Re: NSA and crypto



David A. Scott wrote:
I see you are aruging with little Tommy much has not changed he has
no concept of entropy or Unicity Distance. It is strange he seems
to think if the file is compressed and has same amount of entropy
as a long uncompressed file that it may be easier to break the shorter
file that has a higher entropy density. However he does have a point he
just does not see it. The gzip file with AES may be easier to break
than AES alone since the gzip carries with it a signature that is its
not bijective even if you carefully remove all the headers.

Let me explain the problem so you can understand.

Suppose I have some ciphertext C and I guess a key K. I can decrypt it
to a plaintext P' which through your bijective codec will decompress to
some string P''. All strings P' are valid to the decompressor. And
all of them produce strings that have symbols from a given alphabet.

So far so good.

However, you haven't said how you make sure that all decodings follow a
proper grammar. For instance, I decrypt a JPEG and decompress to some
string of octets. The string won't be a valid JPEG and therefore I can
reject the guessed key as invalid.

Does that make sense now?

Have you got that through your thick f'ing skull yet?

Tom

.



Relevant Pages

  • Re: NSA and crypto
    ... |> no concept of entropy or Unicity Distance. ... I decrypt a JPEG and decompress to some ... | string of octets. ... Heheheheheh h-h-hey ButtHead - he said ...
    (sci.crypt)
  • Re: new /dev/random
    ... >A c1,c2 entropy generator takes any input k and produces a string of ... >fixing any probability distribution it likes over those strings, ... >long as the entropy exceeds k. ... our mixer to do a good job with, we can then ask whether applying SHA1 ...
    (sci.crypt)
  • Re: Entropy
    ... to be the entropy. ... Shannon understands concrete messages as *samples* coming from a ... compress *on average* all messages coming from said source. ... the shortest computer algorithm that re-generates the string. ...
    (comp.compression)
  • Re: Entropy
    ... This bound is then shown to be the entropy. ... Shannon understands concrete messages as *samples* coming from a random source. ... In the Kolmogorov case, a message is an individual thing, but an infinitely long string for which you seek the shortest computer algorithm that re-generates the string. ...
    (comp.compression)
  • Re: VNC authentication weakness
    ... > the randomness pool, but should rarely be used in applications, IMHO. ... > without blocking to wait for more entropy input. ... string in the form, and when the form was posted, checked ... Thus, for an attacker to produce a fake form, they must obtain ...
    (Bugtraq)

Loading