Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A world full of brilliant cryptographers outraged at the NSA, trying to get the NSA off the IETF crypto review board, working on publishing results about NSA-sponsored crypto... and you want to talk about the MD2 and RC2 constants? What's the largest system that ever relied on MD2? Let's start there.


There were certificates (including a root CA) using MD2 until recently. MD2 itself was only retired in 2011 [1].

https://www.rfc-editor.org/rfc/rfc6149.txt


You are obviously right. Now I feel dumb. I concede the importance of MD2.

Do you believe that the starting state for MD2 is a possible backdoor?

Later: I'm batting .000 today on this stuff; it's not the starting state of MD2 that he's talking about, of course, and the misapprehension that he was is part of why I was dismissive. Go me.


It seems your edit did all the work for me. Being in the core of the MD2 compression function puts the Sbox in a good place to be a backdoor.

However I strongly doubt this is one. The attacks that have broken MD2 do not seem to hinge terribly on the Sbox (I may be wrong, it was only a cursory look). It's more likely to me that the Sbox was generated using a hard-to-replicate Knuth shuffle using the digits of Pi.


"were"


i know you have the intellectual curiousity of a sausage, but some of us are simply interested. we don't all need to be motivated by logic.

how would you derive it? tagging pairs of hex digits and sorting doesn't cut it. would rivest have used a hack that's a biased shuffle? i doubt it.

and downvotes. happy xmas!


You're right. I was snippy, and in a particularly dumb way. Sorry about that.


But happy to admit it in a reasonable way. A responsible disclosure of errors if you will.


eh, no need to apologise. i think we're used to you here and there's a level of tolerance given the contributions you make.

also, did you see http://www.jakoblell.com/blog/2013/12/22/practical-malleabil... which i think could be added to an early crypto challenge? (but maybe you already cover the idea).


CBC bitflipping is in set #2. Incidentally, somewhere in the mists of time is a very weird blog post ("If You're Typing The Letters A-E-S Into Your Code, You're Doing It Wrong") I wrote describing how to implement this attack --- though not against LUKS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: