Re: Some application, with sources

From: giorgio.tani (giorgio.tani_at_email.it)
Date: 07/12/05

  • Next message: simon: "Re: Is YellowCrypt OK?"
    Date: 12 Jul 2005 08:57:56 -0700
    
    

    "RC4 falls short of the standards set by cryptographers for a secure
    cipher in several ways, and thus is not recommended for use in new
    applications."
    I know.
    The presence of a distinguisher from random is generally quite accepted
    to be symptom of presence of possible attaks, altough that symptom
    alone can't say if those attacks are practical or theorical.
    Really, implementing various hardening that are quite well studied and
    described in literature, after many years, we have no definitive
    practical attack on RC4, however I agree that such a suspect (as casted
    by the presence of a distinguisher) is enough to don't recommend RC4 in
    new applications.
    The application comes from a previous work, Kyu, that was meant to be a
    framework for experimenting combinations of stream cyphers (how them
    cover biases, how them can influence other s-boxes if some mode of
    feedback is implemented, etc) and the derivation "Crypto Tools" only
    intended to offer the plain, old (but to be fair not known to be
    practically broken) RC4 with all described hardening implemented.
    At least see it like a tribute to a little tool that I liked very much
    that is CipherSaber, since the application can be used in strictly
    CipherSaber compatible mode, to encrypt and decrypt file from a GUI
    interoperating with any other CipherSaber implementation.


  • Next message: simon: "Re: Is YellowCrypt OK?"

    Relevant Pages

    • Re: RC4 broken?
      ... and the method fails if two iterations of RC4 are used. ... I suspect that whoever wrote this was talking about Ciphersaber, ... RC4 in a way that made it vulnerable to the attack presented in the paper ... happens to be one of these extremely weak keys. ...
      (sci.crypt)
    • Re: Whats wrong with this RC4?
      ... > starting point about RC4 basis, example code and general warnings about ... > http://ciphersaber.gurus.com/ is an ARCFOUR implementation targheted to ... > be easy to uderstand and implement properly (ciphersaber ... > scheduling and in the cypher itself (experimental, ...
      (sci.crypt)
    • Re: Crypto Mini-FAQ
      ... > I did not find the collection of Ciphersaber (RC4) implementations. ... > Does anyone have a suggestion? ...
      (sci.crypt)
    • Re: Is YellowCrypt OK?
      ... >>RC4 is also recommended by this very forum. ... forums don't recommend algorithms; ...
      (sci.crypt)
    • Re: Generate a one-time pad from say a 256bit key?
      ... information, so we should recommend them, and not ... The question is not should it be recommended, but is it secure. ... deriving the messages from the encrypted text as is RC4. ... Greg Rose ...
      (sci.crypt)

  • Quantcast