Re: What's the bottom line on RC4??

From: David Wagner (daw@mozart.cs.berkeley.edu)
Date: 02/09/03


From: daw@mozart.cs.berkeley.edu (David Wagner)
Date: Sun, 9 Feb 2003 17:34:05 +0000 (UTC)

Yama wrote:
>But I wasn't advocating using a nonce without dropping bytes so I feel
>the recommendation to use a nonce is sound in the way I stated, which
>was to use them with a master key to create a session key key for a
>particular data set or period of time.

I agree that the Fluhrer-Mantin-Shamir attack doesn't apply if you drop
the first few bytes of output, but after seeing the FMS attack (and other
related-key attacks on RC4), I believe it would be most unwise to put
any faith in the RC4 key schedule. In particular, I believe it would
be imprudent to generate RC4 session keys by concatenating a master key
and a nonce (as you suggested) -- no matter how many bytes of keystream
you drop, this still seems risky.



Relevant Pages

  • Re: Whats the bottom line on RC4??
    ... >>to use RC4 in the way you've proposed, after the WEP disaster. ... and the method of generating the nonce appeared broken. ... the referenced attack does not rely on repeated nonces, ... > With respect to David Hopwood, and a lot of respect to you, I'm ...
    (sci.crypt)
  • Re: Encrypt a UsernameToken Authenticated WSE Response
    ... >> using the password, the label WS-Security, the nonce, and created date. ... >> then a hacker cannot generate that key without knowing the password. ... >> and is just used to generate the session key to encrypt. ... >>> username and passwort und the data is symmetric encrypted, ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Whats the bottom line on RC4??
    ... >>>I believe David Hopwood is entirely correct. ... >>>to use RC4 in the way you've proposed, after the WEP disaster. ... >> I did read the WEP attack information, ... and the method of generating the nonce appeared broken. ...
    (sci.crypt)
  • Re: What is the best medication for mental illness
    ... > obsessive litigants and allow their misfortune to dominate their lives, ... Not really a conspiracy a cock up perhaps cos I can explain what ... anymoney, we waited more than 6 months and got nothing, no attack in ... telling him to fuck off after we found out he was a nonce is ok ...
    (uk.legal)
  • Re: RC4 on AMD64
    ... There's no relationship between RC4 and RC5/6 ... It isn't the case that all block ciphers ... Helix, all *require* the use of a nonce, and short ... Greg Rose ...
    (sci.crypt)

Quantcast