From: Edward Shushkin <edward@namesys.com>
To: reiserfs-list@namesys.com
Subject: Re: Proposal for keying encrypted filesystem
Date: Mon, 31 Mar 2003 16:09:48 +0400 [thread overview]
Message-ID: <3E88300C.22B54FD7@namesys.com> (raw)
In-Reply-To: 3E8824B4.55C63A55@namesys.com
Edward Shushkin wrote:
>
> Pierre Abbat wrote:
> >
> > On Saturday 29 March 2003 13:17, Edward Shushkin wrote:
> > > Any collision can be used by attacker for access to remained decrypted data
> > > in memory, so you should assign the *whole* output of any crypto-stable
> > > hash function (20 bytes for SHA1). If you use 19 bytes for ID, there is no
> > > any guarantee that someone can not find a collision easy.
> > > Edward.
> >
> > There isn't any guarantee with all 20 either,
>
> Yes of course, but with all the 20 bytes I have a guarantee of SHA1 stability
> announced in appropriate papers, and I do have nothing for 19 bytes..
So from this standpoint I would rather prefer 16-byte ID created by full-grade md5,
then 19-byte ID created by restricted SHA1. Maybe this standpoint is too conservative,
but this is right..
>
> it's just 256 times as hard to
> > find one and practically impossible. What about using the MD5 of the
> > passphrase for the key ID, and the SHA1 of the passphrase for the key?
>
> Each secret key must be generated by special method which is specific for
> the used crypto algorithm, I think such methods are already exists, so we
> don't need to invent something new..
>
> Edward.
>
> >
> > phma
> > --
> > .i toljundi do .ibabo mi'afra tu'a do
> > .ibabo damba do .ibabo do jinga
> > .icu'u la ma'atman.
next prev parent reply other threads:[~2003-03-31 12:09 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-03-29 1:26 Proposal for keying encrypted filesystem Pierre Abbat
2003-03-29 16:46 ` Edward Shushkin
2003-03-29 16:55 ` Pierre Abbat
2003-03-29 18:17 ` Edward Shushkin
2003-03-29 20:49 ` Pierre Abbat
2003-03-30 10:12 ` Hendrik Visage
2003-03-30 17:00 ` Pierre Abbat
2003-03-31 9:15 ` Hendrik Visage
2003-03-30 16:30 ` Pierre Abbat
2003-03-31 11:21 ` Edward Shushkin
2003-03-31 12:09 ` Edward Shushkin [this message]
2003-03-31 13:36 ` Hendrik Visage
2003-03-31 13:54 ` Pierre Abbat
2003-03-31 16:35 ` Hendrik Visage
2003-03-31 20:11 ` Pierre Abbat
2003-03-31 21:31 ` Hendrik Visage
2003-03-31 22:40 ` Pierre Abbat
2003-04-01 9:31 ` Hendrik Visage
2003-03-31 13:58 ` Edward Shushkin
2003-03-31 16:45 ` Hendrik Visage
2003-04-01 12:28 ` Edward Shushkin
2003-04-01 16:06 ` Hans Reiser
2003-04-01 16:16 ` Anders Widman
2003-04-01 16:21 ` Hans Reiser
2003-04-02 2:56 ` Pierre Abbat
2003-04-02 6:06 ` Hans Reiser
2003-04-02 13:05 ` Pierre Abbat
2003-04-02 15:11 ` Edward Shushkin
2003-04-03 16:14 ` Valdis.Kletnieks
2003-04-03 19:43 ` Hans Reiser
2003-04-03 20:08 ` Valdis.Kletnieks
2003-04-03 19:44 ` Hans Reiser
2003-04-03 23:22 ` Pierre Abbat
2003-04-04 0:25 ` Russell Coker
2003-04-04 14:01 ` Valdis.Kletnieks
2003-04-04 14:30 ` Pierre Abbat
2003-04-04 14:47 ` Valdis.Kletnieks
2003-04-04 14:57 ` Pierre Abbat
2003-04-04 16:36 ` Edward Shushkin
2003-04-04 16:45 ` Valdis.Kletnieks
2003-04-04 15:25 ` Edward Shushkin
2003-04-04 16:50 ` Hans Reiser
2003-04-04 17:19 ` Edward Shushkin
2003-04-04 18:45 ` Hans Reiser
2003-04-05 0:01 ` Pierre Abbat
2003-04-07 0:44 ` Valdis.Kletnieks
2003-04-07 1:14 ` Pierre Abbat
2003-04-07 4:52 ` Valdis.Kletnieks
2003-04-07 16:55 ` Hans Reiser
2003-04-07 18:38 ` Edward Shushkin
2003-04-07 19:46 ` Hans Reiser
2003-04-07 22:36 ` Pierre Abbat
2003-04-08 10:10 ` Edward Shushkin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3E88300C.22B54FD7@namesys.com \
--to=edward@namesys.com \
--cc=reiserfs-list@namesys.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.