@SteveBellovin@infosec.exchange
Post #4171912
2026-07-28 19:36 UTC
@cryptomancer I follow @CryptoOrrDun@ioc.exchange here…
That LLMs should find bugs in crypto libraries is utterly unsurprising at this point. But these results are about the algorithms, which is much more interesting.
Replies (2)
-
@agreeable_landfall@mastodon.social 2026-07-28 23:16
@SteveBellovin@infosec.exchange @cryptomancer @CryptoOrrDun@ioc.exchange An LLM might find _something_, but I won't believe it's a crack until a cryptographer or two with deep experience says it's a crack.
-
@CryptoOrrDun@ioc.exchange 2026-07-29 08:40
@SteveBellovin@infosec.exchange @cryptomancer The short answer: They improve an attack from 2013 (Derbez et al.), based on our improvement from 2010, of an attack by Demirci and Selcuk. They save a byte guessing in a very innovative way, but I am not sure that the true gain is x200 to x800 (or more precisely, I am sure that the ALGORITHMIC gain is not that big, but as they can access smaller tables, then it may be faster in real life).