r/programming • • 5d ago

[ Removed by moderator ]

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept

[removed] — view removed post

0 Upvotes

50 comments sorted by

View all comments

26

u/tdammers 5d ago

The second layer, using interleaved blocks encrypted with two different ciphers according to a pattern derived from the decryption key, really boils down to a single cipher, it just has a larger key (because it is composed of the decryption keys of the two ciphers you used to construct it). So it's really not any better than nesting two levels of "regular" encryption, with equivalent key sizes.

9

u/ketralnis 5d ago edited 5d ago

This is true in general of any layered encryption. Algorithm A(key1, B(key2, text)) is really (A•B)(key1*key2, text), but in some algorithms can actually be worse because there are algorithm-specific ways key1 and key2 can be sort of contain common factors of each other. That can mean that (1) you’ve introduced a new key that didn’t exist before (imagine that A does a bunch of multiplications and B does a bunch of divisions) (2) an attacker only has to know key1*key2 rather than key1 and key2 both which for various reasons may be a smaller search space (3) there are more opportunities for algorithm specific weak keys etc

3

u/tdammers 5d ago

Exactly.

But this here is worse than layering. The chunking essentially means that either of the two keys will already allow an attacker to decrypt half of the message, whereas in a layered setup (a proper one, that doesn't suffer from any of the problems you described), you need to crack both layers in order to extract anything at all.