Hidden Secret
1 - secrets.randbelow(3) is a uniform trit in {-1, 0, 1}, so each published sample is with one secret multiplier a, one secret evaluation point x, and 7 secret ternary polynomials of degree < 40. The AES key is sha256(str(x)), so x must be recovered exactly — nothing less will do.
PDF not displaying? Download it instead.
Something wrong with this page?
Wrong details, a stolen writeup, or something that should not be published here — tell a moderator. This does not go to the author.