7 ms·
[deleted]
by miovoid 2y ago
[deleted]
- madars 2y agoYour E/Fp has order 2^3 * 3 * 37991 * 21183269 * 373015308871 * 16071902378831708724506232718210977087913221837027589 and thus you can't hope for more than 86 bits of security due to Pohlig–Hellman, never mind cofactor attacks. encrypt() is also insecure (xor every byte of the message with the same shared secret byte), even if you chose a better curve.
- tptacek 2y agoThis is much better version of the sibling comment but I'm a message board nerd and can't keep myself from pointing out that this code is probably a little bit tongue-in-cheek.
- leijurv 2y ago`for char in message: encrypted_char = ord(char) ^ (shared_secret[0] % 256)` This is not real encryption, it picks only one byte of shared secret and XORs it into the plaintext. Therefore, there are only 256 possible decryption keys to check, which is trivial. Instead, you'd want to use the shared secret as a key to something strong and symmetric like AES.
- tptacek 2y agoI don't think it's meant to be real encryption.
- leijurv 2y agoI suspect it was, given that they've now deleted their comment.
- thechao 2y agoAny idiot knows not to use power-of-two! You gotta use "+13", which is prime and, therefore, *secure*.
- BobbyTables2 2y agoAnd Twice is nice!
- Jerrrrrrry 2y agoand more than thrice increases your chances of collision by
- deleted 2y ago[deleted]