4 ms·
I guess I'm not so much dissing RC4 as pointing out a ridiculous double-standard. Almost every application of RC4 depends on correlation immunity while most ap
by brl 17y ago
I guess I'm not so much dissing RC4 as pointing out a ridiculous double-standard. Almost every application of RC4 depends on correlation immunity while most applications of SHA-1 do not require collision resistance.
That said, I don't think RC4 is a reasonable cipher to use anymore. It has fallen to so many attacks already that it's impractical to expect people to be aware of all the caveats and pitfalls regarding it's use. At the very least it should be respecified with a new key schedule that drops the first N keystream bytes rather than leaving that as an 'implementation detail'.