You realize a few methods rely on generating and exchanging a
symmetric key in an initial step encrypted by asymmetric keys?
Just think of what could happen when one of both parties "looses"
their symetric key ? And just assume that they do not realise
that it has happened.
Nuno,
You realize a few methods rely on generating and exchanging a
symmetric key in an initial step encrypted by asymmetric keys?
That would solve the problem related to exchanging(?) a symmetric key.
But than why use symmetric keys when you already have something that generates and works with a-symmetric ones ? Thats twice the work, with no benefit.
Gab,
Why though? There is no magical vulnerability in symmetric
encryption.
You're correct, there is nothing magical about it.
Asymmetric encryption solves key distribution problem,
nothing else.
Just think of what could happen when one of both parties "looses" their symetric key ?
And just assume that they do not realise that it has
happened.
Regards,--- Synchronet 3.22a-Linux NewsLink 1.2
Rudy Wieser
...You realize a few methods rely on generating and exchanging a
symmetric key in an initial step encrypted by asymmetric keys?
But than why use symmetric keys when you already have something that
generates and works with a-symmetric ones ? Thats twice the work,
with no benefit.
Efficiency of computation, smaller complexity.
Just think of what could happen when one of both parties "looses"
their symetric key ? And just assume that they do not realise
that it has happened.
Just think of what could happen when one of both parties "looses"
their symetric key ?
I'm pretty sure they then would exchange keys again.
We can "just assume" a lot of things.
Nuno,
...You realize a few methods rely on generating and exchanging a
symmetric key in an initial step encrypted by asymmetric keys?
But than why use symmetric keys when you already have something that
generates and works with a-symmetric ones ? Thats twice the work,
with no benefit.
Efficiency of computation, smaller complexity.
You do seem to have little context awareness.
Your answer is in regard to using only one encryption method (likely the symmetric key one). Your own "You realize" talks about using *both* methods in the same program.
So, again : why use a symmetric key when you already have generated and used an a-symmetric one - just so you could safely get that symmetric key to some other party ?
Just think of what could happen when one of both parties "looses"
their symetric key ? And just assume that they do not realise
that it has happened.
I'm still missing an answer to this question though. :-|
I get the feeling that you have no idea how to defend your stance that the usage of symmetric encryption is equal to that of a-symmetric
encryption.
In that case we should end our conversation sooner rather than later.
Regards,
Rudy Wieser
So, again : why use a symmetric key when you already have generated and
used an a-symmetric one - just so you could safely get that symmetric key
to some other party ?
Because the asymmetric encryption used to exchange the symmetric key is
more expensive than the symmetric encryption, so in a longer exchange
you do asymmetric encryption at the beginning, to establish the key for
the cheaper symmetric encryption that takes place for the rest of the conversation/exchange.
Just think of what could happen when one of both parties "looses"
their symetric key ? And just assume that they do not realise
that it has happened.
I get the feeling that you have no idea how to defend your stance that
the usage of symmetric encryption is equal to that of a-symmetric
encryption.
That's not my stance.
Librarian2025,
Just think of what could happen when one of both parties "looses"
their symetric key ?
I'm pretty sure they then would exchange keys again.
Thats not what I asked.
We can "just assume" a lot of things.
Ah yes, the famous whataboutism.
Try to answer the question. If you can't than maybe just keep your mouth shut.
Just think of what could happen when one of both parties
"looses" their symetric key ?
I'm pretty sure they then would exchange keys again.
Thats not what I asked.
Well, that's what I answered.
"R.Wieser" <address@is.invalid> writes:
Librarian2025,
Just think of what could happen when one of both parties "looses"
their symetric key ?
I'm pretty sure they then would exchange keys again.
Thats not what I asked.
Well, that's what I answered.
We can "just assume" a lot of things.
Ah yes, the famous whataboutism.
It was not me who started with "just assume..."
Try to answer the question. If you can't than maybe just keep your mouth
shut.
I'm not obligated to only give you answers that you like.
Nuno,
So, again : why use a symmetric key when you already have generated and
used an a-symmetric one - just so you could safely get that symmetric key >>> to some other party ?
Because the asymmetric encryption used to exchange the symmetric key is
more expensive than the symmetric encryption, so in a longer exchange
you do asymmetric encryption at the beginning, to establish the key for
the cheaper symmetric encryption that takes place for the rest of the
conversation/exchange.
And so you have drifted off from how to use symmetric encryption keys for exchange of multiple messages (ref: hermes suggested MycroCrypt program) to a so-called session-encryption key - normally with a rather short lifespan.
But you have a point, I did not think of doing it that way.
Just think of what could happen when one of both parties "looses"
their symetric key ? And just assume that they do not realise
that it has happened.
And I'm *still* missing an answer to this question.
I get the feeling that you have no idea how to defend your stance that
the usage of symmetric encryption is equal to that of a-symmetric
encryption.
That's not my stance.
Than what /is/ your stance ?
But, in a nutshell :
The security of a symmetric key fully depends on how often you replace it.
An a-symmetric public key doesn't have that vulnerability.
Regards,
Rudy Wieser
I think at one point in the thread the usefulness of symmetric
encryption was questioned, hence why I mentioned that.
MicroCrypt is a multi-purpose symmetric encryption app for mobile and desktop.
I get the feeling that you have no idea how to defend your stance
that the usage of symmetric encryption is equal to that of
a-symmetric encryption.
That's not my stance.
Than what /is/ your stance ?
If I have to have a stance and make it public on anything you choose
to point out in the context of threads I'm replying to, that's a game
I don't want to play.
But, in a nutshell :
The security of a symmetric key fully depends on how often you replace
it.
An a-symmetric public key doesn't have that vulnerability.
Oh, but it does have similar weaknesses depending on size and the
advance of computing machinery, and making them age-limited is a
thing that *is* done too.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 74 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 121:15:46 |
| Calls: | 1,194 |
| Files: | 1,352 |
| Messages: | 290,208 |