Adding a nounce before hashing as covert channel

Werner Koch wk at gnupg.org
Thu Dec 12 12:15:03 CET 2024


On Wed, 11 Dec 2024 22:39, Jacob Bachmeyer said:

> The problem is that strong algorithms *become* weak without advance
> warning.  Therefore, it is necessary to take measures to reduce the

But we don't know in which way they become weak.  You can't exclude that
a new weakness is leveraged by the extra random salt [1].


Salam-Shalom,

   Werner



[1] We are talking about a salt and not a nonce (number-used-once).

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 247 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20241212/d8fe2e75/attachment.sig>


More information about the Gnupg-devel mailing list