[76588] in cryptography@c2.net mail archive
Re: It's a Presidential Mandate, Feds use it. How come you are not using FDE?
daemon@ATHENA.MIT.EDU (Saqib Ali)
Thu Jan 18 15:03:28 2007
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Thu, 18 Jan 2007 08:50:48 -0800
From: "Saqib Ali" <docbook.xml@gmail.com>
To: "Jonathan Thornburg" <jthorn@aei.mpg.de>
Cc: cryptography@metzdowd.com
In-Reply-To: <Pine.LNX.4.63.0701181214000.14073@xeon44.aei.mpg.de>
Since when did AES-128 become "snake-oil crypto"? How come I missed
that? Compusec uses AES-128 . And as far as I know AES is NOT
"snake-oil crypto"
Closed-source doesn't mean that it is "snake-oil". If that was the
case, the Microsoft's EFS, and Kerberos implementation would be "snake
oil" too.
I think you are mistaken on the definition of "snake-oil crypto".
Snake-oil crypto refers to "New mathematics", "Proprietary
cryptography", and "Pseudo-mathematical gobbledygook"....
Please see the following URL for more into on snake-oil crypto:
http://www.schneier.com/crypto-gram-9902.html#snakeoil
saqib
http://www.full-disk-encryption.net
> If I have data that's valuable enough to need encryption, I'm going
> to be nervous trusting it to closed-source software. How do I know
> that Compusec's cryto is done properly? As Bruce Schneier has
> famously said, to the user snake-oil crypto looks just like good
> crypto -- both scramble the bits enough to look "random" to the eye.
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com