<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Poll] What&#x27;s the best symmetric cipher? in Security</title>
<link>http://www.dslreports.com/forum/r5068418</link>
<description></description>
<language>en</language>
<pubDate>Thu, 03 Dec 2009 14:19:20 EDT</pubDate>
<lastBuildDate>Thu, 03 Dec 2009 14:19:20 EDT</lastBuildDate>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5122987</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> :  <BLOCKQUOTE><SMALL>said by  boomerbubba <A HREF="/useremail/u/411913"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>1) Is the security/insecurity of my suggestion purely a matter of the quality of the PRNG?  Or is it that there is no such thing as an acceptable PRNG for these purposes?<HR></BLOCKQUOTE><br>Well, the problem is that its still PRNG. It has to be. If it was RNG, then you couldnt agree upon it and you would have to change keys in beforehand (like true OTP). As it is PRNG, it can be cracked open. It is very, very hard to determine how secure PRNG is so its very hard to tell what kinda security it would give.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>2) If a good PRNG method does exist and is publicly known, what if the methodology is changed to:  Use that PRNG, and the secret symmetric key is the the seed value?<HR></BLOCKQUOTE><br>Still the same problem exists. Its PRNG. Something quite similiar to what you are saying is actually RC4 or C4 cipher used in SSL/TLS connections (https that is). It basicly a PRNG which output is XOR:ed to datastream. :)<br><br>Something related to this is Jaxor. Its encryption program that I have designed (it should be out...some time...). <br>&raquo;<A HREF="http://www.markusjansson.net/erecent.html#jaxor" >www.markusjansson.net/erecent.html#jaxor</A><br>"Basicly what we are talking here is using the one-way hash function to create pseudorandom keys which are then XOR:ed to datastream. The "master key" (passphrase) is salted using the just created ciphertext to make new keys. "<br><br>Its actually very secure cipher. The security of these kinda of ciphers relies on the security of the hash function, since the hash function is the source of PRNG data. If the hash function is good, then its practicly RNG. But not in theory. Very close to RNG but not RNG... :)<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>I'm not being argumentative.  Rather, I'm glad to have a forum where I can ask questions like this.  (I would be driven out of sci.crypt as a hopeless newbie.)<HR></BLOCKQUOTE><br>And Im glad that we can have this kinda discussion here! Im a bit tired to all these "help, Im under attack because someone hit my port 2222 with a packet" -discussion we see too often... ;) :)<br><SMALL>--<br>My computer security & privacy related homepage <br>&raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></SMALL><br><i>[text was edited by author 2002-11-25 14:14:53]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5122987</guid>
<pubDate>Mon, 25 Nov 2002 14:12:46 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5122497</link>
<description><![CDATA[<A HREF="/useremail/u/411913"><b>boomerbubba</b></A> :  <BLOCKQUOTE><SMALL>said by  jansson_mark <A HREF="/useremail/u/444625"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR> <BLOCKQUOTE><SMALL>said by  boomerbubba <A HREF="/useremail/u/411913"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>A One Time Pad, generated by some proprietary PRNG method known only to the parties involved in the communication.<HR></BLOCKQUOTE><br>It might be very secure or it might be very insecure. I would not advice on using such method.<br><HR></BLOCKQUOTE><br>Markus, a couple of follow-up questions:<br><br>1) Is the security/insecurity of my suggestion purely a matter of the quality of the PRNG?  Or is it that there is no such thing as an acceptable PRNG for these purposes?<br><br>2) If a good PRNG method does exist and is publicly known, what if the methodology is changed to:  Use that PRNG, and the secret symmetric key is the the seed value?<br><br>I'm not being argumentative.  Rather, I'm glad to have a forum where I can ask questions like this.  (I would be driven out of sci.crypt as a hopeless newbie.)<br><small>--<br>A good lock will keep an honest man out.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5122497</guid>
<pubDate>Mon, 25 Nov 2002 13:22:38 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5117709</link>
<description><![CDATA[<A HREF="/useremail/u/222765"><b>MeeToo7</b></A> : Ok, I see I went in over my head with you ;)<br><br>I'm obviously not as much into encryption as you are. I'm not using PGP or any encryption anymore, my knowledge is limited and haven't kept up with it.<br><br>Continue on ;)<br><small>--<br>Help find a cure, join <A HREF="http://www.dslreports.com/forum/folding">Team Helix</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5117709</guid>
<pubDate>Sun, 24 Nov 2002 21:45:37 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5117161</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> :  <BLOCKQUOTE><SMALL>said by  MeeToo7 <A HREF="/useremail/u/222765"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>You're poll question is misleading. Your categories are comparing apples and oranges.<HR></BLOCKQUOTE><br>No Im not. :)<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>First, AES is not an encryption algorith itself, but a name to be given to the best contenders of encryption, it stands for Advanced Encryption Standards.<HR></BLOCKQUOTE><br>Yes, I know. I thought about calling it Rijndael but since most people dont know what it is, I desided to use the AES term.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Second, Twofish is an evolution on Blowfish. It's been considered so good that it was encluded in PGP before AES was finalized.<HR></BLOCKQUOTE><br>And DES is an evolution of Lucifer. And MARS is a evolution of perhaps most of the other ciphers in the world today. They are still different ciphers. Besides, many people concider Blowfish better than Twofish, because Blowfish has longer track record.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Single DES is old news, it was cracked in a single day using an EFF machine. Don't know if 3DES has been cracked yet, but it seems pretty impossible to me, as it was said to take the time of the age of the universe to decipher, just a couple years ago.<HR></BLOCKQUOTE><br>When referring to 3DES, the DES is the algorithm. One could also ask do you prefer 3Skipjack or Skipjack...thats insane. The algorithm is still the same one.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>But the power of computers seem to advance at light speed to me.  I think this phenomenon is called Moore's Law? (The underestimation of computer power.)<HR></BLOCKQUOTE><br>True. However, there are much more efficient ways of breaking a modern cipher than brute forcing it.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>CAST, IDEA, 3DES and Twofish haven't been cracked yet to my knowledge. The preference is subjective.<HR></BLOCKQUOTE><br>Thats why we are having this poll. :) I would like people to tell about why they prefer some cipher and not some other.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> Some people don't like 3DES because it's based on DES, but well known experts hold it in high regards, from what I've read.<HR></BLOCKQUOTE><br>Not all experts. Finnish goverment computer security team  does not recommend or permit the usage of 3DES for encrypting sensitive material. However, they do permit for example CAST5-128. :)<br><small>--<br>My computer security & privacy related homepage + PGP keys &raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5117161</guid>
<pubDate>Sun, 24 Nov 2002 20:51:10 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116730</link>
<description><![CDATA[<A HREF="/useremail/u/222765"><b>MeeToo7</b></A> : You're poll question is misleading. Your categories are comparing apples and oranges.<br><br>First, AES is not an encryption algorith itself, but a name to be given to the best contenders of encryption, it stands for Advanced Encryption Standards. <br><br>Second, Twofish is an evolution on Blowfish. It's been considered so good that it was encluded in PGP before AES was finalized. <br><br>Single DES is old news, it was cracked in a single day using an EFF machine. Don't know if 3DES has been cracked yet, but it seems pretty impossible to me, as it was said to take the time of the age of the universe to decipher, just a couple years ago. But the power of computers seem to advance at light speed to me.  I think this phenomenon is called Moore's Law? (The underestimation of computer power.)<br><br>CAST, IDEA, 3DES and Twofish haven't been cracked yet to my knowledge. The preference is subjective. Some people don't like 3DES because it's based on DES, but well known experts hold it in high regards, from what I've read. <br><small>--<br>Help find a cure, join <A HREF="http://www.dslreports.com/forum/folding">Team Helix</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116730</guid>
<pubDate>Sun, 24 Nov 2002 20:12:37 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116696</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : No problem break it down.<br><br>They are the same, just like ZA and Kerio are both firewalls, that in ways work the same, but in other ways work differently.<br><small>--<br>TrojanHunter Stands For Privacy!!!!!!!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116696</guid>
<pubDate>Sun, 24 Nov 2002 20:09:04 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116651</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> :  <BLOCKQUOTE><SMALL>said by  Vampirefo <A HREF="/useremail/u/260736"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>Yes they are different in some ways but they are the same type of ciphers, very small differences.<HR></BLOCKQUOTE><br>Sorry to break this to you but, no, they are not at all the same type of ciphers. They are used on totally different things and the algorithms are totally different in nature. :)<br><small>--<br>My computer security & privacy related homepage + PGP keys &raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116651</guid>
<pubDate>Sun, 24 Nov 2002 20:05:17 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116539</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : I will "for for" for you TomMc.. then we only have to find one more for..and that would make free..sorry... three DES><br><small>--<br>GAV-Gladiator AntiVirus Forum-&raquo;<A HREF="http://www.forum.gladiator-antivirus.com/" >www.forum.gladiator-antivirus.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116539</guid>
<pubDate>Sun, 24 Nov 2002 19:56:21 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116354</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> :  <BLOCKQUOTE><SMALL>said by TomMc:</SMALL><HR>How can you not have Triple DES included? <HR></BLOCKQUOTE>Just for for DES three times :-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116354</guid>
<pubDate>Sun, 24 Nov 2002 19:33:18 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5116224</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : How can you not have Triple DES included?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5116224</guid>
<pubDate>Sun, 24 Nov 2002 19:17:57 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5115494</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : Yes they are different in some ways but they are the same type of ciphers, very small differences. <br><small>--<br>TrojanHunter Stands For Privacy!!!!!!!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5115494</guid>
<pubDate>Sun, 24 Nov 2002 17:51:16 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5115078</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> :  <BLOCKQUOTE><SMALL>said by  Vampirefo <A HREF="/useremail/u/260736"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>&raquo;<A HREF="/forum/remark,5068523~root=security,1~mode=flat">[Poll] What's the best asymmetric cipher?</A><br> <HR></BLOCKQUOTE>The current poll is for <B>symmetric</B> ciphers: the  referenced poll is for <B>asymmetric</B> ciphers. They're different.<br><br>Steve<br><small>--<br>Stephen J. Friedl • Security Consultant • Tustin, California USA • <A HREF="http://www.unixwiz.net">my web site</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5115078</guid>
<pubDate>Sun, 24 Nov 2002 17:06:55 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5114860</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : &raquo;<A HREF="/forum/remark,5068523~root=security,1~mode=flat">[Poll] What's the best asymmetric cipher?</A><br><small>--<br>TrojanHunter Stands For Privacy!!!!!!!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5114860</guid>
<pubDate>Sun, 24 Nov 2002 16:40:58 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5114817</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> :  <BLOCKQUOTE><SMALL>said by  boomerbubba <A HREF="/useremail/u/411913"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>A One Time Pad, generated by some proprietary PRNG method known only to the parties involved in the communication. <HR></BLOCKQUOTE>If it uses <U>pseudo-</U>random number generator, it's not a one-time pad. Plenty of ciphers have been broken by cracking the PRNG. Only truly random (e.g., not calculated in software) inputs are allowed, such as something that measures radioactive decay.<br><br>Steve<br><small>--<br>Stephen J. Friedl • Security Consultant • Tustin, California USA • <A HREF="http://www.unixwiz.net">my web site</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5114817</guid>
<pubDate>Sun, 24 Nov 2002 16:36:11 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5114206</link>
<description><![CDATA[<A HREF="/useremail/u/631880"><b>LowWaterMark</b></A> : I prefer one-way encryption.  No decrypt option.  That way, no one can ever figure out what it says.  It's a similar concept to WOM (write-only memory).<br><br>;)<br><small>--<br>Use the most powerful combo Firewall/AV/AT package available - "Common Sense" - It can be upgraded daily!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5114206</guid>
<pubDate>Sun, 24 Nov 2002 15:24:51 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5113869</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> :  <BLOCKQUOTE><SMALL>said by  boomerbubba <A HREF="/useremail/u/411913"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>A One Time Pad, generated by some proprietary PRNG method known only to the parties involved in the communication.<HR></BLOCKQUOTE><br>It might be very secure or it might be very insecure. I would not advice on using such method.<br><br>But our military messaging system (SanLa) uses encryption somewhat similiar than that. It uses symmetric cipher(s) and "matrix" to encrypt. First the message is encrypted using symmetric ciphers and then that mess is encrypted using "matrix" similiar to that you descibed here. Without knowing the exact nature of the "matrix", its a pain in the *** to try to break it, since the message is already a mess before its putted throught the "matrix", so in practice you cant know when you have managed to "break" the "matrix" so you could start trying to break the symmetric cipher(s). :) Hehehehehee...<br><br>btw. did you know that the only cipher that "anti-Allieds" side used that wasnt broken during the WWII, was Finnish cipher? It was called "worm box" and was used until 1980:s. :)<br><small>--<br>My privacy related homepage & PGP keys:&raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5113869</guid>
<pubDate>Sun, 24 Nov 2002 14:50:22 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5070229</link>
<description><![CDATA[<A HREF="/useremail/u/411913"><b>boomerbubba</b></A> : A One Time Pad, generated by some proprietary PRNG method known only to the parties involved in the communication.<br><small>--<br>A good lock will keep an honest man out.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5070229</guid>
<pubDate>Wed, 20 Nov 2002 01:37:04 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5069989</link>
<description><![CDATA[<A HREF="/useremail/u/520562"><b>Lithp</b></A> : twofish]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5069989</guid>
<pubDate>Wed, 20 Nov 2002 01:03:36 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5068712</link>
<description><![CDATA[<A HREF="/useremail/u/151802"><b>jaykaykay</b></A> : Ah!  Good bedside reading.  :)  Thank you.  I am not certain I will understand all that you've given me, but I shall make a good stab at it.  <br><br>As far liking something NSA made, that's good thinking.  Your point 2 says it all and quite well.<br><small>--<br>JKK:-)Age is a very high price to pay for my maturity. If I can't stay young, I can at least stay immature!  </small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5068712</guid>
<pubDate>Tue, 19 Nov 2002 22:57:54 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5068593</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> : My favorite is Skipjack. Why?<br>1) It was made by the NSA<br>2) They know how to crack codes and they know how to make them.<br>3) They didnt believe it would be published in open<br><br>Only downside is relatively small keysize (80bits), but if you would implement it like Skipjack -> 3Skipjack (like DES -> 3DES) then... :) :) :)<br><small>--<br>My privacy related homepage & PGP keys:&raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5068593</guid>
<pubDate>Tue, 19 Nov 2002 22:48:27 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5068562</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> :  <BLOCKQUOTE><SMALL>said by  jaykaykay <A HREF="/useremail/u/151802"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>I couldn't begin to answer that.  First I would have to have a description of what a Symmetric Cipher is.  :) <HR></BLOCKQUOTE>:) &raquo;<A HREF="http://www.ssh.com/support/cryptography/introduction/algorithms.html" >www.ssh.com/support/cryptography&middot;&middot;&middot;hms.html</A> :)<br>"There are two classes of key-based encryption algorithms, symmetric (or secret-key) and asymmetric (or public-key) algorithms. The difference is that symmetric algorithms use the same key for encryption and decryption (or the decryption key is easily derived from the encryption key), whereas asymmetric algorithms use a different key for encryption and decryption, and the decryption key cannot be derived from the encryption key."<br><br>&raquo;<A HREF="http://www.mccune.cc/PGPpage2.htm#128bit" >www.mccune.cc/PGPpage2.htm#128bit</A><br>"Since PGP uses public keys so much larger than this, it is easy to become confused when we hear the "reality" of PGP being "only" 128 bit encryption. To understand this, it is necessary to know that PGP uses both symmetric algorithms (IDEA, CAST, or Triple DES; Twofish is an additional option in PGP 7.0, and AES is still an additional option in 7.0.1) and asymmetric algorithms (RSA or DH). The process is the same regardless of the algorithms used, so my explanation will simplify it by referring only to the traditional use of IDEA and RSA. IDEA is a thousand (or more) times faster than RSA, but cannot be used for encrypting a file/message to one key, and then decrypting that file/message to a different matching key (public key encryption, which RSA can do). So, PGP speeds up the whole process by first encrypting the file or message to IDEA, using a randomly generated "session key" (an IDEA key used just for that one instance of encryption). That randomly generated session key is then encrypted to the recipient's public key(s), and packaged along with the IDEA encrypted file/message. The recipient(s) then uses his/her private key to decrypt the session key, which is then used to decrypt the file/message. In addition to tremendously speeding everything up, this use of underlying symmetric encryption to a randomly generated session key, improves the overall security of PGP - and also helps explain why the same file/message encrypted to the same public key always looks different (a different session key was used). These underlying symmetric algorithms are believed to be best broken by a brute force attack of trying all possible keys, which is considered impossible to do because of the sheer number of keys to try - each additional bit doubles the number of keys that would have to be tried, so that a 57 bit algorithm would have twice the number of possible keys as a 56 bit algorithm. The asymmetric RSA algorithm is believed to be best broken by mathematical factoring. It is believed that a 3000* bit RSA asymmetric key would require as much time and effort to factor, as the time and effort to do a brute force attack on 128 bit IDEA.  These key size comparisons are considered roughly comparable for the other algorithms used in PGP (except that 256 bit Twofish and AES compare to a 15000 bit DH or RSA key) - so if you want the highest possible level of security in PGP, you should use an RSA or DH key at least as large as 3000 bits."<br><br>Also, check from<br>&raquo;<A HREF="http://www.pgpi.org/doc/pgpintro/" >www.pgpi.org/doc/pgpintro/</A><br>&raquo;<A HREF="http://senderek.de/security/secret-key.protection.html#methods" >senderek.de/security/secret-key.&middot;&middot;&middot;methods</A><br><br><SMALL>--<br>My privacy related homepage & PGP keys:<br>&raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A></SMALL><br><i>[text was edited by author 2002-11-19 22:55:23]</i>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5068562</guid>
<pubDate>Tue, 19 Nov 2002 22:44:21 EDT</pubDate>
</item>

<item>
<title>Re: [Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5068531</link>
<description><![CDATA[<A HREF="/useremail/u/151802"><b>jaykaykay</b></A> : I couldn't begin to answer that.  First I would have to have a description of what a Symmetric Cipher is.  :)  Yes, I have a general idea, but I would love your explanation so that I and so many others that still need to learn get some good education.<br><small>--<br>JKK:-)Age is a very high price to pay for my maturity. If I can't stay young, I can at least stay immature!  </small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5068531</guid>
<pubDate>Tue, 19 Nov 2002 22:39:26 EDT</pubDate>
</item>

<item>
<title>[Poll] What&#x27;s the best symmetric cipher?</title>
<link>http://www.dslreports.com/forum/remark,5068418</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> : [poll]What do you think is the best cipher currently known in the public? (forget the keysize issue),AES,DES,Skipjack,Twofish,Blowfish,MARS,CAST,IDEA,RC4,RC6,GOST,SAFER,SERPENT,somethi  ng else?[/poll]<br><i>[text was edited by author 2002-11-19 22:30:50]</i><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,5068418</guid>
<pubDate>Tue, 19 Nov 2002 22:29:19 EDT</pubDate>
</item>

</channel>
</rss>
