Re: encryption decryption without mcrypt?
| From: | Brian Huddleston | Date: | Thu, 24 Aug 2000 20:25:15 +0000 |
| Subject: | Re: encryption decryption without mcrypt? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-13515@lists.php.net to get a copy of this message | ||
And just to reiterate Dean's point. The numbers used to generate the pad
must be truly random. Really.
Otherwise your security begins and ends with how good your random number
generator is...the usual answer
being, not very. So you end up being not much better off than Rot13ing it.
Use a real encryption algorhytm if you are serious about it at all.
Brian Huddleston
Huddleston Consulting
----- Original Message -----
From: "Dean Hall" <hall@apt7.com>
To: "Lewis Bergman" <lbergman@abi.tconline.net>
Cc: <php-general@lists.php.net>
Sent: Thursday, August 24, 2000 3:09 PM
Subject: Re: [PHP] encryption decryption without mcrypt?
> > $onetimepad = OneTimePadCreate(strlen($secretkey));
> > $key = OneTimePadEncrypt($secretkey, $onetimepad);
> > session_register("onetimepad");
>
> That's all fine and dandy if all you need is a one-time pad. But one-time
> pads are only good once -- by definition, a one-time pad must be *truly*
> random, the same exact length as the plaintext, and only used once. If it
> doesn't meet any of these qualifications, it's not a one-time pad and is
> *not* good for encryption.
>
> But, if you do need a one-time pad, it's unbreakable. :-) Really!
>
> Dean.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>