4 ms·
> Why is this not popular? If you meant using a counter-based cipher: it is. GCM is the most popular mode on the modern internet, for example. If you meant us
by minitech 3y ago
> Why is this not popular?
If you meant using a counter-based cipher: it is. GCM is the most popular mode on the modern internet, for example.
If you meant using multiple ciphers: because it adds overhead without adding security.
- SAI_Peregrinus 3y agoOf note: cascading ciphers is, in general, at most as secure as the first cipher. The rest add nothing. For additive stream ciphers (like CTR mode) it's as secure as the most secure cipher instead.
- deleted 3y ago[deleted]
- n2d4 3y agoI think you made a typo, "at most as secure" should be "at least as secure" :) But you're right, the important takeaway here is that encrypting with a weak and a strong cipher sequentially may be less secure than just using the strong cipher. For those to which this seems counterintuitive, here is the paper that shows this result: https://link.springer.com/article/10.1007/BF02620231 https://link.springer.com/article/10.1007/BF02620231
- magicalhippo 3y agoWould be a fun plot twist in a Bond-like movie. Baddies have used multiple encryption algorithms like an onion, which due to this issue can be broken rather easily by the good guys. "Good thing they didn't know about this issue and put the weak cipher first..."
- SAI_Peregrinus 3y agoCorrect, should have been "at least".
- dataflow 3y agoHow does it not add security? It forces attackers to break every cipher instead of just one. That doesn't add security?
- thadt 3y agoIn theory - yes, multiple ciphers are harder to break. In practice, we have zero examples of anyone breaking (good) modern ciphers, and lots of examples of people breaking clever constructions involving those ciphers.