3 ms·
AES-CBC-HMAC-SHA2-ETM is fine as a last resort, assuming you have a secure compare function and a CSPRNG so your IVs never repeat for a given key and are unpred
by CiPHPerCoder 8y ago
AES-CBC-HMAC-SHA2-ETM is fine as a last resort, assuming you have a secure compare function and a CSPRNG so your IVs never repeat for a given key and are unpredictable.
TLS's AES-CBC is MTE not ETM, and that distinction matters [1]. You shouldn't use CBC mode in SSL/TLS. (You also shouldn't be supporting SSL; only TLS.)
But an application-layer AE construction [2] as described in the article is fine.
[1] https://moxie.org/blog/the-cryptographic-doom-principle https://moxie.org/blog/the-cryptographic-doom-principle
[2] https://github.com/defuse/php-encryption/blob/b87737b2eec06b13f025cabea847338fa203d1b4/Crypto.php#L116-L122 https://github.com/defuse/php-encryption/blob/b87737b2eec06b...
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]