3 ms·
within the birthday bounds of the underlying cipher (exabytes? So modern stream ciphers do leak, just so slowly, it shouldn't ever matter in a practical sense
by stcredzero 3y ago
within the birthday bounds of the underlying cipher (exabytes?
So modern stream ciphers do leak, just so slowly, it shouldn't ever matter in a practical sense if you're using them correctly? That was more or less my understanding to begin with, but maybe expressed ineptly.
the bounds of your nonce width --- they're not leaking _anything_
This reminds me of unicity distance. So under a certain number of outputs, one simply can't infer the internal state of the algorithm? It could be any number of internal states? That makes sense to me.
- tptacek 3y agoI don't think "leak" is the right way to think about it. There's are birthday bounds on the transform and, for nonce-based modes, on the nonces used for successive encryptions. I'm not sure it's really meaningful to think about the incremental marginal degree of "leakage" with each successive ciphertext up to that limit. We're coming up to the limit of what I'm comfortable talking about though; this is normally the point where 'pbsd jumps in to explain why what I'm saying is dumb.