article

Blog » The Cryptographic Doom Principle

Dec 13, 2011·~6 minutes·4 chapters

Chapters

4 total

When it comes to designing secure protocols, I have a principle that goes like this: if you have to perform any cryptographic operation before verifying the MAC on a message you’ve received, it will somehow inevitably lead to doom.

0:17

1. Vaudenay Attack

4:27

2. SSH Plaintext Recovery

1:54

In Conclusion

0:17

Description

When it comes to designing secure protocols, I have a principle that goes like this: if you have to perform any cryptographic operation before verifying the MAC on a message you’ve received, it will somehow inevitably lead to doom.

We are not affiliated with Moxie Marlinspike or Signal. This unofficial audio edition is available to listen to and share for free. Read the originals on moxie.org.

Details

Duration

~6 minutes (6K characters)

Release date

Dec 13, 2011