cryptanalysis
12 posts tagged cryptanalysis.
-
How Fully Homomorphic Encryption Would Break: The Seams Above the Lattice
Fully homomorphic encryption computes on data it never decrypts. Its likeliest failure is not the post-quantum lattice beneath it, but the scheme layer above.
-
No Cipher Fell: How Secure Multiparty Computation Would Break
MPC has no security level, only security relative to an adversary model. How it breaks at the honest-majority line and the selective abort, no cipher touched.
-
How the NIST Finalists Broke: Rainbow in a Weekend, SIKE in an Afternoon, and the Graveyard of Post-Quantum Candidates
In 2022 two vetted NIST post-quantum candidates fell to classical math -- Rainbow in a weekend, SIKE in ten minutes. That is the process working, not failing.
-
How Falcon Would Break: NTRU Lattices and the Structure Nobody Fully Trusts
Falcon is NIST's smallest post-quantum signature and its only lattice one still in draft. A structural case for why its likeliest break is NTRU-specific.
-
How Q-Day Breaks Everything: Shor's Algorithm and the Simultaneous Fall of RSA, Diffie-Hellman, and ECC
RSA, Diffie-Hellman, DSA, and elliptic curves share one abelian period. A single quantum computer running Shor's algorithm reads it and breaks all four at once.
-
How SLH-DSA Would Break: The Signature That Can Only Fall If a Hash Falls First
SLH-DSA has almost no attack surface of its own. A structural tour of FORS, WOTS+ hypertrees and tweakable hashes, and why it fails only if SHA-2 or SHAKE does.
-
The Hedge and Its Fault Line: How Classic McEliece and HQC Would Break
Classic McEliece and HQC hedge post-quantum encryption on syndrome decoding, a problem unrelated to lattices -- and here is where their own math gives way.
-
Two Standards, One Lattice: How ML-KEM and ML-DSA Would Break
ML-KEM and ML-DSA rest on one hard problem, Module-LWE, measured by one ruler. Here is how that ruler would slip -- and why one slip debits both standards.
-
How RSA Would Break: Why Factoring Is the Slow Path and Coppersmith Is the Fast One
Everyone says you break RSA by factoring the modulus. That is the slowest path. A structural tour of the fast lane, the slow lane, and the quantum one.
-
How SHA-2 and SHA-3 Would Break: Merkle-Damgard Collisions, Length Extension, and the Sponge's Algebraic Frontier
SHA-2 and SHA-3 have never broken, yet each construction already dictates how it would fall -- collisions, length extension, and the sponge algebraic frontier.
-
The Fortress and the Afterthought: How AES Would Break at Its Key Schedule
AES is not broken -- but if it ever were, the crack would start at its linear key schedule, not its celebrated round function. A structural cryptanalysis tour.
-
The Log Was Never the Weak Part: How Discrete-Log Cryptography Actually Breaks
For a well-chosen group the discrete log is optimally hard. Every faster break exploits the group's structure, not the log -- only Shor survives a clean one.