5 ms·
There are many standardized and reviewed encryption methods out there that are much more complex and secured than a simple XOR. I think the point he was trying
by crypt1d 13y ago
There are many standardized and reviewed encryption methods out there that are much more complex and secured than a simple XOR. I think the point he was trying to make is that this technique doesn't even deserved to be called an encryption in the first place. I have a feeling linksys devs just wanted something to hide the passwords from the plain view (eg, if somebody peaks at your config file over your shoulder they won't be able to tell what your root password is) and ended up using a wrong name for the feature.
- willvarfar 13y agoROT13 and XOR are encryption. This is crypto101. With a username like yours, you ought to give some books on the subject a cursory glance, at least at their first chapter where they always start with some chap called Caesar ;)
- josephlord 13y agoI would argue ROT13 isn't encryption as there is no key (it is just defined within the algorithm). Simple XOR with a constant is (bad) encryption and the constant is the key.. The Caesar cipher is encryption because the shift is the key.
- eterm 13y agoROT13 is just like XOR; The "key" is "NOPQRSTUVWXYZABCDEFGHIJKLM". In the same way in this case the XOR "key" was just 0xFFFFFFFF.
- SEMW 13y agoI think josephlord's point was that the name "ROT13" completely specifies the 'key': If you changed that, it would no longer be ROT13. So it arguably can't be considered a key if you define 'key' to mean 'a piece of information additional to knowing the algorithm used that is necessary to decrypt'. (If the 'algorithm used' was specified just as ROT (i.e. caesar cypher) then 13 would be a key). But this is basically semantics.
- crypt1d 13y agoNever said wasn't, just that we came a long way since the Roman era ;)
- rurounijones 13y agoDepends on the definition of "encryption". It looks like GP's definition of "encryption" does not include childish stuff like RO13 and XOR. Is his definition technically accurate? No, but then words are malleable and companies hiding behind "technically accurate" in their marketing blurb is never a good thing.
- dspillett 13y ago> Is his definition technically accurate? No, but then words are malleable I've taken to calling simple XOR/Rot based schemes like that "encoding" instead then encryption, as it would seem have others, as they are essentially static alphabet changes - converting ANSI to UCS or UTF16 would be almost as effective. Of course marketing are going to use the best sounding word they can in any small way justify rather than caring about any disconnect between reality and what things actually mean to the people they are marketing to. Obfuscation is another work I'd use for such simple schemes. They have much the same effect as code obfuscation: they hide something from the most casual of viewers but offer no protection at all against anyone with five minutes to spare.
- willvarfar 13y agoThe words encryption and obfuscation do not contain any overtones of their complexities. You would rename the Caesar Cipher to be Caesar Encoding? Not going to fly. Any encryption where the password is public knowledge is just obfuscation. So if these backups were AESed, reversed, RC4ed, bzipped and then DES3ed ... that'd just be time-consuming obfuscation.