3 ms·
So is there a per-chunk MAC, or do you rely on the signed hashes of ciphertext for the integrity and authenticity of each chunk?
by swordswinger12 10y ago
So is there a per-chunk MAC, or do you rely on the signed hashes of ciphertext for the integrity and authenticity of each chunk?
- GamePad64 10y agoActually, there is per-chunk HMAC support in the protocol and present revisions add HMAC for each chunk into Meta: https://github.com/Librevault/librevault-common/blob/master/src/Meta_s.proto#L68 https://github.com/Librevault/librevault-common/blob/master/... This HMAC is computed over plaintext chunks and used to determine, if we already have this chunk in database (because of random IV we get different hash of ciphertext every time), not for verification. And what is wrong about verifying integrity and authenticity by hash-then-sign?
- swordswinger12 10y agoMaybe nothing, but it's just kind of a weird, nonstandard way of doing things. Also it's not immediately obvious to me that your method meets modern security definitions like IND-CCA2.