Series

How It Would Break

13 parts of 13

  1. 41 min read

    AES is not broken -- but if it ever were, the crack would start at its linear key schedule, not its celebrated round function. A structural cryptanalysis tour.

  2. 49 min read

    SHA-2 and SHA-3 have never broken, yet each construction already dictates how it would fall -- collisions, length extension, and the sponge algebraic frontier.

  3. 42 min read

    Everyone says you break RSA by factoring the modulus. That is the slowest path. A structural tour of the fast lane, the slow lane, and the quantum one.

  4. 54 min read

    For a well-chosen group the discrete log is optimally hard. Every faster break exploits the group's structure, not the log -- only Shor survives a clean one.

  5. 50 min read

    RSA, Diffie-Hellman, DSA, and elliptic curves share one abelian period. A single quantum computer running Shor's algorithm reads it and breaks all four at once.

  6. 43 min read

    ML-KEM and ML-DSA rest on one hard problem, Module-LWE, measured by one ruler. Here is how that ruler would slip -- and why one slip debits both standards.

  7. 52 min read

    Falcon is NIST's smallest post-quantum signature and its only lattice one still in draft. A structural case for why its likeliest break is NTRU-specific.

  8. 49 min read

    SLH-DSA has almost no attack surface of its own. A structural tour of FORS, WOTS+ hypertrees and tweakable hashes, and why it fails only if SHA-2 or SHAKE does.

  9. 44 min read

    Classic McEliece and HQC hedge post-quantum encryption on syndrome decoding, a problem unrelated to lattices -- and here is where their own math gives way.

  10. 41 min read

    No post-quantum algorithm is proven hard. The stack's only real defense is a deliberately uncorrelated portfolio of lattice, code, and hash assumptions.

  11. 41 min read

    Fully homomorphic encryption computes on data it never decrypts. Its likeliest failure is not the post-quantum lattice beneath it, but the scheme layer above.

  12. 43 min read

    Zero-knowledge proofs rarely break at the math. They break in the circuit, the trusted setup, and the Fiat-Shamir transcript -- here is exactly how, and why.

  13. 44 min read

    MPC has no security level, only security relative to an adversary model. How it breaks at the honest-majority line and the selective abort, no cipher touched.

Related tags

#aes#cryptanalysis#key-schedule#related-key-attacks#biclique#block-ciphers#security-margin#sha-2#sha-3#keccak#hash-functions#merkle-damgard#length-extension#sponge-construction#rsa#factoring#coppersmith#lattice-attacks#shor#public-key#post-quantum#cryptography#discrete-logarithm#elliptic-curves#diffie-hellman#quantum-computing#number-field-sieve#shors-algorithm#post-quantum-cryptography#elliptic-curve-cryptography#hidden-subgroup-problem#ml-kem#ml-dsa#module-lwe#lattice-reduction#core-svp#fips-203#falcon#ntru#lattice-cryptography#digital-signatures#fn-dsa#hash-based-signatures#slh-dsa#sphincs-plus#fips-205#nist-pqc#code-based-cryptography#classic-mceliece#hqc#information-set-decoding#syndrome-decoding#kem#cryptographic-assumptions#sidh-sike#crypto-agility#correlated-failure#hybrid-key-exchange#fully-homomorphic-encryption#fhe#ind-cpa-d#ckks#bootstrapping#zero-knowledge-proofs#zk-snarks#soundness#fiat-shamir#trusted-setup#circuit-security#zk-starks#secure-multiparty-computation#mpc#honest-majority#selective-abort#fairness-impossibility#adversary-model

← All series Start here