6 ms·
> CBC is far easier to implement... Never implement your own cryptography. Edit: In fact an incorrect implementation of CBC mode famously caused a vulnerabil
by password11 4y ago
> CBC is far easier to implement...
Never implement your own cryptography.
Edit:
In fact an incorrect implementation of CBC mode famously caused a vulnerability in Microsoft's ASP.NET in 2010 (https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 https://learn.microsoft.com/en-us/security-updates/securityb...). The margin for error is small and even subtle mistakes or incorrect design can cripple security. Even Microsoft got it wrong once (although they handled remediation very well).
- dragontamer 4y agoOr... you can have a more nuanced viewpoint and note that CBC is really, really, really easy to implement, and _really_ doesn't fall into that category of discussion. The reason you don't implement your own block ciphers is because side-channel attacks are damn near impossible for normal programmers to understand. Especially timing attacks. But block-modes of operation? Some of them are really easy. I've ever heard of a bad implementation of CBC causing a security bug. ------- I'd say you shouldn't implement your own GCM mode. GCM is quite complex, and the Galois Field's authentication bits could be side-channeled if you don't know what you're doing. CBC? Where's the flaw? Its so stupid simple I don't think that even a novice would make a critical error.
- tptacek 4y agoYou keep saying "the Galois Field" as if that was a thing. It's GCM. The components of GCM are CTR mode and the GMAC authentication code, which is based on GHASH. If you're afraid of Galois fields, you don't get to use AES at all! Nobody should be implementing any of these primitives themselves, very much including CBC, which, as you saw downthread, left both you and the author of this project with an insecure cryptosystem. Vulnerabilities in CBC systems were for a long time during the 2000s the most common crypto vulnerabilities on the Internet. There are more things that go wrong with CBC mode than just forgetting to authenticate it!
- dragontamer 4y ago> You keep saying "the Galois Field" as if that was a thing You're kidding, right? You've never looked at how GCM-mode works? The entire set of math is inside of the GF(2^128) field. That's why its called a Galois Counter Mode. I don't think anyone should be implementing their own GCM mode. Its very subtle and potentially full of traps. CBC on the other hand is pretty dumb and simple, and surprisingly secure and robust > Vulnerabilities in CBC systems were for a long time during the 2000s the most common crypto vulnerabilities on the Internet. There are more things that go wrong with CBC mode than just forgetting to authenticate it! If they're so common, you shouldn't have much of an issue naming one such vulnerability.
- tptacek 4y agoI think some of my comment went over your head.
- devman0 4y agoBEAST and POODLE were both high profile attacks against how SSL used CBC.
- dragontamer 4y agoBut neither were attacks on CBC itself. That is to say: to "fix" BEAST or POODLE, you don't change a lick of CBC code at all.
- tptacek 4y ago[flagged]
- vengefulduck 4y agoThe math used in AES (Rijndael) utilize operations in GF(2^8) tho, so you're doing operations using Galois fields whether your utilizing GCM or CBC. I don't really see how adding the GCM mode utilizing GF(2^128) on top is significantly more difficult or error prone than implementing the AES block cipher itself. You should still be familiar with operations over Galois fields regardless if you've for some reason (foolishly imo) decided you want to implement AES cryptographic primitives on your own. Regardless there's no good reason not to use a vetted open source implementation instead, preferably with an even higher level of abstraction so your not having to worry about ciphers or modes of operation at all[1]. [1] https://doc.libsodium.org/secret-key_cryptography/secretbox https://doc.libsodium.org/secret-key_cryptography/secretbox
- deleted 4y ago[deleted]
- password11 4y ago> Or... you can have a more nuanced viewpoint The nuanced viewpoint is never implement your own cryptography. > Its so stupid simple I don't think that even a novice would make a critical error. Ask Microsoft about that one: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 https://learn.microsoft.com/en-us/security-updates/securityb...
- dragontamer 4y agoThat's a Padding Oracle vulnerability, not a CBC error.
- password11 4y agoPadding is an important part of CBC.
- dragontamer 4y ago[flagged]
- tptacek 4y agoNo, to all of this.
- deleted 4y ago[deleted]
- bawolff 4y agoBy that metric all security vulnerabilities can be explained away as a fault in a different part of the system.
- IncRnd 4y ago> Furthermore, padding oracles are completely irrelevant to data at rest, like as described in this topics use case. So it really is a bit of a non sequitur too. That's not true and extremely dangerous to say. In an offline, black-box scenario no server is needed for a padding-oracle. You are thinking of a side-channel oracle. A padding-oracle attack can absolutely be feasible in many cases.
- deleted 4y ago[deleted]