RE: 3DES versus SHA-1

From: Cushing, David (David.Cushing@hitachisoftware.com)
Date: 07/09/02


Date: Tue, 9 Jul 2002 14:19:37 -0400
From: "Cushing, David" <David.Cushing@hitachisoftware.com>
To: <SECURITY-BASICS@securityfocus.com>

Mario,

> The purpose is to transfer data between sites securely
> using emails, HTTP, FTP, IP (LAN/WAN), etc.

Then you should use things like:
PGP - encrypted/signed email
HTTPS - web over ssl
SCP - secure copy instead of ftp
IPSEC / VPN - network level encryption

> Which algorithm should I use: 3DES or SHA-1 ?

The two algorithms you mention are very different things.

3DES is a block cypher. It is used to encrypt information. SHA-1 is a hashing algorithm. It is used for validating data integrity. Both have their place in security schemes, but they aren't comparable.

Use standard solutions as suggested above. They have the algorithms built in already.

-David



Relevant Pages

  • Re: Outlook & FTP Passwords
    ... Subject: Outlook & FTP Passwords ... POP3, FTP, and HTTP are plaintext protocols, including ... instead of HTTP, there's always HTTPS, which also uses SSL encryption. ...
    (Security-Basics)
  • freeware server for win2k
    ... i have a beloved win2k machine that i want to install servers for home ... networking on, just something for emails and ftp along with some http, ...
    (microsoft.public.windows.server.general)
  • installing servers on win2k
    ... i have a beloved win2k machine that i want to install servers for home ... networking on, just something for emails and ftp along with some http, ...
    (microsoft.public.win2000.advanced_server)
  • Re: firewalls that can ssl ftp?
    ... Secure Transfers ... Bruce Schneier's Blowfish encryption for data transfers. ... Secure SSL based Web Administration Portal ... Works with other FTP Clients/Servers ...
    (Security-Basics)
  • RE: Encryption for FTP/MAil/Web
    ... Subject: Encryption for FTP/MAil/Web ... Tunneling ftp through ssh ... ssl-ftp can encrypt the control & data channel; ... As for ssl-ftp servers, I only found one RFC compliant one for Windows; ...
    (Security-Basics)

Quantcast