5 ms·
"After encryption it is gzipped" is a red flag. After encryption it should be noise, why try to compress it?
by lsb 12y ago
"After encryption it is gzipped" is a red flag. After encryption it should be noise, why try to compress it?
- kelseyhightower 12y agoSorry, if I said that in the video. What we do is base64(gpg(gzip(data))) We gzip the data first, then encrypt it, finally base64 encode it.
- dantiberian 12y agoThe article says you encrypt, then compress. You might want to clarify that.
- bketelsen 12y agoMy bad - fixed.
- michaelmior 12y agoIn the next paragraph after the one you fixed > crypt encrypts, compresses, then encodes your value for storage
- bketelsen 12y agodammit.
- saturdayplace 12y agoIn this thread: just talking or writing _about_ encryption can be difficult. To say nothing of correctly implementing it in a project.
- doomrobo 12y agoHow can you possibly compress encrypted data? An ideal cipher should produce output indistinguishable from randomness, which is inherently difficult (read: near impossible) to compress.
- kelseyhightower 12y agoHopefully we corrected the docs and the comments here help, but we don't encrypt before we compress. We compress before we encrypt.
- tptacek 12y agoDon't compress then encrypt. It doesn't matter in this use case, but it matters very much in others. When attackers have chosen plaintext (which is virtually always), they can exploit compression to create a traffic-analytic side channel. This is the CRIME and BREACH attack on TLS, for instance. Schneier, in Applied Cryptography (which: avoid) recommended compressing before encrypting. That was bad advice. Compression and encryption interact in treacherous ways. Get of out the habit of combining them.
- kelseyhightower 12y agoAre you saying that compressed data should not be encrypted? We are trying to limit the amount of data we have to store in the backend K/V store. Can you provide links so I can read up on this. Thanks.
- somethingnew 12y agoExactly, the wikipedia articles for BREACH and CRIME are good starting points if nothing else. [1] http://en.wikipedia.org/wiki/BREACH_(security_exploit) http://en.wikipedia.org/wiki/BREACH_(security_exploit) [2] http://en.wikipedia.org/wiki/CRIME http://en.wikipedia.org/wiki/CRIME
- tedunangst 12y agoDo not compress chosen and/or known plaintext. The compression ratio alone reveals information about the data. i.e., how similar the unknown data is to the known data. > compressed data should not be encrypted? That's really tricky to answer simply. "No" might be taken to mean you should store compressed data unencrypted, which would be much worse. Nor do you have to decompress already compressed data before encrypting. But if somebody hands you data to encrypt and store, don't compress it as part of the encrypting phase.
- AYBABTME 12y agoThis is interesting and counter to my intuitions. Care to elaborate or point to references so I can educate myself? =)