4 ms·
Can you walk me through how AES-GCM or ChaPoly breaks authenticity and confidentiality, but AES-CTR doesn't? I'm not following you. Moreover, I'm pretty sure B
by throwawaymath 8y ago
Can you walk me through how AES-GCM or ChaPoly breaks authenticity and confidentiality, but AES-CTR doesn't? I'm not following you.
Moreover, I'm pretty sure Borg's developers are actively considering ChaPoly for the future.
- dchest 8y agoGCM/Poly1305 require unique nonces, so if they are repeated, the authenticity is broken. HMAC doesn't need nonces, so authenticity is preserved as long as the key is secret.
- throwawaymath 8y agoI'm aware of that, and mentioned that point in my original comment. What I'm not following is why Borg can't safely use AES-GCM or ChaPoly instead of AES-CTR + HMAC. Again: the team is actively considering using AES-GCM and ChaPoly in the future. I don't see anything intrinsic to either that preempts their use in Borg.
- blattimwind 8y agoYes, in a different construction there would be no problem. And there have been plans since at least 2016 to replace/augment the current construction with something that uses a master key to derive per-chunk encryption keys; it just never has been implemented. IIRC AES-GCM was kinda low on the list with a preference for just using Chapoly, because Chapoly just works and is also secure on any processor, unlike AES-GCM, which is very nasty to implement without hardware support for the arithmetic over GF(2^128).