An attack on a fundamental proof technique reveals a glaring security issue for blockchains and other digital encryption schemes.
The underlying math behind secure web transactions, blockchain (crypto) security and apps that use encryption has a flaw. It could be used to have these apps certify statements that are false, and fundamentally break the security needed for cloud systems and cryptocurrencies to keep data safe.
'A host of different computing applications — from cryptocurrencies to cloud computing — involve convincing a bunch of strangers on the internet that you’ve performed a computation correctly. The new paper shows how to hijack a fundamental technique that enables people to certify such computations. The technique, called the Fiat-Shamir transformation, is useful not just in blockchains and cloud computing but also in many other cryptographic applications, such as the key exchanges that safeguard web transactions and encrypt text messages. It’s so ubiquitous that it has become a verb, as in “Let’s Fiat-Shamir this.” '
It remains to be seen if and when this can be exploited, but the stakes are enormous and the motivation to make a successful attack is extremely high.
















