2004-03-04 17:49:15

by daw

[permalink] [raw]
Subject: Re: dm-crypt, new IV and standards

Jean-Luc Cooke wrote:
>Like you said, CBC is not trivial to temper with - though it is do able. CTR
>is trivial on the other hand. Which is why NIST and every cryptographer will
>recommend using a MAC with CTR. (Why still have CTR? Unlike CBC, you can
>compute the N+1-th block without needing to know the output from the N-th
>block, so there is the possibility for very high parallelizum).

I'm worried about the potential for confusion, so let me clarify: Good
cryptographers will recommend using a MAC, whether you use CTR, CBC,
or CFB. The need for a MAC is not specific to CTR; CBC is not exempt.