Is Multiple Symmetric Encryptions Weak?

From: Apple Tree (ym4dapa02_at_sneakemail.com)
Date: 12/12/03


Date: 12 Dec 2003 02:41:36 -0800

I have a file that is encrypted daily using GnuPG symmetric encryption
and then transferred to another machine. The machine keeps each
version. The same passphrase is used for all encryptions (because it
is done by a cron job).

Occasionally I change the file, but certainly not everyday.

If someone got access to all past versions of the file, could they use
those versions together to crack the encryption? Does it make it any
easier?

I notice that when I do gpg -c repeatedly on a test file, and give the
same passphrase, it comes out different everytime. Does that have any
bearing?



Relevant Pages

  • Re: On the Recent PGP and Truecrypt Posting
    ... changing the passphrase would lock out prior users. ... Clearly a users with a backup copy of an encrypted disk for which they ... clear that real world users actually understand the need to re-encrypt ... You will also also see the architecture extend to some *very* cool storage encryption very soon. ...
    (Bugtraq)
  • Re: GC and security
    ... as i recall we did that because we needed the passphrase more than once, ... i forget whether gpg can be given a list of files to decrypt. ... on the USB keys that can utilize the same encryption keys. ...
    (comp.lang.python)
  • Re: Hash question ...
    ... header of the file. ... When a user enters an incorrect passphrase, ... if I generate an encryption key with the ... could I safely store the SHA of the passphrase ...
    (sci.crypt)
  • Re: needed: reviewers for an implementaion of AES
    ... This passphrase becomes the default ... encryption key, but is used to generate a 256 bit encryption key called ... encrypted with any file key which uses this master key structure. ... using the master key IV and CBC block chaining. ...
    (sci.crypt)
  • Re: Help secure my data (They will steal my drive)
    ... but it supports strong password-based encryption and can be ... printable ascii characters about 6.5 bit per character. ... In case your passphrase is not trivial it's much more likely an attacker ... will try to recover plaintext from swap files/virtual memory and from ...
    (sci.crypt)

Quantcast