[Wikimedia-l] Disinformation regarding perfect forward secrecy for HTTPS

Anthony wikimail at inbox.org
Sat Aug 3 02:53:23 UTC 2013


Google also seems to be using RC4 128, so that explains why there's no
padding by default there.

RC4 is a stream cipher.  The more secure ciphers are (all?) block ciphers.

"A block cipher <https://en.wikipedia.org/wiki/Block_cipher> works on units
of a fixed size
<https://en.wikipedia.org/wiki/Block_size_(cryptography)> (known
as a *block size*), but messages come in a variety of lengths. So some
modes (namely ECB<https://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Electronic_codebook_.28ECB.29>
 and CBC <https://en.wikipedia.org/wiki/Cipher_block_chaining>) require
that the final block be padded before encryption."


On Fri, Aug 2, 2013 at 10:42 PM, James Salsman <jsalsman at gmail.com> wrote:

> > please address
> https://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Padding
>
> Sure. As soon as someone creates
> http://en.wikipedia.org/wiki/Sunset_Shimmerso I can use an appropriate
> example.
> _______________________________________________
> Wikimedia-l mailing list
> Wikimedia-l at lists.wikimedia.org
> Unsubscribe: https://lists.wikimedia.org/mailman/listinfo/wikimedia-l,
> <mailto:wikimedia-l-request at lists.wikimedia.org?subject=unsubscribe>
>


More information about the Wikimedia-l mailing list