4 ms·
It looks like the implementors failed to follow the recommended usage and design (and indeed common sense) of the algorithm: * They used 16 bit math instead of
by SolarNet 10y ago
It looks like the implementors failed to follow the recommended usage and design (and indeed common sense) of the algorithm:
* They used 16 bit math instead of 32 bit math (with, I'm assuming, a 32 bit output size rather than the recommended 64 bit output). Which has the effect of looking like 10 rounds, but it's a rather more serious security failure.
* They generated keys in the alphanumeric range (instead of the full byte range) significantly reducing entropy.
All which seems to have weakened it substantially (understatement).
- danbruc 10y agoI read that on the GitHub page but I am still having a hard time imagining that those changes weaken the function enough to become attackable by a genetic algorithm. According to my intuition even relatively weak cryptographic functions should be pretty hard to tackle by genetic algorithms due to the complex structure of the search space with many extrema. Maybe I will have a closer look tomorrow, I am starting to get really curious.
- SolarNet 10y agoI think the limited key space is a large part of the answer, 46 lopsided choices is easier to learn about than 256 equally distributed choices. The smaller word width probably makes the memory requirements reasonable.