Re: encryption decryption without mcrypt?

From: Date: Thu, 24 Aug 2000 20:25:15 +0000
Subject: Re: encryption decryption without mcrypt?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-13515@lists.php.net to get a copy of this message
And just to reiterate Dean's point. The numbers used to generate the pad must be truly random. Really. Otherwise your security begins and ends with how good your random number generator is...the usual answer being, not very. So you end up being not much better off than Rot13ing it. Use a real encryption algorhytm if you are serious about it at all. Brian Huddleston Huddleston Consulting ----- Original Message ----- From: "Dean Hall" <hall@apt7.com> To: "Lewis Bergman" <lbergman@abi.tconline.net> Cc: <php-general@lists.php.net> Sent: Thursday, August 24, 2000 3:09 PM Subject: Re: [PHP] encryption decryption without mcrypt? > > $onetimepad = OneTimePadCreate(strlen($secretkey)); > > $key = OneTimePadEncrypt($secretkey, $onetimepad); > > session_register("onetimepad"); > > That's all fine and dandy if all you need is a one-time pad. But one-time > pads are only good once -- by definition, a one-time pad must be *truly* > random, the same exact length as the plaintext, and only used once. If it > doesn't meet any of these qualifications, it's not a one-time pad and is > *not* good for encryption. > > But, if you do need a one-time pad, it's unbreakable. :-) Really! > > Dean. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#13515) next »