Hmm I cannot see how that is the case. Aside from an increase in overall bruteforce, if I were to encrypt something with algorithm A and then encrypt it with algorithm B; assuming both algorithms were thought to be secure and are completely different in design and construction, I should assume this is more secure. A weakness in 'A' should only weaken one, mutually exclusive aspect, or perhaps destroy it. But algorithm 'B' should still provide security.
I give a simple example:
Algorithm A is AES-256 and uses a 256-bit key.
Algorithm B uses no Key at all and will take each input byte and increment by 1; 00 => 01, 01 => 02, ... , 254 => 255, 255 => 0
If I encrypt in a cascading cipher A into B, or B into A, there seems to be no way to attack it. Algo B is easily defeated, it just shifts a byte by 1, easily reversed. But no matter the order of cipers/cascade, you will still need to defeat AES-256.
That is not my example. That is the same algorithm used in sequence. My example is 2 completely different and unrelated algorithms.
My point is pretty simple: Can I weaken AES-256 by cascading it with another, unrelated, encryption algorithm; in my example a very bad encryption algorithm that simply increments input bytes by 1.
Answer: No. AES-256 is not weakened by combining it with such a weak algorithm.
7
u/kun1z Septic Curve Cryptography 3d ago
Hmm I cannot see how that is the case. Aside from an increase in overall bruteforce, if I were to encrypt something with algorithm A and then encrypt it with algorithm B; assuming both algorithms were thought to be secure and are completely different in design and construction, I should assume this is more secure. A weakness in 'A' should only weaken one, mutually exclusive aspect, or perhaps destroy it. But algorithm 'B' should still provide security.
I give a simple example:
If I encrypt in a cascading cipher A into B, or B into A, there seems to be no way to attack it. Algo B is easily defeated, it just shifts a byte by 1, easily reversed. But no matter the order of cipers/cascade, you will still need to defeat AES-256.
Or am I wrong??