4 ms·
> Nobody should be using RC4. I don't think this opinion gets enough play. A collision attack on SHA-1 is published which is still 'academic' enough that nobo
by brl 17y ago
> Nobody should be using RC4.
I don't think this opinion gets enough play. A collision attack on SHA-1 is published which is still 'academic' enough that nobody has actually produced a single collision and Debian thinks it's worth re-keying their entire infrastructure over ("Attacks will only get better!").
Meanwhile, Fluhrer, Mantin, Shamir tore RC4 a new one almost a decade ago and everybody just applied a kludge and forgot about it. Then 5 years later, improved attacks are published and still no talk about permanently retiring RC4.
- tptacek 17y agoI could be wrong but I think what's happening is this: RC4 is the only stream cipher anybody really knows. People don't really understand how OFB and CTR mode work, and don't get that AES is already a serviceable stream cipher. Therefore, people don't really have a "go-to" stream cipher besides RC4. You'd hope eSTREAM would change that --- Trivium would make a great replacement for RC4 --- but it may be that NIST simply has to bless something to make RC4 go away.
- ajross 17y agoRC4 is also just plain beautiful; it's a permutation of all unique bytes with just two pointers into the array. It's implementable in what, 4 lines of code? Trivium is comparably simple, I guess, but the LFSR-like structure makes for significantly longer (and uglier, IMHO) code. Trivium is also brand new and has had vastly less attention paid to it. RC4 isn't "unbroken" exactly, but even after all these years RC4-based protocols are working securely in the real world right now, and that has to count for something. I'm not arguing for using RC4 either. The sentiment is more: "Don't diss RC4, it's still a really great piece of work."
- tptacek 17y agoThe fact that the most elegant solutions are rarely secure is yet another reason why otherwise sane developers shouldn't be going anywhere near cryptography.
- ajross 17y agoRSA is elegant and secure. MD5 is ugly and broken. RC4 is really elegant and not-quite-unbroken. I've extended the data set now to three points, and the graph looks like a pretty good correlation between elegance and security, actually. Your text implies the opposite, and I think that's wrong. Crypto stuff is just hard. But I think that elegance is as good a guide to correctness there as it is anywhere else. Elegance never gets you correctness automatically anywhere. But it's not a bad place to start your analysis.
- brl 17y agoRSA quickly becomes a lot less elegant once you start patching in all the cracks. What I mean is that if you give an otherwise competent developer who is not a cryptographer a description of the elegant version of the RSA algorithm and ask them to implement it and design a secure protocol what they come up with will be completely broken.
- ajross 17y agoSure. But to be honest, that point is kinda trivial, no? If you give any competent developer a hard problem in an area where they are not a domain expert and ask them to deliver a correct solution based on nothing but an elegant description of an algorithm, they're likely to fail. My point was this: it's easy from your perspective to complain about subtle practical details with stuff like RC4. But that obscures the fact that RC4 is an important algorithm, and worth studying. It's prudent to put on your expert hat and warn amateurs away from crypto stuff, but if they're going to study it, they should know about RC4.
- tptacek 17y agoIf, like you, they're going for a PhD in the subject, then yes. If, like me, they're faced with it in practice, then what they need to know is, "bad".
- brl 17y agoI guess I'm not so much dissing RC4 as pointing out a ridiculous double-standard. Almost every application of RC4 depends on correlation immunity while most applications of SHA-1 do not require collision resistance. That said, I don't think RC4 is a reasonable cipher to use anymore. It has fallen to so many attacks already that it's impractical to expect people to be aware of all the caveats and pitfalls regarding it's use. At the very least it should be respecified with a new key schedule that drops the first N keystream bytes rather than leaving that as an 'implementation detail'.