asciilifeform: the purpose of 'padding' is to a) never have transform of known input deterministically give same output b) prevent arbitrarily flipped bits of ciphertext from yielding a valid (attempt to eat) message
asciilifeform: 'well, one could devise methods for signing long messages that don't involve hashing, such as splitting up the message into small segments, tie each segment together with an identifier and a segment sequence number, and sign each individually. However, hashing works so much easier that no one ever considers an alternative.' << quoted verbatim from shit-overflow
asciilifeform: it would mean that an existential signature forgery is trivial
asciilifeform: phf: am i catastrophically missing something, (i didn't sleep much), or is this an even greater clusterfuck than if the 16bit were used ?!!
asciilifeform: how does it help anybody (other than hitler), including mircea_popescu, when hitler knows for certain, but everybody else is left to mathematicize fruitlessly (or, worse, work on faith)
asciilifeform: can't rule out that even 20 yrs ago hitler knew that factoring is np-complete.
asciilifeform: i would like an asymmetric transform whose complexity were provably unknowable. that would be spiffy.
asciilifeform: see, i could even agree re: ~provably unknowable~ (i.e. godelian) unknowns. if these could be had. but 'unknown uknowns' inescapably shed the first 'unknown'
asciilifeform: is the idea that enemy wastes resources on cryptoanalytic derp vs setting up coke machine dungeon ?
asciilifeform: how does this beat 'proven np-complete and the lowliest amoebic scum knows' ?
asciilifeform: hitler rediscovers the proof. then what
asciilifeform 's throat is not big enough for this pill
asciilifeform: (most academitards neglect the second part!)
asciilifeform: while also proving that none of the 'practical' aspects of employing the transform, leak key.
asciilifeform: to round off the thread, imho the 'holy grail' of asymmetric crypto is to demonstrate ~provably measurable strength~ - that is, prove np-completeness of inverting the transform.