> Converse curiously; don't cross-examine.
You could have just corrected them and not goaded them into further revealing their ignorance. Yes, they underestimated how difficult it is to crack 3DES. You could have simply told them that.
> Converse curiously; don't cross-examine.
You could have just corrected them and not goaded them into further revealing their ignorance. Yes, they underestimated how difficult it is to crack 3DES. You could have simply told them that.
The thread that ensued, a discussion of what it means for a cipher to be obsoleted or unsafe versus "broken", is an actually-interesting question.
I feel pretty OK about how this went.
> The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, ...
They're clearly talking about it's use as a cipher. Again, someone who has been here as long as you have should understand that you shouldn't put words in their mouth or be evasive in this way.
The conversation would still have touched on these interesting topics, and would likely have done so more immediately.
They were clearly suggesting that there exists a publicly available tool to attack this algorithm. They clearly didn't care one way or the other about whether it was used in passwords. What they actually cited was vulnerabilities in network services.
You are being disingenuous. Cut it out.
They were clearly suggesting that there exists a publicly available tool to attack this algorithm.
What were you referring to? If it was Hashcat, then I have just one more question:
Is Hashcat a publicly available tool that attacks AES?
with a quick google of "3des broken" and reading the first paragraph of wikipedia on 3des, i was able to guess (correctly!) what they original commenter was referring to.
Thank you!