Re: How much must be revealed



HilltopLab@xxxxxxxxxxxxx schrieb:
If I have an encryption program, is it possible to describe the
algorithm sufficiently to give people confidence in its security
without revealing the source code? Or must it be given away before any
worth is appreciated?
These are two different issues:
You can convince peope to trust your /algorithm/ by publishing it. Or by choosing a well known one and saying "I use AES/CTR with that kind of Key/Counter management".

You can convince people that you are not a liar by providing source code.
In cases without random numbers (i.e. if your program is fully deterministic)
people can perhaps trust you if they can reproduce ciphertext by means of pencil and paper and it matches your output and you take reasonable pains
to ensure integrity of thge download (i.e. by providing pgp keys, checksums
and the like).

Lots of Greetings!
Volker
--
For email replies, please substitute the obvious.
.



Relevant Pages

  • Re: How much must be revealed
    ... You can convince peope to trust your /algorithm/ by publishing it. ... You can convince people that you are not a liar by providing source code. ... Not only because the algorithm cannot be ...
    (sci.crypt)
  • RE: [Full-Disclosure] Vulnerability response times -- MS and others
    ... > on solving security issues. ... no trust should be placed in code from others. ... There is little trust to be placed in source code. ... Microsoft is willing to place their complete trust in all those ...
    (Full-Disclosure)
  • Re: How To Give The Client Peace Of Mind
    ... would be better spent gaining brownie points with the customer by just ... Give them the source code and they will be more relaxed ... about this issue and it will increase their trust in you. ... Thanks for the reply DFS. ...
    (comp.databases.ms-access)
  • Re: Linux jpg conversion
    ... For me what matters more is "trust in verifiability". ... who probably does *not* read source code. ... I personally compile many of the ... saying that Open Source is *ever* going to be perfect. ...
    (rec.photo.digital.slr-systems)
  • Re: Linux jpg conversion
    ... I feel that the trust in "open source" is rather misplaced. ... I do sometimes read source code. ... | compile the OS yourself? ...
    (rec.photo.digital.slr-systems)