RE: Data integrity check in CIPE - Please explain me the necessit yor benefit of a larger checksum.
Тарасов Андрей Андреев ич <[email protected]>
| Newsgroups | gmane.comp.encryption.cipe |
|---|---|
| Message-ID | <117DF1A7B1C6D411BEE50000212B25B32546@EXCH> |
Hi Hans & everybody! > Hi Taracos (?), > > >> ôÁÒÁÓÏ×, (Taracos?) > >> > >Sorry, national language encoding. Corporate standard and > such. Can't > >write from home. > Doesn't matter, I just was curious if I translated the > russian alphabet correctly. Close to that :) Tarasov would be more correct. > > >I've tried to ran cipe over fast ethernet and achieved 1.7 mbps > uncompressed > >FTP file transfer with P-225 (overclocked a bit :)) > What do you get without CIPE? Never tried. If you ask about bandwith, it's asymmetric and is varying from 512 to 800 k in the slower direction. > >Another idea just popped up in my mind: why we can't just put CRC32 > >into encrypted part of the message, and control consistency of the > >message > after, > >say , "blind" decription? This just won't let any open part > that could > >possibly be analyzed and corrupted, except for the whole message? > > > This looks like an example of synchronicity: Mark came with > the same idea. See the list for the responses. It is worth to > investigate. I must apologise for being too hasty. As follows from the protocol.txt, checksum is already transferred in the encrypted part of the message, so all transmission over cipe tunnel is secure as long as secret key is secure. Of course, stronger hash will improve things, but there are no immediate danger (in my hasty opinion :)) Man in the middle can force using secret key more often, and may also ran a DOS attack, but don’t think that we can handle this with a simple patch. Being in the middle is too powerful position anyway. For example, one can flood you with total garbage on cipe ports (with source address spoofed), and I see no protection. -- Message sent by the [email protected] mailing list. Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body Other commands available with "help" in body to the same address. CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>