[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Lotus Notes



[Birthday paradoxing to get test for non-random padding]

> simply generating a few thousand messages (maybe six or seven
> thousand, to be safe), and seeing whether or not we ever get a
> duplicate LEAF. We expect to, after about 2^12 encryptions, if

If you were to try this, you'ld probably want to try around 12,000 to 
reach the 95% confidence interval. However, I seriously doubt that this 
is going to be the case; they're using BSAFE, which does random padding 
to PCKS1 in just about all it's RSA modes.  The only people Lotus could 
hire to get it that wrong probably have too much tied up in options to be 
easily head-hunted.

Simon