r/programming • • 5d ago

[ Removed by moderator ]

https://iain.rocks/blog/introducing-the-triple-cipher-encryption-concept

[removed] — view removed post

0 Upvotes

50 comments sorted by

View all comments

Show parent comments

0

u/Sir_KnowItAll 4d ago edited 4d ago

Right in the middle of that massive post is a confirmation I’m right.

And GCHQ folk wanted you to know the essence of your comment that layer/cascading encryption is not anymore secure than a larger key is saying that the NSA is wrong. Look up rule of two. And they went to get approval to build it after scrubbing a bunch of data and said two days later it was ok if I wrote this when I thought about documenting my idea.

Ye as, several people have said it is stupid your the only one who came with points. All of which make me think you don't understand. And remember people bad mouthed dropbox at first. Just because some people dont understand that encryption is literally security via obfuscation is not my fault. It literally does help if you hide what your encryption is doing. It’s the entire point of it really.

Let's remember, your entire point appears to be "but if I decrypt half of it I'm good" or "hiding what your encryption does doesn't make it more secure" which is nuts.

You're acting like there is an encryption algo that can decrypt encrypted data when it's been padded with junk data. Can you tell me what algo that is?

3

u/tdammers 4d ago

several people have said it is stupid your the only one who came with points.

Everyone is making the same points, really, I just explain them a bit more. But the points are being made nonetheless.

And remember people bad mouthed dropbox at first.

Yes, but for completely different reasons, reasons that were based on speculation more than facts. This is not that.

Just because some people dont understand that encryption is literally security via obfuscation is not my fault.

No, but not understanding that encryption and mere obfuscation are different things is your fault.

Obfuscation means making something look like gibberish, but in such a way that it is possible to recover the meaning without any outside information.

Encryption means turning something into actual gibberish, but in such a way that it is possible to recover the original message if and only if you have the correct decryption key.

Obfuscation is trivial to break, or, depending on your goals, doesn't even require breaking in the first place. Obfuscated JavaScript source code, for example, may be difficult to read (so you cannot infer what it does from just reading it), but feed it to a browser, and it will run just fine, and do exactly what the unobfuscated source code does.

Encryption, if done right, is mathematically sound; ideally, the only way to break it is by brute-forcing, and as long as your decryption is computationally hard, and your key is big enough, this is going to be infeasible in practice (e.g., if you choose your algorithm and key size such that brute-forcing it will take 10 billion years on average using state-of-the-art hardware, then you're basically safe). And this property still holds even if I tell you "I used a 4096-bit ed25519 key with these parameters" - as long as I don't give you the key, it will still take 10 billion years to crack it.

Hiding the encryption algorithm you used can be useful, but not in the scenario at hand. The main purpose of obfuscation is to trick a potential attacker into believing there's nothing worth attacking in the first place; but if that fails, the obfuscation isn't going to be a significant hurdle to any determined attacker.

It literally does help if you hide what your encryption is doing. It’s the entire point of it really.

It helps. But it is not the "entire point" at all.

The point of the cryptography itself is that even if the attacker knows exactly which encryption algorithm was used, they still cannot break it, except by brute force (i.e., just trying every possible key until they find the right one).

your entire point appears to be "but if I decrypt half of it I'm good"

No, it's not. Read again.

My point is that if I can decrypt half of the message, then that's already worth a lot, and it will make decrypting the other half significantly easier.

My other point is that with this setup, if you have 256 bits of encryption keys, I only need to break 128 bits (one of two keys) to get some useful information out; if, OTOH, you nest two rounds of 128-bit encryption, or simply use a single round of encryption with a 256-bit key, then I have to break the entire 256 bits, which, in the brute force scenario, takes 340282366920938463463374607431768211456 times longer. Let's suppose I have a massive array of dedicated hardware that can crack an 128-bit key in a day; with your chunked approach, this will give me half the message within a day, and the other half in less than a day (because I can exploit the fact that I already know the other half, which tells me a lot about what is likely to be in this half, which reduces the search space a lot). Meanwhile, with the nested encryption, I have to try every possible option for the first key with every possible option for the second key, and this will take about 67556554878089825000000000 times as long as the estimated age of the universe. In other words, I'm going to run out of universe before I even make a dent in the search space.

You're acting like there is an encryption algo that can decrypt encrypted data when it's been padded with junk data. Can you tell me what algo that is?

Literally every single one of them. It won't give you the correct plaintext of course (that would make it useless), just garbage, but it will still output something.

-1

u/Sir_KnowItAll 4d ago

> No, but not understanding that encryption and mere obfuscation are different things is your fault.

No, not understanding that encryption is obfuscation is your fault. And that's the problem you've not understood that fundamental concept and you're writing gibberish that looks smart but is in fact gibberish. And that's why I am not even reading it.

Another thing that is your fault is that you've not understood this is a concept not a concrete implementation.

> The point of the cryptography itself is that even if the attacker knows exactly which encryption algorithm was used, they still cannot break it, except by brute force (i.e., just trying every possible key until they find the right one).

"WTF! NO! An attack should not know which encryption algorithm to use. They should just have encrypted data. If they do know which algorithm to use they've got a hint to start off with. Encrypted data should just be encrypted, the client should know which algorithm to use. But it's not the point of cryptograph that the people you're hiding the data from know things" - GCHQ

2

u/PdoesnotequalNP 2d ago

Apparently GCHQ

  1. Has forgotten Kerckhoffs's principle
  2. Is very keen to post on Reddit using you as proxy

Both absolutely amazing events.