Great Circle Associates Firewalls
(December 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: WAN Encryption
From: Adam Shostack <adam @ bwh . harvard . edu>
Date: Wed, 20 Dec 1995 12:47:02 -0500 (EST)
To: bvvanor @ rssi . rssi . com (Brad VanOrden)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <9512201626 . AA01581 @ mel . rssi . com> from "Brad VanOrden" at Dec 20, 95 11:26:25 am

Brad Van Orden wrote:

| I have a question regarding the level of protection I can expect from
| compressing traffic before it hits a WAN.  That is, the compression
| box vendor stated that since the data is compressed, that unless a snooper
| has the compression key, the data is also essentially encrypted.
| 
| My customer has stated that the data is not classified, but would also
| like to keep it out of plain view.
| 
| Do you feel the "compression" encyrption is good enough, or should I look
| for a better encryption method?

	I wouldn't trust a compression algorithim, even if it is
keyed.  They tend to use obscurity, rather than a good cryptosystem.

	If your customer expects that a competitor might spend an hour
to break the encryption, then you want something stronger.  (Not that
the algorithim will be broken in an hour, but many people, especially
outside the security field, underestimate the effort that will be put
into breaking a system.)

	I find that a good basic test of encryption strength is if the
US government forbids its export.  If its export is not forbidden,
then the encryption is very weak, and shouldn't be trusted.

Adam

-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume



References:
Indexed By Date Previous: Microsoft marketing strategy (MARKET.EXE)
From: "Dave Druitt" <dave_druitt @ GWFX1 . sysorex . com>
Next: New performance results for Raptor
From: Alan Kirby <akirby @ raptor . com>
Indexed By Thread Previous: WAN Encryption
From: Brad VanOrden <bvvanor @ rssi . rssi . com>
Next: Re: WAN Encryption
From: Chris Kostick <ckostick @ ashton . csc . com>

Google
 
Search Internet Search www.greatcircle.com