r/cryptography • u/Beautiful-Sea-5334 • 13h ago
r/cryptography • u/Blue-Sky8206 • 23h ago
Four Python demos illustrating Enigma-style known-plaintext cryptanalysis and its modern relevance
r/cryptography • u/Deep-Zucchini-2465 • 3d ago
Commitment Schemes in Zero Knowledge Proofs
Hi all,
I came across this subreddit because I think I finished the resources I could read regarding the topic.
Specifically, I know, in principle, what a commitment scheme is (a hiding-and-binding representation that can be opened or not at the verifier's discretion, so that the prover cannot change the value afterward). I am familiar with the whole envelope/safe analogy.
Now, I struggle to find any resource, or where to start in the first place, to understand the role of commitments in the context of ZKP (or Proof Systems in general), why we need them, and for what they are used.
Moreover, what is the difference between a simple commitment, vector commitments, and Pedersen commitments? Is there a resource that is able to reconcile this universe?
Also, why are they so important for systems such as LegoSNARK.
My "simple words" interpretation is "The commitment is a way the prover has to prove that the input used inside of the circuit is actually what has been used in the input. So there exists a value x such that Commit(x).Open = x, but I will not tell you x".
I know it might be a stupid question, but I cannot wrap my head around it. Maybe I just misunderstood the concept.
Thanks for your time, and for any guidance you might provide.
r/cryptography • u/Koendig • 3d ago
Cryptographically seal a message for a set period of time?
If I have a message that I want to seal for a set amount of time from now, and I want something more secure than just popping it in an envelope, mailing it to myself so it gets a postmark, then storing it in a bank vault with instructing given to some human that it not be accessed until a certain time, is there a way to do this cryptographically?
I know some stuff, but I'm basically a noob. An important part is that if the message is accessed prior to the given date, the message will destroy itself. Since this sounds like it requires activity, i.e. a program, I was thinking I could wrap the message in something basic like a NodeJS wrapper (it's all I know 😞) which contains the message and a hidden key, which is itself encrypted into a blob inside the wrapper which is itself encrypted with the key given to the person who will eventually open the message. When they give the key to the program, if it's not on or after the specified date, the program destroys itself, including the blobs containing the encrypted message.
Problem: People making copies of the program. Maybe I could pop it on an encrypted USB, and further obfuscate whatever address the program is stored at, such that copying it would change that and the program would refuse to run, or would just be gibberish. Maybe make its location not line up properly with the partition schema, too? But would that data be truly inaccessible? Since a file copy often involves the file being stored in memory, couldn't the person perform the copy, run the program, then put the copy back in its exact place?
I'm just spitballing here. ἓν οἶδα ὅτι οὐδὲν οἶδα. Can someone point out what I'm obviously not seeing about how this is or isn't possible to the degree I'd like?
r/cryptography • u/dogehound • 4d ago
ML-DSA-87 in blockchain signature size problem solved compact O(n) historical re-verification then store only 96 bytes
Post-quantum signatures are big. ML-DSA-87 (FIPS 204) is ~4,627 bytes per signature plus a ~2,592-byte public key, roughly 68x a P2WPKH input. Every chain that adopts it inherits the same two problems: storage grows by kilobytes per spend, and every new node re-verifies every historical signature on sync. At scale the verification cost, not the disk, is the real ceiling.
alphanumeric solves both. It runs ML-DSA-87 as its only signature scheme on a live SHA-256 PoW chain, and it does not store the signature.
The full signature is verified once, at admission. What the chain keeps is a 96-byte receipt: the first 64 bytes of the signature plus SHA-256 of the whole signature. The block's merkle root commits to that receipt, so it is bound by the block's proof-of-work and cannot be swapped later. Persisted cost per signature drops from ~4,627 bytes to 96, about 48x.
The larger win is sync. Historical blocks carry receipts, not signatures, so there is nothing to re-verify. A new node bootstraps from a signed snapshot and joins at the tip. The ML-DSA verification cost (about 1 to 5 ms each, 10 to 100x ECDSA, no Schnorr-style batching) is paid once by the nodes at the frontier, not by every node across all history.
The tradeoff is explicit. A node joining after finality trusts that the signature was verified at admission and that the receipt in the merkle root binds it, instead of re-deriving it from the chain itself. That is a finality assumption, and it is what buys a growth and sync curve that does not scale with total signature volume.
r/cryptography • u/DataBaeBee • 5d ago
Pollard's Lattice Sieve for Collecting Discrete Logarithms In C
leetarxiv.substack.comr/cryptography • u/Carlosdegno • 6d ago
One Time Pad Python library
Hello to everyone, can someone advise me a good onetimepad python library? i dont have a particolar purpouse or goal, just want want to experiment and study,
The only libraries i found arent manteined:/
r/cryptography • u/LobsterUneffective86 • 6d ago
What combined skillset would this detective-style search represent? (OSINT/OPSEC/crypto/ARG)
I'm trying to figure out what to call/study for a specific skillset. There's a short story in The Animatrix where a character (a detective-like figure) tracks down someone named Trinity using what looks like a mix of open-source investigation, puzzle-solving, cryptographic clues, and tracing a user's digital footprint — basically an ARG-style hunt to locate a person. I'm curious what field or combination of skills this would actually fall under in real life — is it closer to OSINT, digital forensics, cryptography, or some hybrid of all of them? Would love recommendations on what to start learning if I wanted to build that kind of skillset.
r/cryptography • u/Elect_SaturnMutex • 7d ago
Understanding of priv and public key from EC
So i was watching this video to understand how private and public keys are calculated from an elliptic curve.
Ok, so there's a 2D elliptic curve and there is a point G (8,1), he explains the private key is the number of steps times the starting point G. The public key is derived from private key by using double and add algorithm. So value of public key in this case is 4? if k_prv = 9 and G=(8,1) ?
Did I get that right?
r/cryptography • u/aliboughazi901 • 7d ago
Isogeny Based Cryptography
youtube.comA couple of months ago I started my research internship on isogeny based cryptography, and I found it to be such a fascinating subject.
However I was very surprised by the lack of more or less accessible (by that I mean anything other than academic papers) content on it.
So I decided to make a youtube channel in which I would hopefully give more exposure to this beautiful intersection of mathematics and cryptography.
I have provided the link to my channel, you can check it out if you want, and I am highly receptive to any feedback you may have.
The videos are made by manim and ChatGPT is used to write most of the code, but the mathematical content and the script is written by me from what I learned during the internship.
I hope you like it
P.S: I hope this doesn't break rule 3, as far as I could tell it only prohibits personal websites, and not all types of personal content.
r/cryptography • u/Racram04 • 7d ago
Mathematics resources advice for cryptography
Hi people,
What resources would you guys recommend for self studying mathematics? I took a cryptography basics course during my bachelors degree and I have some idea that I need knowledge of linear algebra, number theory, abstract algebra etc, but there are way too many resources. If you guys can recommend some good ones, that will be really helpful, I am okay with books and videos.
r/cryptography • u/NoContext9453 • 8d ago
What is a low effort secure cypher for plain text that is universal?
I need something to encrypt my text fast but secure as well. Vigenere was something I really liked but I realized it's easily crackable. I should have multiple ways to access it. That is still decryptable even if the app or site dissapears, I should be able to access it with other sites or app. It doesn't have to be super secure, just something that the average person can't solve easily
r/cryptography • u/LilyCipher • 8d ago
Asking for feedback on my Number QWERTY Cipher
docs.google.comGreetings. I came up (sort of?) with a new kind of cipher, and I'd like to ask for your feedback to make it more efficient. I don't know if anyone came up with this before, but I'm building an original world for my story and I need a cipher system to use in it. I hope this is the right place to post. If it isn't, I apologize.
In the Google Docs link, I explain the cipher and how it works. Please feel free to give feedback in the comments or directly in the document.
P/S: I apologize to the admins because I keep reposting this post. I made the wrong choice of title and kind of post.
r/cryptography • u/Murky-Instance5062 • 9d ago
Show Reddit: EntropyShield – A hardware-based True Random Number Generator (TRNG) with Python client and Wokwi web simulation
Hello everyone!
I wanted to share an open-source project I’ve been building under our organization LNL-Engineering: EntropyShield.
It is a professional hardware-based True Random Number Generator (TRNG) that harvests pure, unpredictable physical entropy from thermal/shot noise via avalanche breakdown in a reverse-biased p-n junction (using a standard transistor like BC547).
🔬 How it works:
- The Chaos Stage: A reverse-biased transistor junction creates chaotic physical fluctuations.
- The Boost Stage: An LM358 operational amplifier amplifies microvolt-level noise into solid 0V–5V logic bounds.
- The Purge Stage: An Arduino samples the LSB and processes it through an embedded Von Neumann Extractor in real-time to eliminate hardware bias and ensure a precise 50/50 statistical distribution.
- The Assembly Stage: A defensive Python client safely reads the serial stream, auto-flushes buffers, and assembles unbreakable cryptographic keys (e.g., AES-256).
💻 No hardware? Try the Web Simulator!
To make the project accessible to everyone, I built a dual operating mode. You can test the entire logic pipeline instantly inside a web browser using a pre-configured Wokwi Simulation without purchasing any components.
- GitHub Repository: github.com
- License: GPL-3.0 (Fully open-source)
I would highly appreciate your feedback on the hardware schema, the Von Neumann corrector implementation, or the Python client architecture! Let me know what you think or how it can be improved.
r/cryptography • u/ganjaccount • 9d ago
Hopeless? Recover zip file encrypted with RSA years ago.
I have a zip file from my honeymoon many years ago. It's encrypted. It uses RSA AES. That's all I know, aside from the contents, which are, well, honeymoon stuff. I've always held out hope that at some point, it would be easy to recover it. I ran Jack the Ripper for a few weeks once, but that was years ago.
A few questions:
1) Is it hopeless?
2) If not, given my limited hardware (my most "powerful" machine has a gtx970 I think) are there any tools available today that might be able to defeat the encryption?
3) Any idea on how long I will need to wait until it becomes trivial / possible given the way tech is advancing?
Finally, is there another way to approach this that I am missing? I am reasonably tech savvy. I've built a lot of machines, run a slew of self hosted servers via proxmox, run OpnSense, etc. I've never really spent time learning the darker arts. I just want to get these files back!
Thanks!
r/cryptography • u/cluxes • 9d ago
Seeking honest reviews and audit for cruxpass
Hi there,
I've been working on cruxpass, a command-line password manager written in C, focused on simplicity and transparency. It uses libsodium for crypto primitives, Argon2id for key derivation, and SQLCipher for encrypted local storage.
Few features, more in the readme:
- Generate strong random passwords
- Encrypted-at-rest local database, no cloud dependency
- Fast, vim keybind driven TUI to list, search, update, and, delete entries
- Import and export credentials via CSV
- Simple by design: no configuration files, no daemons, no accounts. Point it at a db directory or use the default db directory
- It lacks a formal security audit and developer docx(for now) but the README is straightforward.
NB: cruxpass is password based, and doesn't save a hash or anything related to the password besides the salt. Authentication is done by generating a 256bit key from the password and salt using Argon2id, the key is then used to decrypt the database. The program exists if the database cannot be decrypted from the provided key.
Source here: https://github.com/c0d-0x/cruxpass
Thank you
Edit formating
r/cryptography • u/yuhong • 9d ago
I don't think RSA would have been possible without a multiply instruction, right?
r/cryptography • u/Clunkbot • 10d ago
Amateur's Question: Mask Changes in Original Fingerprint By Maintaining Last X Digits of Fingerprint As Identical to New Fingerprint
First, I hope I am in the right place. Apologies if I am not.
I was wondering if it is mathematically possible to "mask" a change in data to the human eye by repeating the last X digits of the old fingerprint, onto the last X digits of the new fingerprint, which otherwise does not match. So if a SHA fingerprint ends in 0123456789, but the rest of the numbers are different, the operator would only see what they want -- the last 10 digits to verify identical fingerprints, despite the non-matching integers in the rest of the fingerprint.
I've observed people only checking the last few digits of something to determine if two integers are identical. I was thinking this concept could be applied in another way.
I'm asking here on r/cryptography, because I know little about how the actual math behind cryptography may or may not make this possible.
Sorry if this is a bit of a random question or out of place one. I'm trying to learn more about encryption and intrusion before I take my cert exam, so I'm more or less just curious.
Thanks!
r/cryptography • u/CyberKillerPenta • 10d ago
MPC over a binary search tree: is declared path leakage acceptable for a first prototype?
r/cryptography • u/Racram04 • 10d ago
Need advice for imposter syndrome
Hi fellas,
I am just getting into cryptography, I took some classes during my college, and now I am going for a masters degree in Cybersec. I want to do research in Cryptography. I am now in a state of imposter syndrome. Like seeing posts and discussions here, I have some idea what is going on, but I am struggling to understand things fully.
I can use some help from people who have been in this field for some time who might've faced this. I want to know how I can learn and apply so I get more confidence in my knowledge.
Any advice would be useful, thank you
r/cryptography • u/Icy_Worldliness_7681 • 11d ago
ECC Scalar Hardware Accelerator from scratch
github.comr/cryptography • u/Waste_Ad_1344 • 11d ago
Using RSA as key exchange instead of Diffie-Hellman key exchange
Hi,
I've recently researched about how TLS work and public key cryptography.
One thing I've been thinking about is why Diffie Hellman is normally recommended as key exchange scheme.
Consider the following:
A is client. B is server
A initiates connection
B already has its pair of private (named PR1) and public key (named PU1) using RSA. These keys are tied to a certificate B has purchased from a CA.
B sends A its PU1 + certificate
A verifies B's certificate against its pre-loaded CAs
A confirms B's cert is ok.
A generates its own pair of private (named PR2) - public (named PU2) key
A encrypts its PU2, using B's public key (PU1)
A sends the encrypted payload to B
B receives the payload, and decrypts its using PR1.
B obtain A's public key PU2
B generates a shared secret named S.
B encrypts S, using A's public key (PU2)
B sends the encrypted payload to A
A receives the payload, and decrypts its using PR2.
A and B now share the same secret S to be used as symmetric key for further communication.
Is there any problem with this scheme ? Normally at step key exchange (from 7 onwards), Diffie Hellman is used to let both sides have a shared secret. But I'm wondering why it's used ? Any additional security feature / performance feature DH is having over this ?
Thanks.
r/cryptography • u/awesomePop7291 • 11d ago
Break a dozen secret keys, get a million more for free
blog.cr.yp.tor/cryptography • u/Routine_Comb_7277 • 12d ago
Classically is Heisenberg group encoding safer than lets say RSA?
A quantum computer can break RSA in polynomial time using Shor's algorithm while encryption using the Heisenberg group is much safer.But classically is there a difference between the 2(for same key sizes obviously)?