Re: Beginner Question:Rijndael encrypted value over SSL



On Mar 23, 7:08 pm, Mike Amling <nos...@xxxxxxxxxx> wrote:
Matthew Fanto wrote:
I would hardly call RC4 minimal protection if it's done right, which
it is in SSL/TLS. There are certainly weaknesses in RC4, it is bias,
and everything else, but from a practical standpoint, it's not that
weak in SSL/TLS.

You can make that case for 128-bit RC4, but you don't want to
generalize to include SSL's 40-bit RC4.


That much is obvious. A reasonable assumption to make is that I wasn't
including export grade keysizes in my comments as to the relative
strength of RC4. But I suppose to be entirely precise, I should have
said 128-bit RC4.

-Matt


.



Relevant Pages

  • Re: ... Leopard11 CSPRNG ....
    ... You're stating "has no bias" yadada has no merit or weight with this crowd. ... Heck you claimed that Leopard1 had no bias [with the same lack of proof I ... Also, yes RC4 has problems, but just because your algorithm is not RC4 ... It will never hit A again so what is the cycle length? ...
    (sci.crypt)
  • Re: Some questions about stream cyphers.
    ... >does not exhibit the bias that has ... >been demonstrated in RC4. ... I ran a few terabytes ... >just for the fun of it, ...
    (sci.crypt)
  • Re: Needle in a haystack--or is this just stupid?
    ... > reasonably secure if used correctly. ... Regardless RC4 is actually harder to use correctly than that. ... because the first byte has a substantial bias, and 256 makes sense for RC4. ... You demonstrated a lack of understanding of how the attacks actually work ...
    (sci.crypt)
  • Re: Generate a one-time pad from say a 256bit key?
    ... I ask again, what cypher do you suggest that is faster, and more secure. ... Rubin suggested AES or 3DES which probably satisfy the second criterion, ... While the bias is unfortunate, it is not something that anyone knows how to ... use to break RC4 ...
    (sci.crypt)
  • Re: Some questions about stream cyphers.
    ... > does not exhibit the bias that has ... > been demonstrated in RC4. ... I ran a few terabytes ... of a fairly ideal generator would have 'some' bias, ...
    (sci.crypt)