in reply to Re: Safely Transferring Information on the Internet
in thread Safely Transferring Information on the Internet

DES is considered laughable these days. You could probably find many programs that could brute force DES on a common PC in a respectable time.

Look at PGP/GPG for easy public key encryption or consider symmetrical ciphers such as IDEA or Blowfish, any of the leading AES contenders - not just Rijndael - or something like RC5.

There are plenty of good ciphers out there, DES should near the bottom of the list, just below Crypt::Rot26 (jeffa++ :-)

Cheers.

BazB

  • Comment on Re: Re: Safely Transferring Information on the Internet

Replies are listed 'Best First'.
Re: Re: Re: Safely Transferring Information on the Internet
by abell (Chaplain) on Aug 07, 2002 at 22:45 UTC
    DES is considered laughable these days. You could probably find many programs that could brute force DES on a common PC in a respectable time.

    You are right. I forgot to mention that the triple DES version should be used, which basically consists of three repetitions of DES with three different keys. It is significantly more secure than DES. Incidentally, the link I suggested has an implementation of both.
    Of course, the choice of this or any other algorithm (like the ones BazB suggests) should be done according to a number of technical considerations (security constraints, algorithm efficiency, existence of ready-made implementations, etc.).

    Best regards

    Antonio Bellezza
      "I forgot to mention that the triple DES version should be used, which basically consists of three repetitions of DES with three different keys"

      Not quite right, it does use 3 different keys, but it performs:
    • DES Encrypt with Key 1
    • DES Decrypt with Key 2
    • and finally DES Encrypt with Key 3.
      So it is a little trickier than reapeated DES :)

      "Nothing is sure but death and taxes" I say combine the two and its death to all taxes!