Re: Allegations regarding OpenBSD IPSEC

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Ted Unangst
Date: Tuesday, December 21, 2010 - 2:17 pm

On Tue, Dec 21, 2010 at 4:00 PM, Joachim Schipper
<joachim@joachimschipper.nl> wrote:

The attacker either knows nanotime or they don't.  If they know it,
they know md5(nanotime) as well.

RC4 is weak sauce and leaks its key in the beginning, but we avoid
that by discarding, so there's no way to tell what the initial state
is except by guessing.  And guessing md5(whatever) is no harder than
guessing whatever.

The md5 step would only be helpful if the initial key to rc4 were then
also used to something *else*, meaning it had some value apart from
being the key.  But it doesn't.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Allegations regarding OpenBSD IPSEC, Theo de Raadt, (Tue Dec 21, 1:33 pm)
Re: Allegations regarding OpenBSD IPSEC, Joachim Schipper, (Tue Dec 21, 2:00 pm)
Re: Allegations regarding OpenBSD IPSEC, Kjell Wooding, (Tue Dec 21, 2:13 pm)
Re: Allegations regarding OpenBSD IPSEC, Bob Beck, (Tue Dec 21, 2:15 pm)
Re: Allegations regarding OpenBSD IPSEC, Ted Unangst, (Tue Dec 21, 2:17 pm)
Re: Allegations regarding OpenBSD IPSEC, Joachim Schipper, (Tue Dec 21, 2:19 pm)