$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: a complete SIDH key-exchange transcript (p=45*2^117*3^73-1) publishing both public curves AND the torsion images phiA(P3),phiA(Q3),phiB(P2),phiB(Q2); recover the shared secret to decrypt. Solution: the 2022 Castryck-Decru polynomial-time SIDH break — Kani's theorem turns the published torsion images into a (2^a)-isogeny between products of elliptic curves whose existence is detected by a 'glue-and-split' of genus-2 Richelot isogenies, recovering Bob's ternary secret digit by digit. Used the Oudompheng-Pope Castryck-Decru-SageMath reference, adapted for cofactor f=45 and the CM starting curve y^2=x^3+x (custom 2i endomorphism), and patched for a SageMath 9.5->10.x Mumford-divisor API change; recovers sB in ~8s, then shared=j(E_AB) decrypts the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar