From 91f940b1e7e6f9ad04aa3e188359007ef5b9973c Mon Sep 17 00:00:00 2001 From: =?utf8?q?Niels=20M=C3=B6ller?= Date: Mon, 28 Feb 2011 17:08:45 +0100 Subject: [PATCH] Added link for CBC information leakage. Rev: nettle/nettle.texinfo:1.19 --- nettle.texinfo | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nettle.texinfo b/nettle.texinfo index c585e656..5e0d00c4 100644 --- a/nettle.texinfo +++ b/nettle.texinfo @@ -1349,7 +1349,9 @@ Book mode, @acronym{ECB}) leaks information. Besides @acronym{ECB}, Nettle provides three other modes of operation: Cipher Block Chaining (@acronym{CBC}), Counter mode (@acronym{CTR}), and Galois/Counter mode (@acronym{gcm}). @acronym{CBC} is widely used, but there are a few -subtle issues of information leakage. @acronym{CTR} and @acronym{GCM} +subtle issues of information leakage, see, e.g., +@uref{http://www.kb.cert.org/vuls/id/958563, @acronym{SSH} @acronym{CBC} +vulnerability}. @acronym{CTR} and @acronym{GCM} were standardized more recently, and are believed to be more secure. @acronym{GCM} includes message authentication; for the other modes, one should always use a @acronym{MAC} (@pxref{Keyed hash functions}) or -- 2.47.3