Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sean and Kelby do a much better job of describing what LLL is, but this is maybe the best explanation of why LLL is that I've ever read. In all three cases, you only need basic linear algebra, if that (Kelby wants you to grok Gram-Schmidt, which is like just before the midterm of an undergrad linear algebra 101).

I really don't have words for how great this post is. It made my week.

Later

A really concise explanation of the same process you can step through in Python:

https://crypto.stackexchange.com/questions/37836/problem-wit...



Personally I think https://crypto.stackexchange.com/a/86548 is a better answer. It turns the LCG state recovery into a hidden number-like problem, and works out the solution that way. It is easy to go from there to (EC)DSA key recovery.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: