Elektrine lite

← Feed

@mei@donotsta.re

2026-09-18 21:17 UTC

@alwayscurious@infosec.exchange @sophieschmieg@infosec.exchange how do you prove security directly for anything more complex than a one time pad?

Replies (1)

  • @mei@donotsta.re @sophieschmieg@infosec.exchange By “direct proof”, I mean “not a proof by contradiction”. Security reductions are proofs by contradiction: you assume that there is an attacker who can break the protocol, and show that they can solve a hard problem. Since we assume that the hard problem is not solvable, such an attacker cannot exist. A direct proof would be something like, “The server signed the handshake transcript, and we verified the server’s certificate is authentic. Therefore, the ciphertext we got is the one sent by the server, which means that decapsulating it produces a secret only we and the server know. Replay attacks aren’t possible because both the client and the server include a random value in the transcript, and the whole transcript is hashed, so nobody can mix and match handshakes.”

    Open ##4756295