I was under the impression was GCM was one of the better AES modes. Why is it awful?
I was under the impression was GCM was one of the better AES modes. Why is it awful?
I whatever I was developing was open source (any project under an OSI-approved license gets a patent grant), I would use OCB mode, which is not only quite easy to get right, but also friggin fast.
But hey: Don't trust me. Trust Matthew D Green:
> GCM. Galois Counter Mode has quietly become the most popular AE(AD) mode in the field today, despite the fact that everyone hates it. The popularity is due in part to the fact that GCM is extremely fast, but mostly it’s because the mode is patent-free. GCM is ‘on-line’ and can be parallelized, and (best): recent versions of OpenSSL and Crypto++ provide good implementations, mostly because it’s now supported as a TLS ciphersuite. As a side benefit, GCM will occasionally visit your house and fix broken appliances.
> Given all these great features, you might ask: why does everyone hate GCM? In truth, the only people who hate GCM are those who’ve had to implement it. You see, GCM is CTR mode encryption with the addition of a Carter-Wegman MAC set in a Galois field. If you just went ‘sfjshhuh?’, you now understand what I’m talking about. Implementing GCM is a hassle in a way that most other AEADs are not. But if you have someone else’s implementation — say OpenSSL’s — it’s a perfectly lovely mode.
-- Matthew D Green [1]
[1]: https://blog.cryptographyengineering.com/2012/05/19/how-to-c...
If you don’t care about a built in MAC, would you recommend CTR? OCB?
The user wants something that works reliably. If it's hard to implement, confidence decreases. You can compensate with external audits, but those are expensive.
> If you don’t care about a built in MAC, would you recommend CTR? OCB?
You almost always care about built in MAC. If you don't authenticate your data, you will most likely run into trouble. And if you really don't care, I'd rather sidestep the CTR vs OCB vs WTF entirely by using Chacha20 (fast without dedicated hardware, naturally immune to timing attacks, dead simple to implement).
(In the general case, I'd recommend Chacha20 + Poly1305 constructions.)
If you don't have any very good reasons to use CTR (encrypting lots of data with the same key) you.probably shouldn't.