Bill Frantz (frantz@netcom.com)
Wed, 17 Jun 1998 09:56:22 -0800
At 4:01 AM -0800 6/17/98, Victor Emanuel Luz wrote:
>Hi.
>
> I've been trying to use a Blowfish Java implementation by Markus Hahn
>( http://www-hze.rz.fht-esslingen.de/~tis5maha/software.html ) to
>encrypt a small amount of data (less than 256 bytes) whith a 80 bit
>secret key.
> The communication is made from a Applet to a Servlet using simmetric
>encryptation.
> The info that I am trying to encrypt has a valid time of about two
>monthes and it is _not_ too sesitive.
>
>Problem:
>
> Even devius stealth methods are quite simple do declassify the applet
>and gain access to the secret key or function to generate key see
>http://www.awesome.com/declass.html (it's free!) for details.
>
> Does anyone has some clue on how to defeat this ?
Generate the secret key through a Diffie-Hellman key exchange.
-------------------------------------------------------------------------
Bill Frantz | If hate must be my prison | Periwinkle -- Consulting
(408)356-8506 | lock, then love must be | 16345 Englewood Ave.
frantz@netcom.com | the key. - Phil Ochs | Los Gatos, CA 95032, USA
The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:18:36 ADT