note 5072 deleted from function.crypt by jimw

From: Date: Sat, 03 Nov 2001 18:16:26 +0000
Subject: note 5072 deleted from function.crypt by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-20365@lists.php.net to get a copy of this message
<p>Ah, I remembered something VERY important!!!</p> <p>NEVER, EVER, EVER use a simple XOR to encrypt data (except, MAYBE with a one-time pad in certain circumstances). If I have plaintext <code>x</code> and I <code>XOR</code> it with <code>y</code>, like so: <code>x XOR y = z</code>, then you know what? If some malicious guy, Mark, knows the plaintext, he can just do this: <code>z XOR x = y</code>. Now Mark knows your key. If he knows the key, he can get your plaintext: <code>y + z = x</code>. <p>Now, with symmetric ciphers like DES and Blowfish, if somebody knows your key, they can decrypt your data or encrypt it and pose as you. But it would be really difficult for someone to get your key if they knew the plaintext and the ciphertext. With XOR, somebody can get your key with the plaintext. NOT GOOD . . . perhaps unless it's a one-time pad (i.e., the key is as long as the plaintext (you don't have to repeat it), it's REALLY random, and you never use it again). <p>I'm not sure if the PHP encrypt uses a plain XOR cipher (in XOR mode), but it would be horrible if it did. <p>Just so you know. <p>Dean.

« previous php.notes (#20365) next »