CK's Cold Dive: Recent Episodes

cronokirby

Musings about cryptography, software, and technology

cronokirby.substack.com

View Details

Topics

  • The Fiscal Theory of the Price Level

  • Prof. Cochrane’s Blog

  • The Fiscal Theory, as applied to Bitcoin and Ethereum

  • Blockchains as Government more broadly

  • Foreign token reserves?

  • Fees paid as tokenized bonds?

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Bluesky).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics:

  • Why I think the subfield of cryptographic proofs is interesting and worthwhile

  • Why I keep coming back and thinking about it

  • Why you want machines to check proofs (eventually)

  • Some ideas for a new graphical proof language for protocols

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Bluesky).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics

  • Generic groups.

  • A trio of interesting papers:

  • To Label, or Not To Label (in Generic Groups)

  • The Algebraic Group Model

  • An Analysis of the Algebraic Group Model

I should also mention that Léo Ducas had some similar ideas way back in 2009

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics:

  • An anecdote about idealized hash functions

  • https://cronokirby.com/posts/2022/04/canettis-paradoxical-encryption-scheme/

  • My preliminary thoughts on developing a theory of meta-cryptography using category theory.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics:

  • A little bit about MPS.

  • A little bit about Cait-Sith.

  • Bulletin Boards for MPC.

  • Applications of the bulletin board model.

  • Robust Schnorr Signatures.

  • Some deception around group reconstruction circuits.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics:

  • What is Threshold ECDSA again?

  • What is a CAIT-SITH?

  • Simulating networked benchmarks

  • API design for protocol libraries

  • The advantage of key-independent preprocessing

  • Planned improvements

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to check out my blog, and you can even follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

  • 1:10 Thoughts on why AI will not cause as much economic growth as people think

  • 16:10 Why ML techniques would benefit from better integration with classical techniques

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

  • 1:00 Legibility, and an overview of the rest of the episode.

  • 2:50 What is fully homomorphic encryption (FHE)?

  • 7:28 Some applications of FHE.

  • 8:15 Contrasting this with MPC.

  • 11:50 Why you shouldn’t need to care about implementation details for applications.

  • 14:28 Why I’m annoyed when people conflate Machine Learning and computing.

  • 23:20 The legibility problem, and why these kinds of conflations are inevitable.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter. (Or on Mastodon).

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

  • 2:20 Why I prefer alphabetical references to numeric ones.

  • 8:42 Why round complexity in MPC is of limited utility.

  • 23:25 Replacing identifiable aborts with bulletin boards?

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

  • 4:05 The basic components of a signature.

  • 6:00 A primer on cryptographic groups.

  • 11:52 How ECDSA works.

  • 25:55 Bringing ECDSA to the threshold setting.

  • 29:29 Inversion from multiplication.

  • 31:50 The big approaches to multiply numbers.

  • 33:22 Homomorphic encryption in a nutshell.

  • 40:30 Multiplication via Oblivious Transfer in a nutshell.

  • 48:21 Back of the napkin comparison of the two approaches.

  • 50:19 The difficulty of getting malicious security.

  • 54:00 How to implement homomorphic encryption (and why I don’t like Paillier).

  • 59:40 The Paillier lineage of papers.

  • [Lindell17] https://eprint.iacr.org/2017/552

  • [GG18] https://eprint.iacr.org/2019/114

  • [GG20] https://eprint.iacr.org/2020/540

  • [CGGMP] https://eprint.iacr.org/2021/060

  • 1:06:50 The Dörner paper.

  • [DKLS18] https://eprint.iacr.org/2018/499

  • [DKLS19] https://eprint.iacr.org/2019/523

  • 1:07:57 Tweaking generic MPC to handle group operations.

  • Securing DNSSEC Keys via Threshold ECDSA From Generic MPC

  • https://eprint.iacr.org/2019/889

  • 1:10:45 Using triples to isolate the complexity into a pre-processing phase.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

  • 00:54 What are threshold signatures?

  • 04:33 Example use-case: code signing.

  • 06:50 Example use-case: asset custody.

  • 11:08 Example use-case: validators.

  • 14:30 What kind of signatures are usually thresholdized?

  • What makes Schnorr signatures easier to thresholdize: https://cronokirby.com/posts/2021/07/signatures_from_identification/

  • 20:10 How distributed key generation works, at a high level.

  • 27:34 On the utility of key refresh.

  • 30:50 On the utility of pre-signatures

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

4:20 The difficulties in comparing SNARKs together

14:52 SNARKs with varying security parameters

Justin Thaler’s blog post on SNARK security parameters.

https://a16zcrypto.com/snark-security-and-performance/

25:35 A proposal for a uniform benchmarking system for SNARKs.

28:40 It would be nice to be able to compare the cost of different gadgets.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

1:40 The fundamental advantage of an attacker.

3:02 The need for threat modelling.

5:49 Security games.

13:13 What does it mean for games to be secure?

15:43 How do you prove that no adversary can break a game?

19:24 What kind of cryptographic assumptions are there?

28:58 How modelling security can fail in practice?

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

1:30 What the Fiat-Shamir transform is.

6:50 What you need to include in the hash function.

11:35 Rewindable soundness for multi-round protocols.

15:36 What to hash over multiple rounds?

19:25 Merlin & Magikitten

https://merlin.cool

https://github.com/cronokirby/magikitten

31:18 A note on sponge functions.

34:06 Some thoughts on SAFE

(SAFE) https://hackmd.io/bHgsH6mMStCVibM_wYvb2w

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

0:00 “On Security Against Time Traveling Adversaries”

https://eprint.iacr.org/2022/1148

3:47 Why time travel is sort of relevant to Cryptography.

5:53 “On the effectiveness of time travel to inject covid-19 alerts”

https://eprint.iacr.org/2020/1393

10:42 A brief primer on security games.

15:30 Creating a uniform grame for cryptographic schemes.

20:37 The basics of time travel.

23:12 Rewinding back one step.

26:26 Rewinding many steps backwards.

28:13 The forking model of time travel.

31:14 The stack restriction on forking.

34:14 Forking without restrictions.

40:48 How time travel can break some games for encryption and signatures.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

00:28 On using ZK Proofs in the context of Machine Learning.

14:00 On the centralized force of ML.

25:00 On economies of scale in ZK proving.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

00:50 What exactly counts as a SNARK?

08:12 SNARKs with sublinear verification time

12:34 Algebraic Automatons and structured computation

Linear-Time Probabilistic Proofs Over Every Field: https://eprint.iacr.org/2022/1056

16:59 On the limits of structured computation

Miden VM: https://maticnetwork.github.io/miden/intro/main.html

21:17 Why Boolean Circuits are more natural than Arithmetic Circuits

Measuring SNARK performance - Justin Thaler: https://a16zcrypto.com/measuring-snark-performance-frontends-backends-and-the-future/

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

00:43 Models of security for MPC.

07:00 To what extent is the Semi-Honest model useful?

11:15 Connecting MPC with consensus

19:42 On identifiable aborts.

A blog post of mine on the subject: https://cronokirby.com/posts/2022/06/on-identifiable-aborts/

28:00 Some thoughts on block producer privacy

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

1:00 ZK Proofs + MPC in the head recap.

2:57 Boolean circuits and their representations

14:11 Why WASM is an interesting bytecode, and thoughts on compiling WASM to circuits.

19:40 A few thoughts on my Rem-Boo project

Rem-Boo: https://github.com/cronokirby/rem-boo

Reverie (not by me, but mentioned here): https://github.com/trailofbits/reverie/

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics covered in this episode:

0:55 What is Tornado Cash (briefly).

2:00 The U.S. Treasury sanctions Tornado Cash.

https://home.treasury.gov/news/press-releases/jy0916

4:35 How Tornado Cash works, from the bottom up.

15:19 Why smart contracts are really a “service”.

19:27 Broader consequences of this decision.

28:00 How I’d like to see regulation in this space evolve.

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe.

If you want even more updates, feel free to follow me on Twitter.

View Details

Topics covered in this episode:

1:42 Introduction to Zero-Knowledge Proofs.

7:07 What MPC in the head achieves, at a high level.

14:35 The efficiency of MPC in the head.

15:56 What is “MPC” anyways?

18:37 How MPC in the head works, at a high level.

20:38 An overview of the IKOS paper: the one that started it all.

https://web.cs.ucla.edu/~rafail/PUBLIC/77.pdf (2007)

“Zero-Knowledge from Secure Multiparty Computation” - Yuval Ishai, Eyal Kushilevitz, Rafail Ostrovsky, and Amit Sahai

31:05 The ZKBoo paper: making MPC in the head practical.

https://eprint.iacr.org/2016/163

“ZKBoo: Faster Zero-Knowledge for Boolean Circuits“ - Irene Giacomelli, Jesper Madsen, and Claudio Orlandi

My implementation of ZKBoo: https://github.com/cronokirby/boo-hoo

41:22 The KKW paper: adding pre-processing to simulated MPC.

https://eprint.iacr.org/2018/475

“Improved Non-Interactive Zero Knowledge with Applications to Post-Quantum Signatures” - Jonathan Katz, Vladimir Kolesnikov, and Xiao Wang

48:32 The core idea of the Limbo paper: verifying execution traces.

https://eprint.iacr.org/2021/215

“Limbo: Efficient Zero-knowledge MPCitH-based Arguments“ - Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, and Titouan Tanguy

51:07 What distinguishes Ligero from other MPC in the head systems: Sqrt(N) complexity.

https://acmccs.github.io/papers/p2087-amesA.pdf

“Ligero: Lightweight Sublinear Arguments without a trusted setup” - Scott Ames, Carmit Hazy, Yuval Ishai, an dMuthuramakrishnan Venkitasubramaniam

54:10 The “Rambo” paper: how to add RAM to ZK proof programs.

https://eprint.iacr.org/2022/313.pdf

“Efficient Proof of RAM Programs from Any Public-Coin
Zero-Knowledge System” - Cyprien Delpech de Saint Guilhem, Emmanuela Orsini, Titouan Tanguy, and Michiel Verbauwhede

1:03:10 My project, Rem-Boo

https://github.com/cronokirby/rem-boo

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics in this episode:

The recent breakage of SIDH

https://ellipticnews.wordpress.com/2022/07/31/breaking-supersingular-isogeny-diffie-hellman-sidh/

https://eprint.iacr.org/2022/975

A taxonomy of different cryptographic constructions

What constructions are better suited for standards? What about software?

Why is it hard to provide protocols as a library?

Why threat modelling and security properties will always be important

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics in this episode:

The emerging threat of quantum computers and their impact on Cryptography

How NIST’s standardization process works, briefly, and why you don’t need to trust NIST at all.

How you might upgrade messaging protocols to the Post-Quantum age

Implementing Post-Quantum key exchanges with deniable signatures

How much metadata can a centralized E2E messaging server record?

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com

View Details

Topics in this episode

Papers with long appendices

Adding a boolean circuit backend to LLVM

Composing STARKs with SNARKs, and how this compares to MPC in the head

If you enjoyed this episode, and want to get notified when the next one arrives, feel free to subscribe:

If you want even more updates, feel free to follow me on Twitter.

This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit cronokirby.substack.com