Xcott Craver (caj@math.niu.edu)
Tue, 21 Jul 1998 12:44:27 -0500 (CDT)
On Tue, 21 Jul 1998, Robert Hettinga wrote:
> After all, folks, snake oil a *business* concept. They don't call it
> "selling snake-oil" for nothing, right? I mean, nobody *gives* away snake
> oil, they try to *sell* it.
False. Ever hang around sci.crypt recently? Lotta free
snake-oil, perhaps never to be sold commercially, given out
by none-too-bright folks convinced that they are crypto
HEROES for implementing their divine wisdom. They don't want
money, just immortality.
> And so, from a *business* standpoint, DES is now snake oil, pure and
> simple.
You seem to be confusing the cipher itself with software
products which do not adequately implement it. You also
don't seem to realize that 3DES _is_ DES, the cipher,
adequately implemented.
Anyone will agree with you that the keyspace of DES is
way too small. But I simply can't imagine going before an
audience of cryptographers, say at a conference, and declaring
DES snake-oil. Depending on whose definition you use, this
is tantamount to calling DES's designers ignorant frauds.
,oooooooo8 o ooooo@math.niu.edu -- http://www.math.niu.edu/~caj/
o888' `88 ,888. 888
888 ,8'`88. 888 "The user's going to pick dancing pigs
888o. ,oo ,8oooo88. 888 over security every time."
`888oooo88 o88o o888o 888 -Bruce Schneier
____________________8o888'_________________________________________________
The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:20:45 ADT