Re: DCPP



Sebastian Gottschalk <seppi@xxxxxxxxx> wrote:
Just encrypt something with DriveCrypt and run a program with high memory
consumption in parallel. Most likely, the plain encryption key will end up
in your swap file.

Nice. But not significant, because no-one will handle this like that.

Unfortunately, SecureStar only have advertizing nonsense about their
product DriveCrypt on their website:
| 1344 Bit Military Strength disk encryption using the best and most
| proven cryptographic algorithms such as AES, Blowfish, Tea 16, Tea 32,
| Des, Triple Des, Misty 1 and Square.
Nonsense.
Nah, the 1344 bit aren't nonesense. It's Triple-BlowFish, even though it
would have an effective security of 896 bits at best.

There is no "Triple-BlowFish" in the text above, so the text remains
nonsense. And: more than 256bit with a secure block cypher is nonsense, too.

And at least AES, BlowFish, 3DES and Square are best proven. The rest is
trivially broken.

Nonsense, yes. Even DES is mentioned.

But advertizing nonsense is very common, and maybe this product is good
nevertheless.
No, see the snake-oil FAQ. If you can't assume that a cryptographic
software is fully trustworthy in any aspect, it should be considered
useless.

I disagree. The advertizing is nonsense, accepted. And this does not
improve my trust into this company. But you're claiming, that the
encryption can be trivially broken, so please offer proofs for that
claim.

Yours,
VB.
--
"Pornography is an abstract phenomenon. It cannot exist without a medium
to propagate it, and it has very little (if anything at all) to do with sex."
Tina Lorenz
<https://events.congress.ccc.de/congress/2006/Fahrplan/events/1422.en.html>
.



Relevant Pages

  • Re: TripleAES Encryption
    ... >> I've recently seen an ad for a product claiming 3AES encryption. ... >> As I understand 3DES, a plaintext is first encrypted with DES, then ... > There is two key triple DES or three key triple DES. ... These chips are often made to *require* 3 keys, ...
    (sci.crypt)
  • Re: TripleAES Encryption
    ... > I've recently seen an ad for a product claiming 3AES encryption. ... > As I understand 3DES, a plaintext is first encrypted with DES, then ... There is two key triple DES or three key triple DES. ... For some reasons EDE makes a better ...
    (sci.crypt)
  • Re: Triple DES code?
    ... >> Does anyone know where I can get Triple DES code for C? ... encryption algorithm doesn't matter for security purposes - anyone ... here's the standard warning: security systems built by ...
    (comp.programming)
  • Re: [Full-disclosure] Month of Random Hashes: DAY THREE
    ... By definition hashing stuff is also encryption. ... art it is can be categorized under "encryption":) ... nonsense, I think someone is just taking the piss and further degrading ... correlated to the release of some POC or other item of interest, ...
    (Full-Disclosure)
  • 3DES and super-encryption
    ... I'm basically familiar with 3DES and how it was developed to extend the ... short version of what I know about the transition from DES ... DES is basically a secure cipher except that with 56 bit keys it is ... adds nothing to the strength of encryption but may actually weaken a cipher. ...
    (sci.crypt)