4 ms·
> Thanks for agreeing that we don't lose security when using my construct. I don't agree. The construct may not degrade security under several caveats. Most im
by kelson 11y ago
> Thanks for agreeing that we don't lose security when using my construct.
I don't agree. The construct may not degrade security under several caveats. Most implementations are extremely likely to share resources, which will introduce weaknesses. I'd wager those weaknesses would degrade security much more than the composition would enhance it, but it'd depend on the exact situation.
> Yes but it would involve highly paid cryptoanalysts. My proposal is first of all to disprove the root of this thread. Secondly, it makes surveillance more expensive while it's free for us. That what's cryptography all about. Making their life harder while not so much for us.
My exact point was that those cryptographers would already need to develop generic attacks for all the non-standard (read: non-secure) cryptosystems out there. Composing a homegrown cipher with a peer-reviewed secure cipher will not make their lives harder. It will make maintaining and improving the system harder. The net result is overwhelmingly likely to be detrimental.
- madez 11y agoWe don't agree on the effectiveness of security through obscurity.
- angry_octet 11y agoAnd it has the added benefit from the NSA's point of view that your connection/data is precisely fingerprinted as 'homebrew-crypto-1629: refer to analysis cell 2865JQ'. Then the computer is sub basement 19 goes 'ding!' and sends an automated SWAT team to your house.
- madez 11y agoTo fingerprint the connection/data by the used cipher they would need to break KC. If they are able to break KC they can fingerprint you also when you only use KC.
- im3w1l 11y agoThe output of KC is not necessarily completely random. It can contain some metadata. Like "encrypted with KC4096bits, initialization vector is 490282348992489, length of ciphertext is 26728 bytes". When you pass this through a bad cipher it may create a characteristic fingerprint.
- madez 11y agoI think you confuse cipher with protocol. To make it clear: for me a cipher is a bijective function on arrays of a predefined length.
- im3w1l 11y agoWhat do you propose doing with the initialization vectors then? Afaik, all commonly used encryption algorithms have those, for good reason too.
- angry_octet 11y agoYou have said multiple times that the outer wrapper was CC, and the offline, inner wrapper was KC. All they need to do is infer it is CC output, either through online attacks, anomalies in its statistical distribution, block size, etc. Also, certain modes like ECB have watermarking attacks, which inherently reveal that ECB was used. RC4 is a common stream encryption which can definitely be detected. In contrast AES seems much harder. It is called a Distinguishing attack. See: https://eprint.iacr.org/2013/176.pdf https://eprint.iacr.org/2013/176.pdf http://www.security.iitk.ac.in/hack.in/2009/repository/bimal_keynote_hack.in.pdf http://www.security.iitk.ac.in/hack.in/2009/repository/bimal... http://elligator.cr.yp.to/elligator-20130828.pdf http://elligator.cr.yp.to/elligator-20130828.pdf http://cr.yp.to/streamciphers/mag/053.pdf http://cr.yp.to/streamciphers/mag/053.pdf http://christina-boura.info/sites/default/files/KeyDifferenceInvariant_0.pdf http://christina-boura.info/sites/default/files/KeyDifferenc...