Re: RC4 for Authentication and Encryption

From: Unruh (unruh-spam_at_physics.ubc.ca)
Date: 04/28/05


Date: 27 Apr 2005 23:31:50 GMT


"Joseph Ashwood" <ashwood@msn.com> writes:

>Your analogy is exactly the reason RC4 should not be trusted. We have a wide
>selection of chisels that work extremely well against RC4. These range from
>straight out attacks like are applicable to WEP all the way to a
>distinguisher from random, none of these are in any way new. RC4 has been
>fatally wounded for about a decade, it should be allowed to die.

Those are against bad implimentations of RC4. They would be true of any
stream cypher, never mind RC4.
While RC4 may be distinguishabel from random after TB, I do not believe
that anyone has shown even the ghost of an idea of how to use this to
attack a cypher stream encoded by RC4.



Relevant Pages

  • Re: Limiting RC4 to "40 bit" strength
    ... Bill Unruh wrote: ... Since no attacks on RC4 ... RC4...". ... Greg Rose ...
    (sci.crypt)
  • Re: Limiting RC4 to "40 bit" strength
    ... ]<ggr@qualcomm.com (Gregory G Rose) writes: ... Since no attacks on RC4 ...
    (sci.crypt)
  • RC4 for Authentication and Encryption
    ... RC4 doesn't normally have an IV. WEP tried to ... Zoltak in VMPC KSA (run KSA with IV as key, then run KSA with the real ... attacks, however if he want to keep compatibility with Cs and Cs-2 KSA ... The good is that a single bit alteration can generate a random ...
    (sci.crypt)
  • Re: RC4 - discard first n bytes
    ... ...which means that for RC4 chosen-plaintext attacks and known- ... plaintext attacks are the exact same attack. ... >output of RC4 rather than using it to encrypt some text and ... Do you have an "impossible" engineering project that only someone like Doc Brown can solve? ...
    (sci.crypt)
  • Re: RC4 for Authentication and Encryption
    ... >>Your analogy is exactly the reason RC4 should not be trusted. ... >>distinguisher from random, none of these are in any way new. ... Perhaps you're not aware that WEP was broken using almost exactly the same ... or that additional attacks have since been published against WEP ...
    (sci.crypt)