3 ms·
> But when people say "use AES-CBC + HMAC" and cite Signal as an example, and Signal's implementation does this: https://github.com/signalapp/Signal-Android/blo
by peppermint_gum 3y ago
> But when people say "use AES-CBC + HMAC" and cite Signal as an example, and Signal's implementation does this: https://github.com/signalapp/Signal-Android/blob/main/app/src/main/java/org/thoughtcrime/securesms/crypto/MasterCipher.java#L159-L176 https://github.com/signalapp/Signal-Android/blob/main/app/sr...
That's very vague and therefore not very helpful. Could you say what exactly is wrong with the code you linked?
- soatok 3y agoIt does exactly what I've been describing! They provide AE, not AEAD. They feed an IV and ciphertext into HMAC. They don't feed additional authenticated data. If someone followed Signal's example, they either wouldn't have AEAD, or they're likely to make the exact mistake described in the post I linked above. I don't know how to be more helpful here. I've been only repeating myself. AEAD modes let you bind a ciphertext to a context without increasing bandwidth. This is super important for database cryptography. Read more: https://soatok.blog/2023/03/01/database-cryptography-fur-the-rest-of-us/ https://soatok.blog/2023/03/01/database-cryptography-fur-the... Whether "it's not AEAD" matters for an application depends on many factors. Signal doesn't need it.