GnuPG 1.4.15 released
lists.gnupg.org
lists.gnupg.org
I suspect GnuPG only officially distributes source code now, which is slightly safer to use for obvious reasons. :)
www.steike.com/code/useless/zip-file-quine/
* https://admin.fedoraproject.org/updates/gnupg-1.4.15-1.fc18 * https://admin.fedoraproject.org/updates/gnupg-1.4.15-1.fc19 * https://admin.fedoraproject.org/updates/gnupg-1.4.15-1.fc20
According to tptacek, that's in the works, but seems like that didn't make it into this release.
Does anyone know what the Chinese equivalent of NIST is? What does China use?
https://en.wikipedia.org/wiki/SMS4
https://en.wikipedia.org/wiki/Zuc_stream_cipher
Not sure why anybody would want to use them or the GOST standards unless required/forced to do so.
I have no idea how useful this would be in practice.
If you cascade the two ciphers, the American government needs to find a real weakness in the Chinese cipher, and the Chinese government needs to find a real weakness in the American cipher. Which they might have, but they at least can't use backdoors at this point.
That assumes that f(g(x)) is harder to invert than either f(x) or g(x) individually, which is not true in the general case for encryption schemes.
It is quite possible that (f∘g) can be cracked in a way that neither f or g can individually.
It's still twice as hard, correct? And if you have two ciphers, one of which is compromised in some way, wouldn't this composition mean that you're at least as secure as the most secure of the two ciphers?
Also, how does 3DES get away with this? I read on wikipedia (after I looked up the meet in the middle attack) that 3DES encrypts, then decrypts with a second key, then encrypts, and presumably decrypts-encrypts-decrypts on 3DES-decryption -- how is this different?
(Thanks for answering these questions; it's contributed to my knowledge of crypto and I really appreciate it.)
Exactly, and "twice as hard" is another way to say "one extra bit of security."
"It's still twice as hard, correct? And if you have two ciphers, one of which is compromised in some way, wouldn't this composition mean that you're at least as secure as the most secure of the two ciphers?"
It took me some time to locate this, but it is relevant:
http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.36....
You can think of it this way: the meet-in-the-middle attack is generic and does not exploit the structure of the ciphers at all, whereas attacks that do exploit the structure of the ciphers might exist and might do better when the ciphers are composed. In general you should avoid carelessly composing cryptosystems (for that matter, you should avoid carelessly composing cryptosystems with other systems; e.g. the Skype attack).
"Also, how does 3DES get away with this?"
The security of 3DES is twice the security of single DES; the attack still works, but it can only remove one of the DES applications. Note also that 3DES is DES composed with itself, and so attacks on the structure of the components would imply weaknesses in DES itself.