3 ms·
There is no way this construction is weaker than the weakest of the three. To convince yourself of this, assume one of the ciphers is 100% broken and spits out
by maxtaco 13y ago
There is no way this construction is weaker than the weakest of the three. To convince yourself of this, assume one of the ciphers is 100% broken and spits out all 0s. Then you're XOR'ing your ciphertext with all 0s (or some other known pad). So it's just a noop. As the FAQ says, because one cipher is not used as the input to another, there's no way a weakness can spread up or down the chain.
There was a discussion on twitter among cryptographers/security practitioners (search for @agl___), and in spite of some unnecessary flaming, we are almost certain now that the cipher cascade and the MAC scheme are both as strong as their strongest components.
See this publication for more information about the cipher cascade: http://rd.springer.com/article/10.1007%2FBF02620231 http://rd.springer.com/article/10.1007%2FBF02620231
See this publication for more information about the HMAC construction: http://tuprints.ulb.tu-darmstadt.de/2094/1/thesis.lehmann.pdf http://tuprints.ulb.tu-darmstadt.de/2094/1/thesis.lehmann.pd...