Re: Crypto Mini-FAQ

From: Lassi Hippeläinen (lahippel_at_ieee.orgasm-research.invalid)
Date: 01/20/04


Date: Tue, 20 Jan 2004 09:09:03 GMT

Mark Shelor wrote:
>
> David Wagner wrote:
<...>
> > Questions are precisely defined and have verifiable answers (even
> > if we don't always know how to find those answers). We make decisions
> > on the basis of evidence, not on faith, hopes, or appeal to authority.
> > Crypto is a matter for rational thought.

You sound like the Great Mathematical Congress of 1900, where Hilbert
declared that all correctly defined problems can be solved with logical
deduction...

<...>
> "Security" is
> either a measureable and independently-verifiable quantity or it's not.
> If it's not--which certainly appears to be the case--then you have no
> science.

...and then Gödel spoiled the party.

The only cryptoalgorithm that the academics have been able to prove
secure is useless in real life. So we practising engineers have to live
with the unproven kind, with all the mumbling, handwaving, and woodoo
that comes with them. Maybe I should propose a conjecture: all good
algorithms fall to Gödel's category "unable to prove either secure or
insecure" ;-)

-- Lassi



Relevant Pages

  • Re: Summary of Bit-Level SHA Discussion
    ... What's the scenario where dead code makes you more vulnerable? ... If one is simply to have 'one' particular crypto algorithm ... happens to have) compiled on a secure machine and loaded ... David Wagner, thus depriving the 'general' readers of ...
    (sci.crypt)
  • Re: Jim Steuert is a clue-challenged braying jackass
    ... Helix cipher. ... That this construction, in recursive form, yields SHA-1 ... is provable secure. ... as David Wagner asserted "we don't need ...
    (sci.crypt)
  • Re: [Lit.] Buffer overruns
    ... >>David Wagner has repeatedly asserted that he doesn't ... >verifiably secure, and I believe doing so is beyond the state of the art. ... A disciplined approach to programming is required to avoid defects, ... IMHO Pascal was a better language for teaching production of robust ...
    (sci.crypt)
  • Crypto Mini-FAQ
    ... This crypto mini-faq is an attempt to have something that is more ... For producing secure software, see Writing Secure Code, by Michael ... RC4 is a very popular stream cipher for those reasons. ... How can I encrypt a file on my hard drive? ...
    (sci.crypt)
  • Crypto Mini-FAQ
    ... This crypto mini-faq is an attempt to have something that is more ... For producing secure software, see Writing Secure Code, by Michael ... RC4 is a very popular stream cipher for those reasons. ... How can I encrypt a file on my hard drive? ...
    (sci.crypt)