note 5072 deleted from function.crypt by jimw
| From: | jimw@php.net | Date: | Sat, 03 Nov 2001 18:16:26 +0000 |
| Subject: | note 5072 deleted from function.crypt by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-20365@lists.php.net to get a copy of this message | ||
<p>Ah, I remembered something VERY important!!!</p>
<p>NEVER, EVER, EVER use a simple XOR to encrypt data (except, MAYBE with a one-time pad in
certain circumstances). If I have plaintext <code>x</code> and I
<code>XOR</code> it with <code>y</code>, like so: <code>x XOR y =
z</code>, then you know what? If some malicious guy, Mark, knows the plaintext, he can just do
this: <code>z XOR x = y</code>. Now Mark knows your key. If he knows the key, he can get
your plaintext: <code>y + z = x</code>.
<p>Now, with symmetric ciphers like DES and Blowfish, if somebody knows your key, they can
decrypt your data or encrypt it and pose as you. But it would be really difficult for someone to get
your key if they knew the plaintext and the ciphertext. With XOR, somebody can get your key with the
plaintext. NOT GOOD . . . perhaps unless it's a one-time pad (i.e., the key is as long as the
plaintext (you don't have to repeat it), it's REALLY random, and you never use it again).
<p>I'm not sure if the PHP encrypt uses a plain XOR cipher (in XOR mode), but it would be
horrible if it did.
<p>Just so you know.
<p>Dean.