Re: des-die-die-die and RC4
Tom Yu <[email protected]>
| Newsgroups | gmane.ietf.krb-wg |
|---|---|
| Message-ID | <[email protected]> |
Martin Rex <[email protected]> writes: > I was confused by this statement: > > OCTET L40[14] = "fortybits"; > > but the actual truncation of the RC4 key is this: > > if (export) memset (K1+7, 0xAB, 9); > > which flattens 9 of 16 octets (and therefore leave 7 octets = 56 bits). I previously had the same sort of confusion, and wrote text pointing out that 40 bits is small enough to be easily brute-forced by consumer-grade hardware before realizing my mistake. > Tom Yu wrote: >> >> Martin Rex <[email protected]> writes: >> >> > Actually, I would prefer the document to use a different quoting: >> > >> > "export strength RC4" or "40-bit RC4 (RC4_EXP)" >> > >> > rather than >> > >> > "export strength" RC4 >> >> What semantic difference would you want to imply by making such a >> change? (I assume you mean changing the quoting in both the title and >> the body.) >> > > The latter could be interpreted that RC4 is "export strength", > although the term "export strength" is not an attribute to RC4 in > general, but to variants of RC4 with a purposely short (or truncated) key. > > Not everyone is aware what "export strength" means. > With respect to RC4 export strength was originally 40(!) bit. Right, because SSL originally had an exportable RC4 variant with 40-bit keys? I guess the meaning of "export strength RC4" is clear in the context of Kerberos, but ambiguous with respect to RC4 in general. I could change the title to "Deprecate DES, RC4-HMAC-EXP, and other weak cryptographic algorithms in Kerberos", along with a similar change to the Abstract. I could also add some disambiguating text to other occurrences of "export strength" to emphasize that it's a variant of RC4 that has 56-bit keys. _______________________________________________ ietf-krb-wg mailing list [email protected] https://lists.anl.gov/mailman/listinfo/ietf-krb-wg