Hopefully it will not impact BouncyCastle interoperability. Now - also Botan 
interoperability.

Sent from my test iPhone

> On Jul 1, 2019, at 19:00, Jeffrey Walton <noloa...@gmail.com> wrote:
> 
> 
> 
>> On Monday, July 1, 2019 at 6:48:57 PM UTC-4, Mouse wrote:
>> If memory serves, ECIES standard required ^authenticated* encryption. That 
>> means - null hash wasn't allowed. 
>> 
>> Besides, there's Moxy Marlinspike principle: "If you don't enforce 
>> integrity, sooner or later you'll lose confidentiality as well."
>> 
>> Having said that, I don't recall why that particular change was made, and am 
>> willing to experiment to see what would happen if it's replaced with 
>> MAC::DEFAULT_KEYLENGTH (but we'll need to review the algorithm to recall 
>> what is doing there!).
> 
> We have test cases for ECIES in validat8.cpp 
> (https://github.com/weidai11/cryptopp/blob/master/validat8.cpp), but we don't 
> have one for the Null hash. Based on the test cases, I think we should be OK 
> to use MAC::DEFAULT_KEYLENGTH.
> 
> Jeff
> -- 
> You received this message because you are subscribed to "Crypto++ Users". 
> More information about Crypto++ and this group is available at 
> http://www.cryptopp.com and 
> http://groups.google.com/forum/#!forum/cryptopp-users.
> --- 
> You received this message because you are subscribed to the Google Groups 
> "Crypto++ Users" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to cryptopp-users+unsubscr...@googlegroups.com.
> To view this discussion on the web visit 
> https://groups.google.com/d/msgid/cryptopp-users/e7fa1c0d-a955-412d-9f25-825af2899fd5%40googlegroups.com.

-- 
You received this message because you are subscribed to "Crypto++ Users". More 
information about Crypto++ and this group is available at 
http://www.cryptopp.com and 
http://groups.google.com/forum/#!forum/cryptopp-users.
--- 
You received this message because you are subscribed to the Google Groups 
"Crypto++ Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to cryptopp-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/cryptopp-users/EDF6CD04-D4A4-4D13-9873-67B143725FFC%40gmail.com.

Reply via email to