3 ms·
What are some constructions you'd consider "fair"?
by CiPHPerCoder 9y ago
What are some constructions you'd consider "fair"?
- Quiark 9y agoAEAD cipher with nonce generated from plaintext? That would have equivalent security properties except for being needlessly complicated?
- CiPHPerCoder 9y agoSo you mean something like this? $nonce = sodium_crypto_generichash($message, '', 24); $ciphertext = $nonce . sodium_crypto_aead_xchacha20poly1305_ietf_encrypt( $message, $nonce, $nonce, $key ); That solves the literal search problem, but none of the others. However, in my experience[1], when it comes to deterministic encryption, most PHP developers will use ECB mode, or CBC mode with a NULL IV. [1]: https://meta.stackoverflow.com/q/293930/2224584 https://meta.stackoverflow.com/q/293930/2224584