[HN Gopher] Why Did Satoshi Decide to Use Secp256k1 Instead of S...
       ___________________________________________________________________
        
       Why Did Satoshi Decide to Use Secp256k1 Instead of Secp256r1?
        
       Author : g42gregory
       Score  : 70 points
       Date   : 2021-10-09 21:05 UTC (1 hours ago)
        
 (HTM) web link (dappworks.com)
 (TXT) w3m dump (dappworks.com)
        
       | AlexCoventry wrote:
       | > secp256k1 is a Koblitz curve which is defined in a
       | characteristic 2 finite field,
       | 
       | Secp256k1's base field size is a 256-bit prime. What does he
       | mean?
        
         | gizmo686 wrote:
         | The bitcoin wiki explicitly says that secp256k1 is not
         | characteristic 2:
         | 
         | > secp256k1 has characteristic p, it is defined over the prime
         | field Zp. Some other curves in common use have characteristic
         | 2, and are defined over a binary Galois field GF(2^n), but
         | secp256k1 is not one of them.
         | 
         | https://en.bitcoin.it/wiki/Secp256k1
        
       | nullc wrote:
       | Garbage spam page. This shouldn't be on HN. There is a common
       | trend for people to take highly technical subjects do a tiny
       | amount of research and then spam up some page (often full of
       | plagerism) in order to add bulk to their sites. This is
       | especially common in the "defi / ico" fraud ecosystem.
       | 
       | In this case the article is so poorly researched that even though
       | it says fairly little it manages to make outright false claims
       | about basic facts, e.g. "secp256k1 is a Koblitz curve which is
       | defined in a characteristic 2 finite field, while secp256r1 is a
       | prime field curve"-- which is false, secp256k1 uses a prime
       | field.
        
       | 0des wrote:
       | Well, for one, iirc Secp256r1 was pseudo random and can be seen
       | glowing in broad daylight.
        
         | fidesomnes wrote:
         | top reply of the year.
        
         | snypher wrote:
         | From here[1], even the two a,b values seem suspicious:
         | 
         | k curve                 a = 0       b = 7
         | 
         | r curve                 a = FFFFFFFF 00000001 00000000 00000000
         | 00000000 FFFFFFFF FFFFFFFF FFFFFFFC       b = 5AC635D8 AA3A93E7
         | B3EBBD55 769886BC 651D06B0 CC53B0F6 3BCE3C3E 27D2604B
         | 
         | [1]https://www.johndcook.com/blog/2018/08/21/a-tale-of-two-
         | elli...
        
         | themodelplumber wrote:
         | Glowing...is this metaphorical or some industry term?
        
           | 0des wrote:
           | Saying that something 'glows in the dark' implies
           | interference, so unfortunately, within cryptography, it has
           | become an industry term as well as metaphor.
           | 
           | Other examples are the 'mystery padding' in keccak vs sha3.
        
             | stavros wrote:
             | Isn't Keccak SHA3?
        
               | 0des wrote:
               | no, keccak is keccak, sha3 is keccak with NIST's mystery
               | padding added in.
        
             | Ar-Curunir wrote:
             | I've never heard a cryptographer use "glow-in-the-dark"
             | when talking about potentially fishy schemes.
             | 
             | Source: am cryptographer
        
             | Jensson wrote:
             | I read the 3 replies and I still don't know what glowing
             | means in cryptographic terms. I even tried to google it
             | with cryptography added but nothing.
        
               | ajb wrote:
               | It means that the designer may have inserted an
               | unpublished weakness. See also
               | https://en.m.wikipedia.org/wiki/Nothing-up-my-
               | sleeve_number
        
               | 0des wrote:
               | As in the case of Keccak and SHA3, it doesn't necessarily
               | have to be the designer, it can also be the reviewing
               | committee.
        
               | roxaaaane wrote:
               | It's probably metaphorical, to mean distinguishable ?!
               | And the term has never been used in crypto
        
               | 0des wrote:
               | I respectfully disagree, perhaps in your circles you have
               | a point, but this is a common term.
        
               | smoldesu wrote:
               | It's imageboard/IRC slang, you won't find any
               | documentation on it because it's an intentionally
               | obfuscated/dogwhistle phrase intended to only 'make
               | sense' to other browsers who've stuck around long enough
               | to get spoonfed.
        
               | 0des wrote:
               | Using the term 'dogwhistle' seems like a divisive way to
               | discount what I said. Do you care to articulate yourself
               | in a way that addresses the actual substance of what I
               | said, or is this it?
        
               | metagame wrote:
               | "Glowing" means that it's probably a plot of a
               | government. It's not cryptography-specific.
        
           | sva_ wrote:
           | It's a reference to schizophrenic Terry Davis (rip), author
           | of TempleOS, who said CIA agents would glow in the dark, and
           | got popularized through the 4chan /g/ board.
           | 
           | https://www.urbandictionary.com/define.php?term=Glows%20in%2.
           | ..
        
             | serf wrote:
             | weird intersection of the internet.
             | 
             | Terry is/was an HN native, too.
             | 
             | Upvoting all of his shadowbanned stuff that was half-way
             | decent and lucid was a hobby of mine. It still makes me
             | feel good to think about it.
             | 
             | Godspeed Terry.
             | 
             | https://news.ycombinator.com/item?id=7818823
        
               | jcun4128 wrote:
               | I watched some of his live streams, saw some cool things
               | but man the things he would say
        
               | 0des wrote:
               | If we were not meant to distinguish creation from
               | creator, we'd be in a world of trouble. Also, he was
               | quite ill, I'm not sure we can fault him for some of his
               | mannerisms while also admiring his ambition and skill.
        
               | 0des wrote:
               | Hello fellow stranger ;)
        
               | jfoutz wrote:
               | I vouched for a few of his comments as well. I definitely
               | think about how a quirk of biology or environment could
               | flip the wrong switch in my brain.
               | 
               | There are millions of sob stories. I don't do as much as
               | I could, but I do more than nothing to help people out.
               | That one, Terry Davis, keeps me up at night sometimes.
        
               | 0des wrote:
               | Hindsight is 20/20, all we can do is learn for next time.
        
           | collegeburner wrote:
           | Glowie refers to a fed, it started with the templeos guy but
           | is more general now. Glowing means its a fed op to weaken
           | crypto, kinda like the dual ec fiasco.
        
             | [deleted]
        
           | Strilanc wrote:
           | They're saying they don't trust that the constants defining
           | the curve were chosen non-maliciously. The NSA has, in the
           | past, standardized protocols that contained intentional
           | backdoors embedded into the constants used in the definition
           | [1]. Because of things like that, it's desirable for
           | cryptographic protocols to use constants chosen in some way
           | that makes backdooring intractable [2].
           | 
           | 1: https://en.wikipedia.org/wiki/Dual_EC_DRBG
           | 
           | 2: https://en.wikipedia.org/wiki/Nothing-up-my-sleeve_number
        
       | pluc wrote:
       | please refer to him as The Enlightened One
        
       | woliveirajr wrote:
       | > These curves were chosen actually for efficiency not security
       | 
       | Isn't this enough?
        
         | darig wrote:
         | "efficiency" means not having to deal with federal goons and
         | NDAs, and instead do what they say before your family is
         | suicided.
        
       | darthvoldemort wrote:
       | I wonder if you could track down who Satoshi is based on
       | someone's search queries about Secp256k1 specifically
        
         | vbezhenar wrote:
         | If he was careful, probably he would have used Tor for his
         | searches.
         | 
         | But I think that NSA-level organization knows who Satoshi is.
         | It's hard to imagine how one would be able to work on such a
         | project, without any background that could be tracked.
        
         | tediousdemise wrote:
         | This is dark... I bet Satoshi is also a regular user of this
         | website.
        
       | sentinel wrote:
       | Any recommendations for courses or books that give a 101 intro
       | all the way to understanding these curves and why / how they are
       | used?
       | 
       | I'd like to get a grasp on this from first principles. Thank you!
        
         | roxaaaane wrote:
         | Hankerson, Menezes, Vanstone [1] covers almost everything about
         | Elliptic Curves and ECC (Theory and Implementation)
         | 
         | [1]:https://cacr.uwaterloo.ca/ecc/
        
           | [deleted]
        
         | flixic wrote:
         | This is a pretty good intro article:
         | https://andrea.corbellini.name/2015/05/17/elliptic-curve-cry...
        
         | R0b0t1 wrote:
         | Wikipedia, honestly. For background math you may want to rely
         | on the citations or other provided texts but a lot of articles
         | have great examples sections.
         | 
         | But... I think you need a more coherent goal than just
         | "understand the math." You can superficially understand the
         | math when guided, but without any reason to retain it I am not
         | sure what you will gain from the experience.
        
           | tdeck wrote:
           | > You can superficially understand the math when guided, but
           | without any reason to retain it I am not sure what you will
           | gain from the experience.
           | 
           | This has been my experience with almost everything I ever
           | learned about math, much of which I have unfortunately not
           | retained.
        
         | Dig1t wrote:
         | This blog post from Cloudflare proved incredibly useful to me
         | when I was trying to understand this stuff for the first time.
         | The animated gifs about halfway down the page are particularly
         | useful: https://blog.cloudflare.com/a-relatively-easy-to-
         | understand-...
        
       ___________________________________________________________________
       (page generated 2021-10-09 23:00 UTC)