lundi 12 janvier 2015

How to describe RC4 'bias' to non-tech people



I'm looking for the 'plain English' version of 'bias' as used in the context of the RC4 weakness.


I know that RC4 generates a string of psuedorandom bits over, for instance, http(s) traffic. If you encrypt mostly the same data with this, there is little change in what you're encrypting, and this allows for similarities in your output. So, part of your strings will look the same, and may even be repeating what you've seen before.


Can I use 'similarities in your output' or 'parts of strings that repeat themselves' as a translation for 'bias' in this context, or is there a better explanation?





Aucun commentaire:

Enregistrer un commentaire