Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe this will be the motivation everyone else needs to dump RC4?

http://googleonlinesecurity.blogspot.com/2013/11/a-roster-of...



The patent has already expired. Feel free to use it to your heart's content.


Worse, there's the allegation that NSA can crack RC4 in realtime (although I don't know what that means, other than "fast").

https://twitter.com/ioerror/status/398059565947699200


realtime means your algorithm is guaranteed within a certain window of time, even accounting for delays talking to memory, caches, etc. If it's okay to "drop frames" it is referred to as "soft real time", otherwise it is referred to as "hard real time".

Soft example: Video decoding.

Hard example: Mars rover.


I'm not much into crypto but I'm pretty sure RC4 has been broken for a very long time now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: