Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Phantasm (phnt@fluffytail.org)'s status on Tuesday, 04-Mar-2025 07:48:23 JST Phantasm
@meso It's basically as you've said. Instead of a prime factor, there was a chance that the points P and Q for the curve chosen by the NSA had a secret relation with a number that only the NSA knew. And with that knowledge it was trivially simple to go back through the random bits and get into the state of the generator which would compromise all future random bits.
Instead of a prime factor, it was a simple number (d) with which you would multiply Q and it would give you P. (dQ = P). The reason why this simple fact compromises the whole algorithm is somewhat complex, but Computerphile also made a video about that called the Elliptic Curve Back Door.
https://www.youtube.com/watch?v=nybVFJVXbww