SRP + 3DES - secure enough?



My application uses SRP for authentication and then uses the random
session data produced during the SRP authentication process to seed
3DES for encrypting the actual communications.

My question. Once encryption is set up, my application does its own
signon handshake. The data in that handshake is pretty much
constant. Is that a big security hole, or does 3DES do more than XOR
the data against a bit unknown (and changing) value? For example,
does 3DES send the data bytes in a random order or do anything else
that would make it impossible to guess the key based on knowing the
data that's being encrypted?

If not, are there recommendations for 'randomizing' the communications
to fix the problem. Something like inserting random numbers into
unused places in the data stream prior to encryption.

Thanks,
Rob
.



Relevant Pages

  • Re: FW: US Congress already discussing bans on strong crypto
    ... > WASHINGTON -- The encryption wars have begun. ... > communications unintelligible to eavesdroppers. ... > In a floor speech on Thursday, Sen. Judd Gregg ... > backdoors for government surveillance. ...
    (FreeBSD-Security)
  • Re: Conspiracy in the Surveillance Society
    ... I want there to be a world-threatening conspiracy. ... Congregating seems difficult. ... Communications is tougher. ... Encryption might hide what you're saying, ...
    (rec.arts.sf.science)
  • Re: NaNoWriMo, anyone?
    ... such as the Washington-based Intelsat Corporation provide encryption. ... They do not let their customers know that their international communications ... Politicians, whom the public has presumed will be monitoring the intelligence ... If a democratic society wants to control its secret agencies, ...
    (comp.arch)
  • i was offseting providers to instant Pam, whos substituting into the groups community
    ... If you will pay Ramzi's sink as to attendances, it will hence demolish the distinction. ... Yet they neither invest in encryption technology nor insist that organizations ... They do not let their customers know that their international communications ... government and private organizations that innocently entrust their ...
    (sci.crypt)
  • why Anastasias dark texture flys, Abdellah eats contrary to mature, existing parks
    ... Yet they neither invest in encryption technology nor insist that organizations ... They do not let their customers know that their international communications ... are open to continuous interception. ... government and private organizations that innocently entrust their ...
    (sci.crypt)

Loading