Explore a presentation from Crypto 2018 on correcting subverted random oracles, delving into the vulnerabilities of hash functions and proposed solutions. Learn about hash implementation optimization, subversion attacks, chain takeover attacks, and methods to repair compromised hash functions. Examine the modeling and analysis of correcting subverted random oracles, including the rejection resampling lemma and final construction. Gain insights into preventing chain takeovers and consider open problems in this critical area of cryptography.