9 ms·
The "proprietary" part of the solution is the efficiency it brings. MD5 hashes for a large set of data are slow to update and not really usable for a dynamic da
by FileRockDA 13y ago
The "proprietary" part of the solution is the efficiency it brings. MD5 hashes for a large set of data are slow to update and not really usable for a dynamic dataset. Our technology makes integrity checks possible in real-time.
- tptacek 13y agoI'm somehow even more confused than I was before I asked. Why are you using MD5? Stop doing that. And while I'm sure there is some scenario where simply hashing files might be costly, I don't see how that applies to you; for instance, every TLS record you send to your service is being "integrity checked" using a simple hash-based MAC.
- StavrosK 13y agoIt seems to me that they're using a tree-based structure to avoid hash-checking the entire file, but do hash checking in blocks and update it. Since they're using MD5, this probably makes it easier to find a collision and change a specific block. Looks like they're using AES in CFB mode, which would probably complicate things, but I don't know why people don't use CTR mode more (it looks like it has many advantages to me, but I don't know much about crypto anyway), although in this scenario you'd probably want to use XTS. Anyway, "proprietary" and "cryptography" in the same sentence is generally a big red flag to me.
- FileRockDA 13y agoSorry if I wasn't clear. We're not using MD5. And we're not using proprietary cryptography. What's "proprietary" is the implementation of the integrity check technology, which is based on published research.
- wglb 13y agoOk, I see lots of calls to compute_md5. So is the integrity check demonstrably better than HMAC?