Elektrine lite

← Feed

@alwayscurious@infosec.exchange

2026-09-18 23:32 UTC

@sophieschmieg@infosec.exchange @mei@donotsta.re Is there a general guide for what one can and can’t assume when designing protocols? I know a few rules (always hash the full transcript, use randomness in every message, keep secrets twice the security parameter or have other protections from multi-target attacks), but my understanding is that formalizing an authenticated key exchange protocol is really hard, even though making one that’s secure isn’t that hard. I also know that in some cases (Fiat-Shamir) you won’t be able to produce a tight reduction, but everybody ignores that.

Replies (0)

No replies.