Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Debian OpenSSL critical security bug
- Date: Wed, 14 May 2008 10:56:06 +0900
- From: Curt Sampson <cjs@example.com>
- Subject: Re: [tlug] Debian OpenSSL critical security bug
- References: <4fefd6340805131436p641e9605k84954b75accb8e2e@mail.gmail.com> <d8fcc0800805131552g4d1d0324me48d16a82980af33@mail.gmail.com> <20080513232752.GD3781@pragmatic.cynic.net> <d8fcc0800805131803k45e85a95h48569f1bd58516da@mail.gmail.com>
- User-agent: Mutt/1.5.17 (2007-11-01)
On 2008-05-14 10:03 +0900 (Wed), Josh Glover wrote: > 2008/5/14 Curt Sampson <cjs@example.com>: > > > remember the story > > about the NSA's changes to the S-box arrangement of the DES algorithm. > > I don't, but it sounds interesting. Have you a link? Oh, and a small summary, since the Wikipedia page is not all that clear, IMHO: The algorithm used an arrangement of these things called "S-boxes", which were not well understood. To most outside reviewers at the time, one arrangement seemed as good as another. The story I heard is that the NSA, after reviewing the original DES algorithm, asked for one small change in the S-box arrangement before approving it for government use. They wouldn't say why they'd done this. This raised a lot of suspicious; had they changed it to make it easier for them to crack? Many years later, when techniques of differential analysis were discovered by the public community, it turned out that that small change had made DES far more resistant to these techniques than the original version had been, and thus far stronger. cjs -- Curt Sampson <cjs@example.com> +81 90 7737 2974 Mobile sites and software consulting: http://www.starling-software.com
- References:
- [tlug] Debian OpenSSL critical security bug
- From: Gernot Hassenpflug
- Re: [tlug] Debian OpenSSL critical security bug
- From: Josh Glover
- Re: [tlug] Debian OpenSSL critical security bug
- From: Curt Sampson
- Re: [tlug] Debian OpenSSL critical security bug
- From: Josh Glover
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Debian OpenSSL critical security bug
- Next by Date: Re: [tlug] [off topic] religion and the internet in Japan
- Previous by thread: Re: [tlug] Debian OpenSSL critical security bug
- Next by thread: Re: [tlug] Debian OpenSSL critical security bug
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links