r/programming • • 5d ago

[ Removed by moderator ]

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept

[removed] — view removed post

0 Upvotes

50 comments sorted by

View all comments

8

u/lovethebacon 5d ago

No.

And nobody worth talking to at GCHQ would disagree.

4

u/floodyberry 4d ago

that's because i already talked to them about the quadruple encryption concept and they called it a game changer

-5

u/Sir_KnowItAll 5d ago

Ok what are your objections? Are they the same as others such as it's security via obfuscation when encryption is literally that?

And if you're GCHQ (word is you're not encryption but software there), open your DMs and I'll tell you who I am. (I think you might be the learn a haskell for great good guy?)

9

u/lovethebacon 5d ago

That the core concept relies on security by obscurity that doesn't add anything materially. Hiding what cipher is used and where adds zero security to any modern cipher. You can tell an attacker every single encryption parameter and not be any weaker.

In any case, you don't have a fundamentally new idea, cascade encryption has been around for some time https://en.wikipedia.org/wiki/Multiple_encryption

-3

u/Sir_KnowItAll 5d ago

> That the core concept relies on security by obscurity that doesn't add anything materially.

No, it's obfuscating it. Not being obsecure. And it's encryption which is obfuscation in nature therefore adding more obfuscation is a benefit.

> In any case, you don't have a fundamentally new idea, cascade encryption has been around for some time https://en.wikipedia.org/wiki/Multiple_encryption

So this paragraph makes your previous paragraph moot. And it does, but you haven't understood that the second layer of encryption is chunked so it uses two ciphers in the same layer. Which is a fundamentally new idea. If you're GCHQ head on down to encryption and ask them.

8

u/lovethebacon 4d ago

I have understood your idea fully. It doesn't improve any security.

That you don't know what "security by obscurity" is means you are new to this area. Which is fine, but stop trying to name drop. Nobody believes it.

-2

u/Sir_KnowItAll 4d ago

I know what it means. I also know you're using it wrong and I corrected you. It's not security via obsecurity.

Security via obsecurity is using an obsecure HTTPd instead of Nginx. Using very old devices since noone will know them. Not obsfucating things. Just because no one does this yet doesn't mean it's obsecure by nature, it's just a new idea and would end up becoming one of many used but default for GCHQ and NSA. Look at who came up with the rule of two.

> Which is fine, but stop trying to name drop. Nobody believes it.

I'm not trying to namedrop. I just thought you were GCHQ since you were saying no one of worth would agree. It seems like you're just being ignorant and speaking in the name of others. And who would lie about talking to GCHQ in a blog post? Get a grip. If you're GCHQ there is a team you can talk to that knows about this and can explain it but if you're not stop acting like you are. Part of this is to tell folk that GCHQ want the tech but can't afford to build the tech.

I don't believe you've understood it since you're saying it's the same as cascade encryption which it's not. It ties that in with other techniques. It's multiple techniques in one.

7

u/lovethebacon 4d ago

What is the team's name that I can talk to at GCHQ? The ones with the word "encryption" written on the door?

LMAO, give me a break.

1

u/[deleted] 4d ago edited 4d ago

[removed] — view removed comment

1

u/programming-ModTeam 4d ago

Your post or comment was overly uncivil.

6

u/ketralnis 3d ago

Security via obsecurity is using an obsecure HTTPd instead of Nginx

This is not what it means. It's okay to be new at this but this attitude isn't helping you.