All you need is these two numbers:
The number of known points (240 in the example so far)
Excuse if this is silly question because my understanding of this is very limited - but 2
40 is not a very big number, it's around 1 Terra. Since, to my understanding, Y coordinate is not very important because it is binary determined by the X coord and the sign +1/-1, there's only 32 bytes * 1 Terra = 32TB of data to check, which is well within range of todays disk arrays. This shouldn't be hard to check against, should it?
So, is this the correct explanation of the attack method:
- You need 2
40 X coordinates which have the 32 least significant bits matched to the X coord of the attacked public key, and all 2
40 with known private keys. That's what we've been doing in the other thread, collected 8 million of them in a few days
- You go through the sequence n*G, (n+1)*G, (n+2)*G ... (n+k)*G and check only those 32 bits for a match
- If you find a match, you check the X coord against the 32TB of data with known private keys
- If you find a match there you calculate found secret - k to get unknown private key
- If not you add 1 to k and repeat the process
Is this the correct attack vector? It looks too simple to me, I've must have misunderstood something.