Re: [PATCH] dm-crypt: disable block encryption with arc4

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



* Milan Broz | 2010-01-25 19:39:11 [+0100]:

>On 01/25/2010 07:29 PM, Mikulas Patocka wrote:
>> Hi
>> 
>> When using arc4 to encrypt a block device, the resulting device is 
>> unreliable. It reads garbage. That's because arc4 is a stream cipher, if 
>> you write something, it advances its state and if you attempt to decrypt 
>> the same sector, it uses new state that is different.
>> 
>> This patch disables the use of arc4 on block devices.
>
>arc4 again. it is simply not a block cipher:-)
>
>This should be solved inside cryptoAPI and not blacklist it in dm-crypt,
>see that thread
>http://article.gmane.org/gmane.linux.kernel.cryptoapi/3441

I some how remember Herbert saying to test for block size > 1. Wouldn't
this be acceptable to block all stream cipher in one go?

>Milan

Sebastian
--
To unsubscribe from this list: send the line "unsubscribe linux-crypto" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Kernel]     [Gnu Classpath]     [Gnu Crypto]     [DM Crypt]     [Netfilter]     [Bugtraq]

  Powered by Linux