Re: "Alien" cryptanalysis

From: Douglas A. Gwyn (DAGwyn_at_null.net)
Date: 05/19/03


Date: Mon, 19 May 2003 16:52:40 -0400

DSCOTT wrote:
> SKIPJACK was designed by people that really know crypto.
> Not by your typical psuedo acedemic type. However I don't think
> its designed to be secure. Just like DES before it. It likely
> the NSA can easily break anyone foolish enough to use it. Though
> it may be secure from non government people for a few years.

Unless you have actual evidence, the above has to be taken
as paranoid raving. Skipjack was specifically intended for
use *by the US government* (among others) to protect
sensitive but unclassified data. (There were already other
cryptosystems for classified data.) Given how simple the
structure of Skipjack is, it cannot have embedded "back-door
passwords" etc., so if it were readily breakable that would
have to be by means of some general cryptanalytic technique.
That means that any competent cryptanalytic agency, such as
those of foreign governments and perhaps organized crime,
might be able to crack it. It would have been unconscionable
for NSA, half of whose mission is to protect US government
information, to have intentionally put the protection of our
own information at risk.

As to DES, at least as of a few years ago not even the NSA
had any general method of cryptanalytic attack against DES
that was significantly more effective than brute-force key
search. They may have been able to afford advanced
technology in case cracking DES ever became crucial to our
national security interests, and eventually (long after DES's
design lifetime) even the "private sector" was able to
exploit advancements in technology to build a brute-force DES
cracker. It was the gradually deteriorating security margin
for DES that motivated the dvelopment of AES for use in
contexts where DES might have formerly been suitable. And,
anticipating more paranoia, the AES algorithm was developed
in the open by non-US citizens, so it is most unlikely that
the US government could have inserted any weaknesses.



Relevant Pages

  • Re: "Alien" cryptanalysis
    ... >> SKIPJACK was designed by people that really know crypto. ... Just like DES before it. ... >> the NSA can easily break anyone foolish enough to use it. ... >> it may be secure from non government people for a few years. ...
    (sci.crypt)
  • Re: SKIPJACK / AES on PIC
    ... JohnTromaville wrote: ... >I've found an implementation of SKIPJACK and DES on a PIC16F84. ... I'm assuming it is more secure than DES. ... If you were on a higher-end device, ...
    (sci.crypt)
  • Re: SKIPJACK / AES on PIC
    ... JohnTromaville wrote: ... > I've found an implementation of SKIPJACK and DES on a PIC16F84. ... I'm assuming it is more secure than DES. ... I suppose you could always cross-compile Brian Gladman's AES C code. ...
    (sci.crypt)
  • Re: FreeBSDs Visual Identity: Outdated?
    ... Calling it a Windows thing severely misrepresents the facts. ... >> One should not criticize the design of an engine while vehemently ... I asked was indeed a question (opposed to a statement of fact as DES ... To unsubscribe, ...
    (freebsd-arch)
  • Re: FreeBSDs Visual Identity: Outdated?
    ... Calling it a Windows thing severely misrepresents the facts. ... >> One should not criticize the design of an engine while vehemently ... I asked was indeed a question (opposed to a statement of fact as DES ...
    (freebsd-arch)

Loading