3 ms·
The author proposes a corollary to Kerckhoff's principle: > A cryptosystem should be secure even if all the parameters, except the key, are shared across every
by helpfulclippy 3y ago
The author proposes a corollary to Kerckhoff's principle:
> A cryptosystem should be secure even if all the parameters, except the key, are shared across every user.
It seems that if the key counts as a parameter, then surely nonces also count, and we certainly do not want nonces to be reused. This may be why this principle is not best practice. I am quite confident that the author is well aware of this, and I agree with the general thrust of what they're saying... Perhaps another way of saying it is that where parameters can be held constant, they should be. Or to quote Daniel J. Bernstein[1] quoting Mark Twain:
> Behold, the fool saith, "Put not all thine eggs in the one basket"—which is but a manner of saying, "Scatter your money and your attention;" but the wise man saith, "Put all your eggs in the one basket and—WATCH THAT BASKET."
[1]: https://blog.cr.yp.to/20140205-entropy.html https://blog.cr.yp.to/20140205-entropy.html