3 ms·
This one immediately jumped out at me while reading (I'm interested in crypto but when asked about it in a job interview I happily told them that security imple
by fr0styMatt2 11y ago
This one immediately jumped out at me while reading (I'm interested in crypto but when asked about it in a job interview I happily told them that security implementations should be done by someone that knows what they're doing!).
Can someone explain this:
> Let’s ignore the fact that it’s using MCRYPT_RIJNDAEL_256 (the 256-bit block version of Rijndael, not AES) instead of MCRYPT_RIJNDAEL_128 (real AES),
When I look at those enum names I would immediately think that MCRYPT_RIJNDAEL_256 was stronger than MCRYPT_RIJNDAEL_128. The naming strongly suggests the same algorithm but _256 being stronger.
Is this part of an API design issue?
- sarciszewski 11y agoYes, mcrypt is terrible. https://paragonie.com/blog/2015/05/if-you-re-typing-word-mcrypt-into-your-code-you-re-doing-it-wrong https://paragonie.com/blog/2015/05/if-you-re-typing-word-mcr...
- tptacek 11y agoThe 32 byte block option is strictly speaking more secure.
- some_furry 11y agoAre you saying that just because it operates on larger blocks, or do you know something else that I don't?
- tptacek 11y agoAll things being equal, larger blocks are better.
- sarciszewski 11y agoHave you (or any of your colleagues) studied Rijndael-256? I'd be interested in seeing your analyses and conclusions if you have.
- tptacek 11y agoStudied in what sense? It's one of the best studied block ciphers in the world. I wouldn't go out of my way to use it, but I flinched a little when this report suggested its use was a vulnerability. I don't think 32 byte blocks are much better than 16 byte blocks, but 16 byte blocks are much, much better than 8 byte blocks, and so I feel like I should be consistent.
- earthrise 11y agoI usually consider this a "vulnerability" in the sense that the author probably intended to use AES and so they may have misunderstood the mcrypt API. Most importantly, they might have wanted AES-256 and missed the fact that mcrypt selects the key size based on the size of key you give it. That does not appear to be the case this time, however, since the page acknowledges (in an update) "256 bit block" and the fact that it isn't AES. So I should probably make note of that in the CryptoFails post. I'm unsure how well the analysis of AES (and the attacks against it) carry over to Rijndael-256, so I'd be hesitant to actually recommend it without asking a cryptographer... but, like you, I'd be very surprised if it was a source of vulnerability itself.
- tptacek 11y agoI wouldn't actively recommend it. I would worry if someone was using Rijndael-128/256 to make a hash function. But apart from that: the gain in reduced malleability probably offsets any reduced security margin; in other words, using a larger block makes the realistic attacks somewhat harder. There are probably zero crypto implementations that that contain the string "AES" that use Rijndael-X/256 that aren't broken in some other comical way.
- deleted 11y ago[deleted]
- sarciszewski 11y ago> Studied in what sense? It's one of the best studied block ciphers in the world. Are all the studies on the 128-bit block variant of Rijndael (the one christened as AES) also applicable to the 256-bit block variant? I don't know the answer to this question.
- deleted 11y ago[deleted]