Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If secp256k1 is backdoored, why hasn't someone stolen a shit ton of bitcoins?


First, SECP256K1 isn't (IIRC) a NIST curve.

Second, if NSA backdoored a curve standard, they probably did it in a fashion that only allows them privileges. Google [NOBUS NSA]. Dual_EC is a NOBUS backdoor, unless you can efficiently solve the ECDLP, in which case the backdoor doesn't matter anyways.

Finally, even if you stipulate for argument that a curve was backdoored in such a way that a researcher might find the backdoor, who's to say that curve researchers care that much about Bitcoin?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: