Re: New types for transparent encryption

Поиск
Список
Период
Сортировка
От Andrew Chernow
Тема Re: New types for transparent encryption
Дата
Msg-id 4A540770.7070001@esilo.com
обсуждение исходный текст
Ответ на Re: New types for transparent encryption  (Greg Stark <gsstark@mit.edu>)
Ответы Re: New types for transparent encryption  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-hackers
> Encrypting lots of small chunks of data with the same key is a very
> dangerous thing to do and it's very tricky to get right.

Using an initialization vector (IV) is the way to go, recommend using CBC or CFB 
mode.  Although, an IV is never supposed to be used more than once with the same 
key; that can leak hints about the plaintext.  Where is the randomly generated 
IV stored for use during decryption?

-- 
Andrew Chernow
eSilo, LLC
every bit counts
http://www.esilo.com/


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Greg Stark
Дата:
Сообщение: Re: New types for transparent encryption
Следующее
От: Andrew Dunstan
Дата:
Сообщение: Re: New types for transparent encryption