctified inclusion within the Cannon. Or whatever.

I formed my thoughts into a deliberately indirect dissection of this, and now I repost here:

Thanks for your input! I hadn't realized my post had made it to the subreddit since it was immediately removed, so it slipped my mind. Anyway, it's not really related to what you said, but I'll take your remarks as a starting point to have a riff / use as springboard for a thought that's been brewing:

Hearing you say that seasoned cryptographers wouldn't even bat an eye at this surprised me. I'd thought those well-versed in this domain could glance at an idea, scan the smhasher results, and almost intuitively know whether there's potential there or not. I imagined they'd have a sort of gut feeling, something like "this holds promise" or "this won't cut it," directing their decision to delve further. So, why is it such a challenge for non-experts to make substantial contributions? It seems as though there's an unspoken rule prohibiting it.

I suppose this isn't unique to cryptography; it probably exists in any specialized field, like bioinformatics. Yet, there's a distinction - when an outsider steps into a bioinformatics forum with innovative ideas and some groundwork, they're likely to find a receptive audience.

But with cryptography, it feels closed off. It's as if only certain individuals are permitted to work on specific topics within established parameters, and only an elite few are qualified to assess this work. It's reminiscent of religious doctrine where deviation is considered heresy and swiftly dismissed. This leads me to question who's guiding the crypto field to limit creative contributions and why? Who stands to benefit from curbing the development of new algorithms and preventing their widespread adoption? Who might be disadvantaged by a sudden surge of new, potentially powerful crypto algorithms?

It's a challenging balance to strike. Personally, I think the current system could be improved. As an impartial observer with no stake in the outcome, I see this as an intriguing creative outlet. I'm not advocating for a revolution and frankly, I'm not particularly concerned if things stay as they are. However, I do believe that when a field becomes too closed, we all stand to lose.

Here's the intriguing part: while the field is theoretically open, in practice, it mimics a closed one, similar I suppose to the restrictions and veil of esoterica surrounding nuclear technology. But nobody openly discusses this closed-off nature, which only adds to the strangeness.

I understand why it's structured this way, but I can't help thinking there could be a better approach. Given the diverse interests involved, it's challenging to identify what that might be. Surely, I can't be alone in thinking this way, right?

1: https://dosyago.github.io/rain/


The problem with developing your own cryptography is that it's easy to make something you can't crack but which has holes an experienced cryptographer could drive a bus through. A false sense of security is worse than no security at all. Plus, of course, most people who claim to have a Bold New Encryption Algorithm are selling the absolute worst kind of snakeoil, like XORing the input with a single fixed-length key over and over again, because they know most of their victims will be even less knowledgeable than they are. The outright frauds poison the make-your-own cryptography field for the honest ignoramuses.

The field isn't closed off, either. It's just founded on mathematics that's beyond what the average untrained or semi-trained person reaches, especially the ones who feel entitled have Big Opinions on the subject. However, if some can't grasp the mathematical underpinnings of contemporary cryptography, their opinions of how cryptography ought to be done are worth less than nothing. Mathematics isn't a democracy, ignorance doesn't get a vote.


Oh, and even trained mathematicians have a hard time coming up with good new cryptographic primitives. Many of the candidates fail.


We call such a system “secure against the chosen cryptanalyst.”


This is the old Schneier textbook defense that anyone can make a cipher they themselves can’t break, therefore don’t try, yet doesn’t hold water here.

Not that it’s not true when applied to a certain group of oil de serpenthe salesmen, or to noobs making toys, but it obfuscates the reality of outsider talent by unhelpfully conflating complete frauds with budding learners with enthusiastic amateurs with experienced amateurs.

And reinforces the notion of a priest class, upon which amateurs, encountering the same, should abandon their labors and despair.

It’s also a surprisingly hostile way to treat interested budding cryptanalysts and cryptographers. It is a kind of hazing designed not to forge bonds but verily to discourage.

As in: We only want insiders creating crypto and there’s a reason for that; and in the main it’s not about protecting against flawed security; in fact, this reason is about protecting our ability to break.

Protecting this crucial vital main and security mission of the high priests at the top of this hierarchy (who, nevertheless veil their faces in the shadows: the mages’ hood) is the reason for the weird, captured nature of this field.

And because this little aphorism comes from The Book of Bruce, none dare question for fear of being tarred a heretic and cast out. Luckily, for me, an outsider has no such fear: being already on the outside. And hence is revealed a weakness of the little system of forced organization.

Aside from that, such discouraging attitudes and aphorisms, obscure the fact that analyzing new primitives is difficult.

And they conceal the truth that, it’s not so much that tech created by amateurs has no merit, it’s that it may. And this maybe, makes the job that much harder for the code breakers; the mages; The “surveillance state” that this posted HN article, under which I am adding this comment, rails against.

The code mages would much rather everyone stick to a predefined set of spells that follow the designated parameters of good sense and civility, which i suspect coincides not a small amount with the technical exploitation window of the secret code breakers. Indeed some are secretly designed to be broken: one way designs, unbreakable, unless you possess the kernel, upon which a more elaborate design was scaffolded for release. The designer-in-secret retains the secret kernel.

It seems I’ve had to be more direct than I’ve initially desired to explain my point.

It’s hard to do cryptanalysis, and the experts who do it have limited resources, so they don’t want to have to deal with a deluge, so they architect an academic culture empowered with these cutsie aphorisms to further those ends, as well as capture, guide, curtail and direct the fields search from the shadows. Coercive funding withholding is but one means. The strongest is a culture and acolytes with a fanatical devotion to the orthodoxy that sustains this control.

I understand the complexity of the balance that needs to be struck, but i think with these deceptively closed and captured fields, we all lose out.

At least nuclear secrets is open about just how closed it is and why: it’s a weapon a small club of states wield, and no one else.

Crypto in reality is the same. It’s a shield wielded by the state, not by the public. The public gets, not security nor privacy, but what the regulator deems them safe to have.

This situation cannot be admitted because it dispels the illusion that the field is open and not captured. And also the illusion of privacy and security not being monopolized by the state.

I’m not sure of the exact best balance, but I don’t think the current system is the best.

Perhaps a better balance is crypto being more like nuclear secrets, where it’s open about how closed it actually is rather than deceptively, in the vein of the snake oil salesman, posturing a security that is not, in fact, delivered.

If not ignored this notion will, unfortunately, provoke, understandably, furious reactions from both those who depend on the belief and the security, as well as those in the captured industry, who would rail against it, but cannot do so, thus turn their frustrated expression towards any who expose their embarrassing constraint.

I have no vested interest either way, except in the good of everybody…and I think it’s high time for this discussion to be advanced in a better direction. Government transparency, and accountability depends on clarity with, and consideration towards, the public who depend on them.


> And reinforces the notion of a priest class, upon which amateurs, encountering the same, should abandon their labors and despair.

The priests are mathematical algorithms and their judgements are based purely on the ability of candidate algorithms to perform at the current standard or higher. There are no "code mages" in crypto. Anyone is free to contribute.

What you need to understand as an amateur coming into the field is that there are already rigidly tested standards that people depend on and have spent many, many hours thinking very critically about to ensure they are mathematically sound. At this point there are extremely high expectations for minimum levels of entropic distribution.

This is not an art project. New ideas must absolutely perform at a higher standard before anyone will even consider it. You are competing with what exists today and it will be 100% on you to prove that you are setting a higher standard. Everyone will follow you if you can prove this, I assure you.


That’s not really true, the priests are people.

This confuses (or may just respond to only one of) two things I’m saying: field is kept artificially weakened by the priests; and new designs by outsiders are deliberately kept out. These are connected.

What you’re talking about it seems is just genuine competence and performance. I’m fine with that. I’m okay to compete. But it’s not just competition we’re dealing with, it’s artificial bias, designed to keep the field weak.

With crypto hashes it’s more than just entropy: there’s many hashes that sit at the top of good entropy performance regarding smhasher results, but that’s not enough for crypto: you need analysis. And for analysis you need experts.

But if i was worried about just competing on performance, which I’m not (many of my hashes have excellent entropy results), then your piece world be encouraging, it’s a good pep piece! Well done!


You haven't proven that there are better designs out there being kept down by the priesthood, just waved your hands in the direction of Grand Conspiracy and anointed Bruce Schneier a member in that supposed priesthood. The thing is, cryptography isn't kept obscure. It's a mathematical discipline welded to the practical discipline of actually writing software, but so are other topics in that part of CS, such as compression and formal verification.

But here's the nub of my point: It is hard, though, and it's harder than it looks, and this matters more for cryptography than compression because of the things people do with cryptography. If you design a bum compression algorithm, you make files you can't really decompress and you get discouraged. If you make a bum encryption algorithm, and you get all excited and actually use it for something important, and it's easy to break, well, you might get a lot worse than discouraged. Major companies have been bitten by this. Is your algorithm better than HDCP? Probably not. You know what happened to HDCP? Yeah. Intel wishes it had taken the kind of advice any new cryptographer gets about not taking their own inventions too seriously.


Sorry about my late reply! I've been very busy.

So, basically, nobody would have any interest in preventing an explosion of new strong cryptography is that right?


> So, basically, nobody would have any interest in preventing an explosion of new strong cryptography is that right?

Not really.


We don't need very much of this work.

Unlike in many fields, there is no value in a cheap local substitute for cryptographic algorithms. Indeed vanity ciphers (many smaller powers wanted their own symmetric ciphers for national pride reasons) fell out of favour because they're just worse in practice.

So the competition for your Cryptographic hash isn't some idea by a guy from the next town, it's SHA-512/256 and maybe SHA-3.

Try something else, should the US Government have a department which vets architectural plans for a new Capitol building. Sure, the US Capitol is a pre-civil war building, and there's no reason it would be torn down and rebuilt or replaced as a whole, but surely it's unfair to just have one dead guy get to design the Capitol when who knows, Suzy, a ten year old from Maryland, who has no architectural training and mostly just thinks everything should have ponies on it, might have a better design? Why are there so many Gatekeepers? Suzy's design for the Capitol might be great, it's unfair that she's not considered just because she isn't an expert and they don't need a new one designed.


There are indeed established standards just a few for each area like hashing, authentication, encryption and so on--one of the things I'm staying.

However, the idea that work is almost complete in crypto, and therefore new work is unneeded, is false (and likely an artefact of the order I'm describing). Take for instance this current work on ZK hashes: https://www.zellic.io/blog/algebraic-attacks-on-zk-hash-func...


With all due respect, in appears your basis for believing this was submitting to Reddit. Ten minutes of web search seems to indicate you're a guy from Australia who ten years ago was listed on LinkedIn as an unemployed "Hardcore Programmer" looking for work in Hong Kong, then at some point you started a company called Irrzl, LLC that aimed to create a "post-scarcity, space-traveling human population with arbitrarily extended lifespans." In order to fund your own research, you started businesses selling "trade-secret algorithms" while anonymously employing arbitrary people who had no salaries but could request to be paid whatever they wanted on a weekly basis, and now you have some other company Dosyago Corp with an address in Beaverton, OR that is a strip mall with a mail scanning service where you can have mail sent to you without revealing your actual location, so it isn't a real business address.

I really don't want to come across as mean, and I know what your response will be already, but everything a person can find out about you within a few minutes screams crank. You come here wondering why all these gatekeeper mathematicians in their cathedrals won't take you seriously, but it doesn't appear all that mysterious to me. You may very well be what you say you are. You'll live forever and colonize the galaxy, and along the way, also provide better cryptographic hashing functions. But you have to clear some kind of minimum bar for why a person should even look at your work. Most of these mathematicians are presumably not thinking they're going to live forever, so they only have so much time to spend considering everything a person on the Internet thinks they should consider. Whatever heuristic they're using may be as imperfect as Goldman Sachs throwing away any unsolicited resume that doesn't show an Ivy league degree, but they need some kind of heuristic.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: