← Home ← Back to /g/

Thread 106355405

14 posts 8 images /g/
Anonymous No.106355405 >>106355435 >>106355446 >>106355484 >>106355484 >>106356487 >>106356904
is Kuznyechik(Serpent(Camellia)) enough or should I combine it with AES(Twofish) too?
Anonymous No.106355435 >>106355477
>>106355405 (OP)
Is AES-256 not enough for you mad cunt?
Anonymous No.106355446
>>106355405 (OP)
Blowfish + SHA-2 512.
Anonymous No.106355477 >>106355504
>>106355435
what if it's broken / backdoored?
Anonymous No.106355484 >>106356462
>>106355405 (OP)
>>106355405 (OP)
Kuznyechik is interesting. It is suspected by some to have a backdoor. For instance, Botan (crypto library used in KeePassXC) documentation sums it up:

>The sbox of this cipher is supposedly random, but was found to have a mathematical structure which is exceedingly unlikely to have occurred by chance. This may indicate the existence of a backdoor or other issue. Avoid using this cipher unless strictly required.

But the Veracrypt dev stated his reasoning for keeping the Kuznyechik cipher in Veracrypt:

>This leads me to think that maybe there is another interesting possibility: the designer of Streebog and Kuznyechic are aware of new type of algebraic attacks affecting modern ciphers and hash functions and they wanted to ensure that these algorithms are immune against this attack without revealing anything about the attacks they are protecting against!

He goes on to state the same thing happened with DES.

https://github.com/veracrypt/VeraCrypt/issues/419

He removed SM4, the Chinese national cipher, I think because he considered it insecure.

As for your question OP, AES is probably fine. It's been looked at more than any other cipher.
Anonymous No.106355504
>>106355477
If someone found a practical backdoor, it would be worth billions (not just millions) to governments and corporations, because the entire global economy depends on it (TLS, VPNs, disk encryption, etc.). If thereโ€™s a backdoor, whoever has it is sitting on the most valuable secret in the world. Cascades (AES+Twofish, Kuznyechik+Serpent, etc.) are fine for peace of mind, but practically, youโ€™re far more likely to get compromised through side channels, poor opsec, or metadata than through AES itself.
Anonymous No.106356462
>>106355484
we need Kuznyechik(AES(Camellia))
Anonymous No.106356487 >>106356535
>>106355405 (OP)
That should be plenty for anyone.
Anonymous No.106356535
>>106356487
>derailing the thread with race-bait nonsense
Anonymous No.106356721
twofish should have won
Anonymous No.106356836 >>106357664
stop downloading child pornography
Anonymous No.106356904 >>106357044
>>106355405 (OP)
Why are you still using a block cipher?
Anonymous No.106357044
>>106356904
don't stream ciphers have a different usecase?
Anonymous No.106357664
>>106356836
>only usecase for strong encryption is 'p