3 ms·
I didn't write any protocols, didn't design any schemes in the chain of communication; the "engineers" sourced different people for different parts for obvious
by hackermom 16y ago
I didn't write any protocols, didn't design any schemes in the chain of communication; the "engineers" sourced different people for different parts for obvious reasons. I wrote the ADPCM codec for the audio and the bare crypto component. My implementation allowed both EBC and CBC modes. I know keys were randomized for each handheld by the exchange every time an employee checked out a handheld.
- tptacek 16y agoSo basically, and excuse the snark here because I really don't think you're dumb or anything, but... you have a lot of very strong opinions about whether developers should be able to use a 17-year old 64-bit block cipher, but not a lot of opinions about anything that goes into making a block cipher construction secure. (Why did you allow ECB to be used?)
- hackermom 16y agoI think you're (again) falsely assuming something here. I definitely have opinions about what modes of operation should be used for a cipher, as it's yet another sensitive link in the chain. ECB operation was added because the head above me requested it to be there, not from my design choice. I think your fervent and, with all respect to your undebatable knowledge in this topic, priggish nature makes you prone to turn discussions into "unstoppable force meets immovable object" farces, if you understand what I mean, so let's just agree on disagreeing about ciphers :)
- tptacek 16y agoSorry, but I wouldn't have lasted very long in this field if "fear of sounding priggish" had a major impact on my behavior, so let me give this to you straight: In response to SJCL, a library implemented by bona fide cryptographers that at least attempts to capture some of the pitfalls of doing crypto code, you, because of the fact that the library doesn't offer the obsolete Blowfish cipher, recommended: * A Blowfish library that implements only the terribly insecure ECB block cipher mode, which you wouldn't know unless you looked at the code since it doesn't call it "ECB" * A library that claims to implement CBC mode but in fact implements ECB mode, and, as an added bonus, implements RSA as nothing but a wrapper around bignum math. * A library that implements CBC mode --- though without control over IVs --- but only for AES; Blowfish is stuck in ECB mode. Recall your reason for citing the library was "access to things like Blowfish". I'm sorry, but you just gave really bad advice. Give better advice and I promise I'll be less of a twat. I am, for the record, not a crypto expert. Colin Percival is our resident crypto expert. All I know is what I know. In this case, that includes: don't do what 'hackermom just said to do.
- rleffmann 16y agostumbled over this via the referrer list on my host and thought i'd just add something for the record: my jsbfsh does cbc only, not ecb. i think the one making guesses instead of looking at code was you ;-) this was a very interesting and complementing discussion thread.