Question
What are the key parameters of DES and why is it considered insecure today?
Answer
DES uses a 56-bit key with 64-bit blocks over 16 Feistel rounds — it's insecure because 2^56 keys can be brute-forced in hours with modern hardware.
DES parameters:
| Parameter | Value |
|---|---|
| Block size | 64 bits |
| Key length | 56 bits (64 bits input, 8 are parity) |
| Rounds | 16 |
| Structure | Feistel network |
History:
- Developed by IBM, adopted as a US federal standard (FIPS) by the National Bureau of Standards (now NIST) in 1977
- IBM's original "Lucifer" design used a longer key; the published standard fixed it at 56 bits — a shortening widely attributed to NSA influence and controversial at the time
- In 1999, the EFF's "Deep Crack" machine (working with distributed.net) recovered a DES key in about 22 hours
Why 56 bits is too short:
- 2^56 = 7.2 × 10^16 possible keys
- Modern hardware (FPGAs, ASICs, cloud computing) can search this space quickly
- DES was officially withdrawn as a standard in 2005
The algorithm itself is well-designed — the weakness is purely the short key length. This is why 3DES was created as a stopgap.
Go deeper:
Data Encryption Standard (Wikipedia) — the 56-bit key controversy, Deep Crack, and withdrawal.
Note saved — thanks!
Question
True or false: "RSA is immune to side-channel attacks."
Answer
False — RSA is highly vulnerable to side-channel attacks, particularly power analysis (SPA/DPA) during the square-and-multiply computation of $m^d \mod N$.
* Every 1-bit of the private exponent triggers an extra multiply, so its larger power/timing signature lets an attacker read d straight off the trace. *
Why RSA is vulnerable:
- Decryption/signing computes $m^d \mod N$ using SAM (Square-and-Multiply)
- For each bit of $d$: a "1" bit causes a MULTIPLY + SQUARE, a "0" bit causes only a SQUARE
- These operations have different power consumption and different timing
- An attacker monitoring power traces can literally read the private key $d$ bit by bit
Known side-channel attacks on RSA:
- Simple Power Analysis (SPA): Directly read the key from one power trace
- Differential Power Analysis (DPA): Statistical analysis over many traces
- Timing attacks: Different keys cause different computation times
- Electromagnetic emissions: EM radiation leaks key information
Countermeasures:
- Blinding: Randomize the computation using RSA's multiplicative property — multiply $m$ by a random $r^e$ before decryption, then divide by $r$ afterward
- Constant-time implementations: Ensure every bit of the key takes the same time
- Hardware shielding: EM and power filtering
Tip: The multiplicative property of RSA is both a weakness (malleability) AND a tool for defending against side channels (blinding). Context determines whether it's friend or foe.
Go deeper:
Power analysis — SPA & DPA (Wikipedia) — reading a key straight from the power trace.
Side-channel attack (Wikipedia) — the whole family: timing, power, EM, cache.
Blinding (cryptography) (Wikipedia) — the randomisation countermeasure named in the tip.
Note saved — thanks!