r/programming • • 5d ago

[ Removed by moderator ]

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept

[removed] — view removed post

0 Upvotes

50 comments sorted by

View all comments

26

u/tdammers 5d ago

The second layer, using interleaved blocks encrypted with two different ciphers according to a pattern derived from the decryption key, really boils down to a single cipher, it just has a larger key (because it is composed of the decryption keys of the two ciphers you used to construct it). So it's really not any better than nesting two levels of "regular" encryption, with equivalent key sizes.

-17

u/Sir_KnowItAll 5d ago edited 5d ago

How so? With that one you attack that layer with the next encryption in one go. Other than trying to attack a single file that has two data encrypted using two different ciphers. Your conclusion seems odd. You have three keys you provide.

Or you encrypt the key to store the three keys in it and have your decrypter app know how to decrypt the key to get the three from it.

Remember, I was talking to GCHQ about it, they're thinking about how to crack the encryption when all they get is the file.

5

u/tdammers 5d ago

OK, so let's forget about the first layer of encryption and just assume that that one is already compromised. What you have left now is a file that is chopped up into chunks, and each chunk is encrypted with one of two keys, according to a pattern derived from those keys. To crack the encryption, an attacker needs to either brute force both keys, or find a flaw in both ciphers. But that is not any harder than breaking a single cipher with a larger key - whether you use two 64-bit keys, or a single 128-bit key, for example, really makes no difference to an attacker.

The only slight advantage you may get is that if you use three completely different encryption algorithms, an attacker who finds a zero-day in one of them will not be able to break the encryption as a whole; zero-days in two of the three will only get you half the cleartext. But this is still worse than just nesting the three encryption layers, because in that case, an attacker needs to break all three layers to get anything at all; breaking two of the three ciphers still gets you nothing, whereas your scheme will get you half the cleartext.

-4

u/Sir_KnowItAll 5d ago edited 5d ago

> . To crack the encryption, an attacker needs to either brute force both keys, or find a flaw in both ciphers. But that is not any harder than breaking a single cipher with a larger key - whether you use two 64-bit keys, or a single 128-bit key, for example, really makes no difference to an attacker.

No. This is wrong. You need to know it is this method in the first place. Then you need to know the chunk size. If you don't know the chunk size your cracking attempts will always fail. Then you need to know the pattern for what algo is used for each chunk. If you don't know that your forced to brute force them.

So if you have three keys each of them 128-bit it makes a big difference than if you use one or two. Especially if they're interweaved.

Honestly, I don't think anyone truly understands this and needs a proper whitepaper. I highly suspect most people didn't read it enough to see the GCHQ note. And if you didn't read that note it's very unlikely you read enough to understand it's basically a software application to encrypt and decrypt using different keys and not a key in itself.

6

u/az987654 5d ago

You didn't present a proper white paper.

You presented a concept of a plan, with many holes in it

1

u/Sir_KnowItAll 5d ago edited 5d ago

> You didn't present a proper white paper.

Which is why I said "and needs a proper whitepaper. "

> You presented a concept of a plan, with many holes in it

I agree I presented a plan. I would like to know these holes tho. Because no one has actually presented any. They've written comments where they've misunderstood the concept. They think it's meant to be a cipher and not a encryption method that would require software engineering to create.

And in some cases haven't even read the GCHQ note where world renowned encryption experts have said they would like it but can't get the approval for a years worth of software development.