3 ms·
Some years ago I wrote custom software for voice/memo and messaging (incl. storage) for a cellphone-based intercom system used in one or more of Pricewaterhouse
by hackermom 16y ago
Some years ago I wrote custom software for voice/memo and messaging (incl. storage) for a cellphone-based intercom system used in one or more of PricewaterhouseCoopers' establishments here in Sweden. Their offices residing in public complexes prompted the concern for privacy, and they wanted a communications system of their own rather than relying on GSM intercom or buying in on other solutions available at large on the market. I chose Blowfish because I knew I could make it run faster (read: lower power consumption) than AES or any other applicable cipher, which was a priority for their handheld devices, and because I knew that it wasn't at risk of being broken.
- tptacek 16y agoWhat cipher mode did you use, how did you establish keys, what parts of messages were encrypted vs. not encrypted (control channel, call setup, keepalives, audio frames, etc), and how did you protect integrity? (That's my followup question).
- hackermom 16y agoI didn't write any protocols, didn't design any schemes in the chain of communication; the "engineers" sourced different people for different parts for obvious reasons. I wrote the ADPCM codec for the audio and the bare crypto component. My implementation allowed both EBC and CBC modes. I know keys were randomized for each handheld by the exchange every time an employee checked out a handheld.
- tptacek 16y agoSo basically, and excuse the snark here because I really don't think you're dumb or anything, but... you have a lot of very strong opinions about whether developers should be able to use a 17-year old 64-bit block cipher, but not a lot of opinions about anything that goes into making a block cipher construction secure. (Why did you allow ECB to be used?)
- hackermom 16y agoI think you're (again) falsely assuming something here. I definitely have opinions about what modes of operation should be used for a cipher, as it's yet another sensitive link in the chain. ECB operation was added because the head above me requested it to be there, not from my design choice. I think your fervent and, with all respect to your undebatable knowledge in this topic, priggish nature makes you prone to turn discussions into "unstoppable force meets immovable object" farces, if you understand what I mean, so let's just agree on disagreeing about ciphers :)
- tptacek 16y agoSorry, but I wouldn't have lasted very long in this field if "fear of sounding priggish" had a major impact on my behavior, so let me give this to you straight: In response to SJCL, a library implemented by bona fide cryptographers that at least attempts to capture some of the pitfalls of doing crypto code, you, because of the fact that the library doesn't offer the obsolete Blowfish cipher, recommended: * A Blowfish library that implements only the terribly insecure ECB block cipher mode, which you wouldn't know unless you looked at the code since it doesn't call it "ECB" * A library that claims to implement CBC mode but in fact implements ECB mode, and, as an added bonus, implements RSA as nothing but a wrapper around bignum math. * A library that implements CBC mode --- though without control over IVs --- but only for AES; Blowfish is stuck in ECB mode. Recall your reason for citing the library was "access to things like Blowfish". I'm sorry, but you just gave really bad advice. Give better advice and I promise I'll be less of a twat. I am, for the record, not a crypto expert. Colin Percival is our resident crypto expert. All I know is what I know. In this case, that includes: don't do what 'hackermom just said to do.
- rleffmann 16y agostumbled over this via the referrer list on my host and thought i'd just add something for the record: my jsbfsh does cbc only, not ecb. i think the one making guesses instead of looking at code was you ;-) this was a very interesting and complementing discussion thread.