[tor-bugs] #18274 [Tor Browser]: 3DES_EDE_CBC cipher is vulnerable in the current TBB configuration!

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Feb 10 07:57:02 UTC 2016


#18274: 3DES_EDE_CBC cipher is vulnerable in the current TBB configuration!
--------------------------+--------------------------
 Reporter:  bugzilla      |          Owner:  tbb-team
     Type:  defect        |         Status:  closed
 Priority:  Medium        |      Milestone:
Component:  Tor Browser   |        Version:
 Severity:  Major         |     Resolution:  invalid
 Keywords:  tbb-security  |  Actual Points:
Parent ID:                |         Points:
  Sponsor:                |
--------------------------+--------------------------

Comment (by yawning):

 Not interesting.

 Despite what guidelines say, the best known attacks against 3DES are
 computationally infeasable.

 The best known attack against 3DES is computationally infeasible
 (http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.119.1761&rep=rep1&type=pdf).
 Anything that could break 3DES could break 128 bit AES as well, because
 the only likely feasible break is a quantum computer.

 (Landauer's principle doesn't go away just because you have lots of
 money.)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18274#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list