8 ms·
Just in case anyone's wondering, AES - the regular AES-128, 192 or 256 - is not publicly broken (yet).
by underdeserver 2y ago
Just in case anyone's wondering, AES - the regular AES-128, 192 or 256 - is not publicly broken (yet).
- tialaramex 2y agoIn fact it is IMO unlikely this primitive will ever be broken. Its predecessor, DES was "broken" only in the sense that it was intended to be possible to break it with enough computing power when it shipped, as a NOBUS (Nobody But Us can break it) by the US government. In 1975 this is a NOBUS, in 2025 it's basically saying "Please hack us China" so we don't do that any more. Although cryptanalysis of DES did reveal some flaws, the actual breaks, including ones you'd use today if tasked to break DES at scale, all target exactly the two deliberately chosen weaknesses from when it was designed 50 years ago - its keys are too small and its block sizes are too short, that's all, and that's enough. In AES neither of these flaws is present, hence I am not alone in thinking we probably won't ever build another one. You might think well, in 50 years we'll have better computers so that's dumb. Nope. Unless there's an actual mathematical break what runs out isn't mere human ingenuity, it's plain physics.
- randomtoast 2y agoGrovers algorithm can brute-force a 128-bit symmetric cryptographic key in roughly 2^64 iterations (on a quantum computer which we likely have in 50 years), instead of 2^128. Now, lets find another attack vector (maybe with the help of AI) that reduces the 64 a bit and you are in the realm of feasibility.
- metacritic12 2y agoBut everyone will upgrade to AES-256 (many system already has), and that truly will be the final symmetric algo even with moore's law.
- hinkley 2y agoMD-5 died the same way. We had to scare people into investing into upgrading to SHA-1 by showing them the slope of hardware and the variability in new breakthroughs and ask if they'd rather have an emergency that lasted for over a month or work it into the schedule among the other requirements now? Yes, people can upgrade but nobody fucking will until you impress upon them how stupid they're being by gambling the entire company on carrying that debt for another year.
- bluGill 2y agoOnly those who can change. In work in embedded systems - we still have to talk to machines that were built with exportable encryption in the 90's (read if it isn't broken that is only because nobody who has a clue has bothered to try). They can't be upgraded anymore so I have to keep those algorithms building just in case someone wants to mix new with old. (fortunately the old machines are never internet connected so vulnerability requires local access - but the vulnerability is in safety critical functions so I don't rest too easy)
- hinkley 2y agoI use the SHA-1 example in part because that was the newest hash that a bunch of smart cards someone wanted to try to use with our system supported. Of course the max RSA key lengths on the card weren't up to it anyway (kids: if you by crypto hardware and don't use it immediately, don't warehouse it looking for a problem for your solution), but at least I got to put my foot down and we only shipped with SHA-1 and SHA-2 support
- adgjlsfhk1 2y ago2^64 work that is non-paralellizable isn't a threat. 64 bits of classical security is insufficient because computers can do thousands of operations in parallel, and you can combine the effort of millions of computers. Grover's algorithm gives you a sequential complexity of 2^64, so if you have a quantum comptuer with a clock speed of 20GHZ (current quantum computers are in the khz to low mhz range), and you pretend that the quantum computer can process 14 rounds of AES per clock cycle (in reality it would be hundreds of cycles), it will take a quantum computer running for 30 years continuously to crack a single key (and if the temperature ever rises 1 millionth of a degree or the computer loses power for a nanosecond, you have to start over).
- hinkley 2y ago> in 2025 it's basically saying "Please hack us China" so we don't do that any more. It took almost two decades to explain that to sitting presidents and Congress. 'We' have been telling 'them' that shit won't scale since at least the 90's. Everyone forgets about Al Gore's black sheep - the Clipper Chip.
- bluGill 2y agoThat is in the US. Major European countries still haven't figured that out. (I'm not sure if US congress really has either, but at least I haven't seen any backdoor movements come out in the past few years) BTW, if you are keeping score: stop. Every country has things they do well and things they do bad. Look for and fix your local bads, this isn't a game of who is better, it is a game everyone should win.
- hinkley 2y agoI donated money to EFF every year until Gore switched to bothering fossil fuel industries instead of the software industry. I had my first tech job thanks to his NSF funding as Senator Gore but he was also a spook and in the end it ended up evening out. > BTW, if you are keeping score: stop. Yeah maybe not doing so good at that. But you always have to watch out for that time when your 'friends' will accidentally sell you out if you don't reiterate your social and professional boundaries with them from time to time.
- cakealert 2y agoModern ciphers including AES subscribe to the philosophy of using a simple round and then repeat it a bunch of times. While this is most likely sound (due to the sensitivity to initial conditions aka avalanche effect) there is a small chance that this creates a mathematical structure that will one day get exploited. AES is even more vulnerable to this chance than usual because it actually uses mathematical functions for several of its components (the sbox and the 32-bit linear permutation). No one has been able to exploit this combination yet though. Contrast this with SHA-2 for example, it's an unbalanced Feistel permutation that had a lot of 'random' nonlinear crap thrown in. SHA-2 can actually be used as a block cipher (SHACAL-2) however there is no HW acceleration for the inverse permutation - so you would be limited to CTR-like modes.
- tptacek 2y agoExploitable mathematical structure arising purely from the concept of an iterated cipher is probably what Nick meant there by "an actual mathematical break". SHACAL-2 is also an iterated cipher with a relatively simple round structure.
- cakealert 2y agoPretty much all block ciphers (and therefore their derivative constructions) are iterated. The SHACAL-2 permutation though is much more mathematically unstructured than AES. It's an augmented ARX unbalanced Feistel design (w/ additional non-linearities). Hard to imagine you could reconstruct any usable mathematical structure in that mess. It also has a strong key schedule which is not vulnerable to related-key attacks (AES is) which is by design due to its hashing application. 512-bit key space too which allows for easy nonce integration.
- adrian_b 2y agoMost block ciphers iterate the same round function, but this regularity is destroyed by using distinct round keys in each round. The only vulnerabilities of the iterated construction appear when a weak method is used for generating the round keys from the cipher key (i.e. when the so-called key schedule is weak), so that there are predictable relationships between the round keys. There exists an alternative (and equivalent) construction for a block cipher, when the same key is introduced in all rounds, but in this case all the round functions must be different from each other (instead of iterating the same function).
- upofadown 2y ago>...all target exactly the two deliberately chosen weaknesses from when it was designed 50 years ago... I would quibble the deliberate part for the block length (and perhaps strengthen your point). DES came out in the 70's and people were still designing 64 bit ciphers in the 90's. Examples: IDEA, CAST5, Blowfish. I think that it is most likely that the the 56 bit key length was really the only factor intended to make DES deliberately weak. Gigabyte scale files/sessions were just not a thing back then.
- adrian_b 2y agoThe ancestor of DES at IBM, Lucifer, had both an 128-bit block length and 128-bit keys. Therefore there is no doubt that both the reduction of the key length and of the block length have been deliberate. The only thing that can be argued is that perhaps the motivation for the reduction in the block length could have been less for weakening the cipher, but more for reducing the cost of the hardware, based on the assumption that the cipher will be used only for the encryption of amounts of data that are very small for today, but which could have seemed big during the mid seventies.
- upofadown 2y agoTo make a 64 bit block size be helpful for signals intelligence in the '70s the following things would have to be true: 1. Someone would have an encrypted session or file that ran into the 10s of GB. 2. The signals intelligence entity would have to somehow have gotten access that much data. Did they tap a telephone line and intercept a 300 bps modem connection for 30 years straight? Did they get access to half a billion encrypted punch cards? 3. The signals intelligence entity would have enough processing power and memory to actually find the collisions. 4. The signals intelligence entity would be able to extract some useful information out of 1 or 2 colliding 8 byte blocks randomly chosen out of billions in the same file/session. The extreme unlikeliness of that is why such collisions are still of little practical use today.
- adrian_b 2y agoWhen using a block cipher function solely for encryption, it is difficult to exploit a small block size. On the other hand, a short block size complicates a lot the use of a block cipher function in other useful algorithms, e.g. key derivation algorithms, RNG algorithms, MAC algorithms etc. The necessity of using a block cipher function also for such purposes has become very obvious almost immediately after the standardization of DES, but then it was too late. Such applications have been seriously hindered for a couple of decades, until the mid nineties, by the lack of any other publicly known strong block cipher functions. Many workarounds have been published with the purpose of using DES even where its short block length was unacceptable, but all such workarounds were more inefficient than using a block cipher with a greater block size. They were designed only because it was expected that using the already existing hardware integrated circuits that computed DES would be more efficient than implementing a block cipher function in software, on the slower computers of that time.
- SAI_Peregrinus 2y agoI suspect we might move to some sort of cipher that uses the AES round function but isn't full AES, like AEGIS, for performance benefits. Same permutation, but arguably a different primitive. That move won't be because AES got broken though, it'd be because AES wasn't as fast as desired.
- userbinator 2y agoCertainly one of the most clickbaity titles I've seen.
- kali_00 2y ago[dead]