5 ms·
RC4 No More
- SerpentJoe 11y agoThe page makes use of numeric expressions like 9x2^27. What's with the choice of exponent? Why not e.g. 1.125x2^30?
- Sanddancer 11y agoIt's fairly normal in crypto papers to express vulnerabilities and potential vulnerabilities in base two, as so many other bits of crypto, like key sizes, etc, are also expressed in that base.
- Freaky 11y agoHe's questioning normalisation, not base. "Just over 2^30" is a bit more intuitive than "Just under ten times 2^27".
- gipsies 11y agoBecause in the paper they tested the attack with 1x2^27 requests, then with 2x2^27 requests, then 3x2^27, etc etc.
- beefhash 11y agoIf I may ask a potentially silly question, does this have any security implications for RC4-based random number generators (notably, FreeBSD arc4random[1] and libbsd arc4random[2]; OpenBSD and NetBSD seem to have replaced their arc4random with a ChaCha-based RNG around 2013)? [1] https://svnweb.freebsd.org/base/release/10.1.0/lib/libc/gen/arc4random.c?revision=274417&view=markup https://svnweb.freebsd.org/base/release/10.1.0/lib/libc/gen/... [2] http://cgit.freedesktop.org/libbsd/tree/src/arc4random.c http://cgit.freedesktop.org/libbsd/tree/src/arc4random.c
- tedunangst 11y agoYes and no. Practical exploitation depends on how the RNG is being used. The good news is that, as noted, replacement code is available for those who want it.
- sctb 11y agoPrevious discussion: https://news.ycombinator.com/item?id=9892157 https://news.ycombinator.com/item?id=9892157