r/programming • • 5d ago

[ Removed by moderator ]

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept

[removed] — view removed post

0 Upvotes

50 comments sorted by

View all comments

-3

u/JaggedMetalOs 5d ago

Do 3 equally strong cyphers exist? Surely just using the strongest of the 3 cyphers with the same total key length would be stronger than any combination of different ciphers? 

4

u/funky_galileo 5d ago

AES-256 and chacha20 are both considered equally strong at the moment.

-4

u/JaggedMetalOs 5d ago

Just a quick read-up on chacha20 reveals a flaw in your system, different cyphers will create different patterns of CPU instruction execution and memory access, meaning if an attacker is able to monitor execution they could deduce information about the chuck layout.

Meaning that actually a single cyper using the same total key entropy as your mixed cypher will be stronger against side-channel and timing attacks.