logoalt Hacker News

fluoridationyesterday at 8:47 PM3 repliesview on HN

In that case just use CTR mode, no?


Replies

tptacekyesterday at 11:31 PM

https://www.cs.ucdavis.edu/~rogaway/papers/thorp.pdf

(Not that this is the only solution but that it motivates the problem of why you can't just naively apply AES to the problem).

201984yesterday at 10:15 PM

In the context of encrypting 32 or 64 bit IDs, where there is no nonce, that'd be equivalent to XOR encryption and much weaker than TFA's small block ciphers.

show 2 replies
Joker_vDyesterday at 9:00 PM

Some people just itch to use something custom and then to have to think about it. Which can bring amazing results, sure, but it can also bring spectacular disasters as well, especially when we're talking about crypto.

show 1 reply