Re: Compression and crypto
- From: "giorgio.tani" <giorgio.tani@xxxxxxxx>
- Date: 22 May 2006 23:28:18 -0700
Thats the problem its a mistake waiting to bite you. You should assumeI know, I know, with compression we usually put a non negligeable
if you want security that it might be vulnerabe to a plaintext attack
quantity of known or predictable information to "housekeeping" to allow
uncompression.
However, a lot of known or predictable information is anyway featured
in the plaintext in a real world case: think what happens encrypting a
file of known format, we have the header and padding that are known to
the attacker; encryptiong a database, a lot of padding matherial or
some field may be as well be known or guessed, and so on.
Moreover the whole point of my post was that we should *always* assume
that the attacker have an arbitrary knowledge of the plaintext, and
still be not able to recover the key, nor to recover any single bit of
the message he/she doesn't know with a probability > 1/2^n where n is
the number of bit unknown to the attacker, so we anyway need to use
only cryptosystems known to not allow plaintext attack, and imediately
cease using cryptosystems were emerges such attacks, since relying on a
a perfect secrecy of the whole plaintext to te attacker is practically
very hard to obtain (however, I completely agree with you as it would
save us some headhackes making the whole category of plaintext attacks
infeasible, that would be really a good security feature!) and for
Kerckhoffs' principles we should not even need to assume it.
.
- Follow-Ups:
- Re: Compression and crypto
- From: David A. Scott
- Re: Compression and crypto
- References:
- NSA and crypto
- From: David A. Scott
- Re: NSA and crypto
- From: David A. Scott
- Re: NSA and crypto
- From: David A. Scott
- Re: Compression and crypto
- From: David A. Scott
- Re: Compression and crypto
- From: David Wagner
- Re: Compression and crypto
- From: David A. Scott
- Re: Compression and crypto
- From: JR
- Re: Compression and crypto
- From: giorgio.tani
- Re: Compression and crypto
- From: David A. Scott
- NSA and crypto
- Prev by Date: Re: Resources required to retrieved wiped disk
- Next by Date: Re: java implementation of homomorphic encryption
- Previous by thread: Re: Compression and crypto
- Next by thread: Re: Compression and crypto
- Index(es):
Relevant Pages
|