4 ms·
May I repeat your statements in my words, so that we can have understanding in common and communicate efficiently? 1. Elaborated and formalized description abo
by aegistudio 4y ago
May I repeat your statements in my words, so that we can have understanding in common and communicate efficiently?
1. Elaborated and formalized description about encryption method is required.
2. Processes need to be authenticated before they could access ciphertext / plaintext directory, so that they can't recover the key stream.
3. On encrypting the file names, the threshold of directory tree size for the birthday attack to become innegligible, should also be elaborated.
- dhaavi 4y agoI recommend reading Cryptography Engineering [0] and then re-evaluating the design and then get it audited. I took that path and I learned a ton and still had (some smaller) issues in the audit. [0] https://www.schneier.com/books/cryptography-engineering/ https://www.schneier.com/books/cryptography-engineering/
- aegistudio 4y agoSure. Thanks for the reference.
- FiloSottile 4y agoCryptography Engineering was great for its time but has been outdated for years, which in cryptography doesn’t mean “lacks fancy new stuff” but “we learned the hard way to do things differently”. Serious Cryptography and Real World Cryptography are commonly mentioned as successors.
- PYTHONDJANGO 4y agoYou forgot to mention a better source - please be constructive, thanks.
- dhaavi 4y agoThanks. Was not aware of that. I bought/read it in 2015, I think. I'll check out Serious Cryptography - just found out that I already have it! I like JP's approach to things and his bold thinking.
- FiloSottile 4y ago(1) and (3), yes. (2) is not about process authentication but about using authenticated encryption that detects tampering. More broadly, there needs to be a threat model that states what your attacker is capable of. Even more broadly, I get the impression you’re not an experienced cryptography engineer and you didn’t work with one. Learning is great, but this is not presented with any warnings, which is irresponsible.
- aegistudio 4y agoYou are right. I don't come with cryptography background and haven't consider the attack model carefully. I will warn the users about the current status and strive to design it to confront potential attacks.
- shiittile 4y ago[flagged]
- aae42 4y agoJust wanted to note that while the posts were terse, I can't say I would consider them arrogant or non constructive. If I were the author of Enigma I'd be thrilled to get feedback from Filippo. Also, it seems immediately constructive just from the reply you replied to. That said, I kind of have to agree, "you don't know what you don't know" often holds true in the matter of cryptography, and failure tends to be pretty damaging to the user. Actually, not posting a disclaimer when trying to solve a difficult problem as an amateur might be what should be considered arrogant.