4 ms·
Explain to us instead what security concerns there are with the cipher. As you mention DES and 3DES, known to be very vulnerable today, you are implying that yo
by hackermom 16y ago
Explain to us instead what security concerns there are with the cipher. As you mention DES and 3DES, known to be very vulnerable today, you are implying that you know of security issues with the Blowfish cipher, so, please enlighten us - what is that all of the cryptographers in the world except you have completely missed regarding cryptanalysis and weaknesses of this cipher?
Please don't bring any performance claims up, because if you are really as familiar with Blowfish as you appear to imply, then you know very well that with a proper implementation (and there as many bad ones as good ones) it outperforms all of the AES ciphers by several times. Also don't bring up the "incredibly slow" key schedule as a valid point of "why no one should ever use it", because it's not really slow, even by yesterday's measures of computational power.
add.: I'll give you a few reasons of why the cipher is still interesting just for the sake of the discussion :)
1) same encryption time regardless key size - 448 bits of key perform just as fast as 8 bits.
2) very sophisticated s-box/key schedule - trying to brute force the cipher is practically impossible as the raw key is not used in the encryption/decryption process itself, and performing the s-box setup for every bit of possible key pushes the brute force process back a few orders of magnitude in speed, and, trying to brute force by traversing the p- and s-boxes, all 8768 bits worth, just ain't happening today.... or tomorrow.
3) performance - among the (so far) unbroken ciphers, it's quite possibly the fastest one.
- tptacek 16y agoHere's one that's easy to understand: it shares with DES and 3DES an 8-byte block size, which makes a bunch of integrity exploits easier to write. Schneier, who has all but disavowed Blowfish, would also point out that a 64 bit block size gives you a little less than 2^32 block encryptions under the same key before you run into statistical hazards, but I don't care about that. The block size / integrity issue is a pragmatic complaint, but the real issue here is: why on earth would you use Blowfish instead of AES when AES has received many multiples as much scrutiny as Blowfish? Regarding Twofish, the successor to Blowfish, Schneier writes in _Practical_: That [~10 grafs preceding] does not leave a lot of room for Twofish. You should only choose Twofish [again, Twofish, not the obsoleted Blowfish] if you want the speed of AES without the security disadvantages listed above. Of course, all the institutional advantages of AES will now weigh against you. If Twofish is ever broken, you will be blamed for selecting it. I think you can probably tell that the reason I commented about using anything but AES has less to do with the specifics of Blowfish --- which, again, are unfavorable --- and more to do with the concept of selecting libraries solely for the purpose of writing vanity crypto. Cryptosystems that use Blowfish are vanity systems. Let's be very clear that I could give a fuck how fast a cipher is. Smarter people than me who have spent more of their lives on this problem have optimized the universe of acceptable ciphers for speed already. That universe does not include Blowfish (or, for that matter, Twofish --- although who knows, that could eventually change).
- hackermom 16y agoI really can't see any compelling point here of why Blowfish should be avoided when the case is that its benefits panders well towards the intended means, just because there are obvious risks involved - as with all ciphers. These risks you point out exist today in one flavor or the other for AES as well; exploits loom around them, too (and to be fair, AES, too, has its fair share of dangers that Blowfish is immune to), but you seem inclined to ignore AES' case seemingly only because of its young age. Mind you, Blowfish has had its share of prying eyes, too, but I don't think that the amount of scrutiny involved in these two ciphers weighs particularly much at this point when both ciphers are still unbroken. What you're laying forth in AES' favor is really the exact same tune people sang in favor of DES 20 years ago. I find it ironic that, given Blowfish's strengths, you pass all of its use in modern software off as plain, simple vanity. Is OpenBSD's use of Blowfish vain in any way what so ever? Is interest in, or a requirement of, high performance or a compact codebase vanity? And, just to end your weird assumption, let's also be clear that I threw out examples of cryptography libraries for the surplus value of having additional choices at hand, not in any was as passing out advices on what ciphers to use for what purpose. I don't like when people imply that I'm an indoctrinating zealot.
- tptacek 16y ago(a) Yes, OpenBSD's use of Blowfish was a vanity move (outside of bcrypt, which takes special advantage of a Blowfish quirk in a setting where Blowfish's other disadvantages aren't relevant). But it's also an understandable one, since OpenBSD's adoption of Blowfish predates even Rijndael. (b) The risks of using a cipher with a 64 bit block size are simple and pragmatic, and there's almost certainly no offsetting advantages. (c) I don't understand any of the rest of your arguments. I don't think you're an "indoctrinating zealot" (at least, I don't think I think that; I don't know what you mean.) (d) Choice in cryptography is bad. This is not a 'tptacek idiosyncracy. Ferguson and Schneier's book has essentially that principal as its thesis. So do the modern crypto libraries. You seem to have some background with this material. Can you tell me about a system you've implemented that used Blowfish, or any selectable or negotiated block cipher? I'm curious (and have a follow-up question).