|
|
|
|
|
by quantumgarbage
336 days ago
|
|
Yes, what you are missing is that attacks on Fiat Shamir were very contrived up to now. However the paper shows that there in fact exists a pretty simple way to break the Fiat Shamir heuristic, for a protocol operating in the RO model. And such kind of efficient attacks are rather concerning in cryptography land. So this isn't about the attack per se, rather it's about the existence of such an easy one. |
|