Hacker News new | ask | show | jobs
by rgreen 977 days ago
I’m not sure how seeing the generating text would give people confidence that the seeds don’t have certain properties that are useful for cryptanalysis. It’s the same issue with nothing-up-my-sleeve constants. If they aren’t agreed upon before design begins, you could iterate on an infinite set of benign-looking constants until you found a set with desirable properties.
1 comments

It's only if there's a relatively big class of weak curves that you know about that you can find a seed that generates one. It can't be a small set of degenerate cases.

So it definitely adds some confidence.