$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: a CSIDH decisional-Diffie-Hellman challenge over GF(p) with p=2*prod(ls)-1 (so p==1 mod 4), publishing 63 triples (EA,EB,EC) encoding the bits of an 8-byte SECRET; bit=1 means EC is the true CSIDH shared curve, bit=0 means EC is random. Recover SECRET to AES-decrypt the flag. Solution: because p==1 (mod 4) the class group of Z[sqrt(-p)] has 2-torsion, so genus theory (Castryck-Sotakova-Vercauteren, CRYPTO 2020) gives a freely computable QUARTIC character D(E)=b^((p-1)/4) over GF(p) (b = linear coefficient after moving the rational 2-torsion point to the origin). D is a homomorphism on the class-group action, so D(shared)=D(EA)*D(EB)/D(base) deterministically while a random EC is uncorrelated, yielding an exact DDH distinguisher with zero errors. The 'backdoor/secret_marks' is a decoy.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar