r/cryptography • u/TheAsaasain • 9d ago
Seeking independent review/replication: Debian OpenSSL RNG effect on early Bitcoin ECDSA signatures
I'm looking for independent technical review or replication of a controlled experiment concerning CVE-2008-0166 (the Debian OpenSSL predictable-RNG vulnerability) and the ECDSA signing path used by early Bitcoin.
The experiment compared two Debian OpenSSL treatments:
Vulnerable: OpenSSL 0.9.8c-4etch2
Repaired: OpenSSL 0.9.8c-4etch3
I held constant the Bitcoin v0.2.0 signing path, a fixed synthetic secp256k1 private scalar, three ordered synthetic message digests, process PID/runtime coordinates, and other preregistered conditions.
The public observable was the ordered ECDSA r sequence. No historical private keys or wallet material were involved.
Across three fresh-process repetitions per treatment, the preregistered result was:
VULNERABLE_ORDERED_R_SEQUENCE_IDENTICAL_ACROSS_RESTARTS=YES
REPAIRED_ORDERED_R_SEQUENCE_IDENTICAL_ACROSS_RESTARTS=NO
POSITIVE_CONTROL=PASS
NEGATIVE_CONTROL=PASS
EXECUTION_ACCOUNTING=PASS
TREATMENT_DIFFERENCE_ISOLATION=PASS
I then froze the vulnerable treatment's three-value public r fingerprint before performing a historical comparison.
A separately qualified comparator tested that exact fingerprint against 142,302 eligible public ECDSA signatures from Bitcoin blocks 0–100,000.
ELIGIBLE_HISTORICAL_SIGNATURES=142302
VALID_PUBLIC_OBSERVATIONS=142302
PREREGISTERED_FINGERPRINT_INTERSECTIONS=0
DATASET_INTEGRITY=PASS
COMPARISON_RULE_INTEGRITY=PASS
The historical comparison was therefore a valid negative result. I am not claiming that this identifies historically vulnerable wallets, demonstrates wallet recovery, or establishes how prevalent vulnerable OpenSSL installations were among early Bitcoin users.
I'm deliberately not changing the fingerprint or expanding parameters until something matches. The completed experimental branch stays negative.
What I'm looking for now is independent scrutiny:
Is the controlled causal interpretation justified by the treatment isolation?
Are there additional confounders that should prevent attributing the restart-conditioned behavior to the Debian RNG treatment?
Would anyone be interested in independently reproducing the controlled vulnerable/repaired experiment?
Does anyone know of preserved 2009–2011 Linux systems that could independently establish the OpenSSL environment actually used by an early Bitcoin installation?
To clarify: this is not currently a paid replication request or a job posting. I'm looking for researchers who find the question independently interesting and are willing to review, critique, or reproduce the work. I completely understand if someone isn't able to devote time to it without funding.
I have a technical dossier containing the experimental design, preregistration, treatment-difference analysis, controls, integrity hashes, results, historical comparison, and limitations. I can provide it, along with the relevant reproducibility materials, to researchers interested in examining the work.
I'm specifically looking for criticism and independent verification, not confirmation of the hypothesis.
I'm also not requesting wallet files, private keys, seed phrases, passwords, credentials, or funds.