Playing with symmetric encryption algorithms in Ruby
medium.com
medium.com
Debatable. AES-256 is more a hedge against the most optimistic views of quantum computers. Its not like a classical computer is going to get fast enough to actually need that.
> The different modes of encryption algorithms is out of the scope of this blog post so we will not take a deeper look at them
Danger! Danger! The mode is one of the most important parameters. If you do this wrong it will not be secure.
> [a bunch of examples using CBC mode without authentication]
And this is why discussing modes is important. The examples are insecure because they are using CBC mode incorrectly.
Note: I'm not an expert, just a better-than-average-informed worker near the field. I've had the joy and privilege of working with two expert cryptographers and an expert cryptanalyst, and it was a humbling experience: Brains the size of planets and three of nicest, most decent people you'd ever meet.
Side-note: I was working late on a design doc based in part on one of the first PKIX drafts when I came upon something that struck me as odd. The cryptographer responsible for the draft was also working late, so I wandered over to his office and asked about it. Long story short, after we'd drawn and erased a few diagrams on/from his whiteboard, this affable, sweet man fixed me with what I can only describe as a "Cylon stare" and said "So you're saying the lifetime should apply to the key, not the certificate?" When I said "yes", rather more meekly than I'd meant to, the Cylon disappeared and he said offhandedly "OK, I'll update the draft!"
I love working with really smart people. Working with smart nice people is sublime.