From: "Guillaume Lacôte" <Guillaume@Lacote.name>
To: "Jörn Engel" <joern@wohnheim.fh-wedel.de>
Cc: linux-kernel@vger.kernel.org, Linux@glacote.com
Subject: Re: Using compression before encryption in device-mapper
Date: Fri, 23 Apr 2004 17:16:53 +0200 [thread overview]
Message-ID: <200404231716.53481.Guillaume@Lacote.name> (raw)
In-Reply-To: <20040422160033.GB23746@wohnheim.fh-wedel.de>
Feel free to ignore all of my reply; please note that I am not trying to "be
right" or to "be wrong" but I still do not understand ... Thank you still for
your time and pedagogy.
> Yeah, sure, the attacker has no idea what the plaintext of those
> blocks is, but if they appear often enough, it has to be something
> quite common. Something like, say, all ones or all zeros. Or like
> one of those 48 common huffman encodings thereof.
> [...]
> So what! You end up with maybe three bits per zero (assuming all
> zeros). Depending on the size of random data up front, they start
> with bit 1, 2 or 3. Makes 3*2^3 or 24 possibilities. Same for all
> ones, give a total of 48. Great, a dictionary attack is 48x slower
> now!
> [...]
> Still, towards the end of all-ones or all-zeros, each byte will be
> encoded with the same 1-3bit value.
The point I fail to understand is the following : you know the enciphered
value of these 1-3bits. But how can you know what is
compressed-but-deciphered 1-3bit value ? Ok my text contains only 0s. OK
these 0s appear to be "011" once encrypted. How do you launch your
dictionnary attack ? You do _not_ (?) know what the 3bit deciphered code for
"0" is. Or maybe you do ?
> [...]
> In that case, what's your point. If the key is strong and the
> encryption is strong (I sure hope, AES is), nothing short of brute
> force can be successful. What are you protecting against?
Maybe my "endless" story is absurd, but I am _not_ protecting against weak
keys; I am trying to protected against weak _data_ , which is the basis for
dictionnary attacks even in the case of perfectly random keys.
Thank you for having read till here,
Guillaume.
next prev parent reply other threads:[~2004-04-23 15:17 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-13 15:44 Guillaume Lacôte
2004-04-13 16:57 ` Timothy Miller
2004-04-14 6:48 ` Guillaume Lacôte
2004-04-13 17:45 ` Jörn Engel
2004-04-13 19:42 ` Ville Herva
2004-04-14 6:54 ` Guillaume Lacôte
2004-04-14 9:43 ` Jörn Engel
2004-04-14 10:02 ` Guillaume Lacôte
2004-04-14 11:25 ` Jörn Engel
2004-04-14 12:44 ` Paulo Marques
2004-04-14 13:34 ` Jörn Engel
2004-04-14 13:58 ` maccorin
2004-04-14 14:02 ` Guillaume Lacôte
2004-04-14 14:39 ` Grzegorz Kulewski
2004-04-14 15:07 ` Guillaume Lacôte
2004-04-14 16:14 ` Grzegorz Kulewski
2004-04-14 15:23 ` Paulo Marques
2004-04-14 15:32 ` Guillaume Lacôte
2004-04-14 17:25 ` Bill Davidsen
2004-04-15 9:28 ` Jörn Engel
2004-04-22 7:59 ` Guillaume Lacôte
2004-04-22 9:18 ` Jörn Engel
2004-04-22 10:20 ` Guillaume Lacôte
2004-04-22 12:15 ` Jörn Engel
2004-04-22 13:06 ` Guillaume Lacôte
2004-04-22 16:00 ` Jörn Engel
2004-04-23 15:16 ` Guillaume Lacôte [this message]
2004-04-23 16:57 ` Jörn Engel
[not found] <1KykU-4VD-17@gated-at.bofh.it>
[not found] ` <1KPvh-26S-7@gated-at.bofh.it>
[not found] ` <1KSMw-4P1-13@gated-at.bofh.it>
[not found] ` <1KTfJ-5gK-25@gated-at.bofh.it>
2004-04-14 15:02 ` Pascal Schmidt
2004-04-14 15:25 ` Guillaume Lacôte
2004-04-14 19:29 ` Pascal Schmidt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200404231716.53481.Guillaume@Lacote.name \
--to=guillaume@lacote.name \
--cc=Linux@glacote.com \
--cc=joern@wohnheim.fh-wedel.de \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®