RE: Data integrity check in CIPE - Please explain me the necessityor benefit of a larger checksum.

"Mark Smith" <[email protected]>
Newsgroups gmane.comp.encryption.cipe
Message-ID <000601c38670$aeefdc00$d100010a@lyta>
Two items quickly:

Has anyone else had any thoughts about a second list, and if so could anyone
host it?  I'm in the process if finding out if I can get permission, it
appears to be technically possible.

Second, has anyone thought about the just as serious problem of message
replay?  Message deletion for UDP means nothing to me as UDP can drop a
packet just as easily on it's own.  Replay either of existing or modified
packets provides another security hole.  I believe any change should attempt
to address this as well since even I could figure out how to exploit it.

As for CRC itself - can I ask, is the checksum calculated pre- or post-
encryption?  Could a copy of the checksum be included in the payload for
comparison to ensure it hasn't been altered, but without compromising the
encryption key?  I'd imagine that if the checksum was then compressed it
would be 'harder' to compromise.  Would this be enough, perhaps for both
vulnerabilities?

I'm guessing, feel free to explain if you know better.

--
Mark Smith - Avco Systems Ltd
email: [email protected]
Tel: +44 (0)1784 430996 Fax: +44 (0)1784 431078


--
Message sent by the [email protected] mailing list.
Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.