[{"data":1,"prerenderedAt":494},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-cast5":276,"-ciphers-cast5-surround":489},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-lucide-book-open",{"title":37,"path":38,"stem":39,"children":40,"icon":275},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235,239,243,247,251,255,259,263,267,271],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Classical","\u002Fciphers\u002Fclassical","2.ciphers\u002F01.classical",{"title":48,"path":49,"stem":50},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F02.caesar",{"title":52,"path":53,"stem":54},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F03.rot13",{"title":56,"path":57,"stem":58},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F04.rot47",{"title":60,"path":61,"stem":62},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F05.atbash",{"title":64,"path":65,"stem":66},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F06.affine",{"title":68,"path":69,"stem":70},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F07.vigenere",{"title":72,"path":73,"stem":74},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F08.beaufort",{"title":76,"path":77,"stem":78},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F09.autokey",{"title":80,"path":81,"stem":82},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F10.trithemius",{"title":84,"path":85,"stem":86},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F11.alberti",{"title":88,"path":89,"stem":90},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F12.playfair",{"title":92,"path":93,"stem":94},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F13.polybius",{"title":96,"path":97,"stem":98},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F14.morse",{"title":100,"path":101,"stem":102},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F15.bacon",{"title":104,"path":105,"stem":106},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F16.tap-code",{"title":108,"path":109,"stem":110},"A1Z26","\u002Fciphers\u002Fa1z26","2.ciphers\u002F17.a1z26",{"title":112,"path":113,"stem":114},"Book cipher","\u002Fciphers\u002Fbook","2.ciphers\u002F18.book",{"title":116,"path":117,"stem":118},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F19.adfgvx",{"title":120,"path":121,"stem":122},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F20.bifid",{"title":124,"path":125,"stem":126},"Straddling checkerboard","\u002Fciphers\u002Fstraddling-checkerboard","2.ciphers\u002F21.straddling-checkerboard",{"title":128,"path":129,"stem":130},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F22.rail-fence",{"title":132,"path":133,"stem":134},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F23.columnar",{"title":136,"path":137,"stem":138},"Route transposition","\u002Fciphers\u002Froute","2.ciphers\u002F24.route",{"title":140,"path":141,"stem":142},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F25.enigma",{"title":144,"path":145,"stem":146},"Block","\u002Fciphers\u002Fblock","2.ciphers\u002F26.block",{"title":148,"path":149,"stem":150},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F27.aes",{"title":152,"path":153,"stem":154},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F28.aes-cbc",{"title":156,"path":157,"stem":158},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F29.aes-cfb",{"title":160,"path":161,"stem":162},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F30.aes-ofb",{"title":164,"path":165,"stem":166},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F31.aes-ctr",{"title":168,"path":169,"stem":170},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F32.aes-ccm",{"title":172,"path":173,"stem":174},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F33.aes-ocb",{"title":176,"path":177,"stem":178},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F34.aes-lrw",{"title":180,"path":181,"stem":182},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F35.aes-xts",{"title":184,"path":185,"stem":186},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F36.aes-cbc-mac",{"title":188,"path":189,"stem":190},"AES (passphrase)","\u002Fciphers\u002Faes-passphrase","2.ciphers\u002F37.aes-passphrase",{"title":192,"path":193,"stem":194},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F38.rijndael",{"title":196,"path":197,"stem":198},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F39.des",{"title":200,"path":201,"stem":202},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F40.desx",{"title":204,"path":205,"stem":206},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F41.triple-des",{"title":208,"path":209,"stem":210},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F42.triple-des-cbc",{"title":212,"path":213,"stem":214},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F43.blowfish",{"title":216,"path":217,"stem":218},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F44.idea",{"title":220,"path":221,"stem":222},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F45.lucifer",{"title":224,"path":225,"stem":226},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F46.mars",{"title":228,"path":229,"stem":230},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F47.serpent",{"title":232,"path":233,"stem":234},"CAST5 (ECB)","\u002Fciphers\u002Fcast5","2.ciphers\u002F48.cast5",{"title":236,"path":237,"stem":238},"OpenPGP (passphrase)","\u002Fciphers\u002Fopenpgp","2.ciphers\u002F49.openpgp",{"title":240,"path":241,"stem":242},"Stream","\u002Fciphers\u002Fstream","2.ciphers\u002F50.stream",{"title":244,"path":245,"stem":246},"Rabbit","\u002Fciphers\u002Frabbit","2.ciphers\u002F51.rabbit",{"title":248,"path":249,"stem":250},"RC4","\u002Fciphers\u002Frc4","2.ciphers\u002F52.rc4",{"title":252,"path":253,"stem":254},"XOR","\u002Fciphers\u002Fxor","2.ciphers\u002F53.xor",{"title":256,"path":257,"stem":258},"Salsa20","\u002Fciphers\u002Fsalsa20","2.ciphers\u002F54.salsa20",{"title":260,"path":261,"stem":262},"XSalsa20","\u002Fciphers\u002Fxsalsa20","2.ciphers\u002F55.xsalsa20",{"title":264,"path":265,"stem":266},"ChaCha20","\u002Fciphers\u002Fchacha20","2.ciphers\u002F56.chacha20",{"title":268,"path":269,"stem":270},"XChaCha20","\u002Fciphers\u002Fxchacha20","2.ciphers\u002F57.xchacha20",{"title":272,"path":273,"stem":274},"ChaCha20-Poly1305","\u002Fciphers\u002Fchacha20-poly1305","2.ciphers\u002F58.chacha20-poly1305","i-lucide-library",{"id":277,"title":232,"body":278,"description":482,"extension":483,"links":484,"meta":485,"navigation":486,"path":233,"seo":487,"stem":234,"__hash__":488},"docs\u002F2.ciphers\u002F48.cast5.md",{"type":279,"value":280,"toc":476},"minimark",[281,285,289,301,395,398,403,406,409,412,416,425,429,436,440,443,451,469,472],[282,283],"cipher-facts",{"name":284},"cast5",[286,287,288],"p",{},"Found an old PGP message? Check for CAST5 inside. Carlisle Adams published it as RFC 2144 in May 1997, under the name CAST-128. RFC 4880, the OpenPGP spec, then said every implementation must have Triple DES and should have AES-128 and CAST5. So for years it sat right there in the menu.",[286,290,291,292,296,297,300],{},"Here it runs on its own, in ECB, like ",[293,294,295],"code",{},"blowfish"," and ",[293,298,299],{},"idea",". UTF-8 text in, PKCS#7 padding, hex out.",[302,303,308],"pre",{"className":304,"code":305,"language":306,"meta":307,"style":307},"language-ts shiki shiki-themes ciphers ciphers ciphers","const cast5 = create(\"cast5\");\nconst key = \"0123456712345678234567893456789a\";\ncast5.encode(\"ATTACK AT DAWN\", { key }).text; \u002F\u002F \"585e13962a59ed5274e0ab1bdcde47a3\"\ncast5.decode(\"585e13962a59ed5274e0ab1bdcde47a3\", { key }).text; \u002F\u002F \"ATTACK AT DAWN\"\n","ts","",[293,309,310,340,356,377],{"__ignoreMap":307},[311,312,315,319,323,326,330,333,337],"span",{"class":313,"line":314},"line",1,[311,316,318],{"class":317},"skH_V","const",[311,320,322],{"class":321},"s38Sx"," cast5 ",[311,324,325],{"class":317},"=",[311,327,329],{"class":328},"sK71F"," create",[311,331,332],{"class":321},"(",[311,334,336],{"class":335},"shU9J","\"cast5\"",[311,338,339],{"class":321},");\n",[311,341,343,345,348,350,353],{"class":313,"line":342},2,[311,344,318],{"class":317},[311,346,347],{"class":321}," key ",[311,349,325],{"class":317},[311,351,352],{"class":335}," \"0123456712345678234567893456789a\"",[311,354,355],{"class":321},";\n",[311,357,359,362,365,367,370,373],{"class":313,"line":358},3,[311,360,361],{"class":321},"cast5.",[311,363,364],{"class":328},"encode",[311,366,332],{"class":321},[311,368,369],{"class":335},"\"ATTACK AT DAWN\"",[311,371,372],{"class":321},", { key }).text; ",[311,374,376],{"class":375},"scIB-","\u002F\u002F \"585e13962a59ed5274e0ab1bdcde47a3\"\n",[311,378,380,382,385,387,390,392],{"class":313,"line":379},4,[311,381,361],{"class":321},[311,383,384],{"class":328},"decode",[311,386,332],{"class":321},[311,388,389],{"class":335},"\"585e13962a59ed5274e0ab1bdcde47a3\"",[311,391,372],{"class":321},[311,393,394],{"class":375},"\u002F\u002F \"ATTACK AT DAWN\"\n",[286,396,397],{},"That key is the one RFC 2144 uses for its own vectors.",[399,400,402],"h2",{"id":401},"what-a-round-does","What a round does",[286,404,405],{},"It's a Feistel cipher. The block splits into two 32-bit halves, and each round runs the right half through a function into the left. The function takes two subkeys. One is a 32-bit masking key, the other a 5-bit rotation. Mask, rotate, split into four bytes, look each byte up in its own S-box, combine the four words.",[286,407,408],{},"Three round types take turns. Type 1 adds the mask and combines with XOR, subtract, add. Type 2 starts with XOR, type 3 with a subtraction. Same parts, different order, round after round.",[286,410,411],{},"The key is 40 to 128 bits in steps of 8, so 10 to 32 hex digits. A shorter key gets padded with zeros to 128 bits. And up to 80 bits it runs 12 rounds instead of 16. Weaker key, less work. Fair, in a way.",[399,413,415],{"id":414},"eight-s-boxes-copied-not-grown","Eight S-boxes, copied, not grown",[286,417,418,420,421,424],{},[293,419,295],{}," computes its tables from the digits of pi. ",[293,422,423],{},"mars"," grows its S-box from SHA-1. CAST5 has nothing like that. Its eight boxes of 256 words came out of the CAST design procedure Adams wrote up in a paper. No formula, so they're stored. Four run the rounds, four run the key schedule. The file holds them exactly as RFC 2144 Appendix A prints them, eight hex words to a line. A script lifted them from the RFC text, not a pair of tired eyes.",[399,426,428],{"id":427},"checked-against","Checked against",[286,430,431,432,435],{},"RFC 2144 B.1 for the 128, 80 and 40-bit keys, both ways. Then UTF-8 text against ",[293,433,434],{},"openssl enc -cast5-ecb"," with the legacy provider. The RFC also has a maintenance test: a million rounds of two 128-bit values encrypting each other. It took 21 seconds in a local run and ended on the RFC's exact values. Too slow for the test suite, so it ran once.",[399,437,439],{"id":438},"should-you-encrypt-with-it","Should you encrypt with it?",[286,441,442],{},"No. RFC 9580, the OpenPGP spec that replaced RFC 4880 in 2024, says implementations must not encrypt with IDEA, Triple DES or CAST5 anymore. Decrypting old messages is still allowed. GnuPG 2.4 refuses to encrypt with it out of the box. And this page is ECB on top, which leaks every repeated block.",[286,444,445,446,450],{},"Got a whole PGP message rather than raw blocks? That's ",[447,448,449],"a",{"href":237},"openpgp",", which runs CAST5 inside OpenPGP's CFB.",[286,452,453,454,457,458,461,462,464,465,468],{},"A key that isn't 10 to 32 hex digits, or isn't whole bytes, is an ",[293,455,456],{},"InvalidOptionError",". A missing key is a ",[293,459,460],{},"MissingOptionError",". On ",[293,463,384],{},", ciphertext that isn't whole 8-byte blocks, or doesn't end in PKCS#7 padding, is a ",[293,466,467],{},"CipherError",".",[286,470,471],{},"Plain TypeScript, not constant time. Old messages and learning, not secrets.",[473,474,475],"style",{},"html pre.shiki code .skH_V, html code.shiki .skH_V{--shiki-light:var(--shiki-token-keyword);--shiki-default:var(--shiki-token-keyword);--shiki-dark:var(--shiki-token-keyword)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":307,"searchDepth":342,"depth":342,"links":477},[478,479,480,481],{"id":401,"depth":342,"text":402},{"id":414,"depth":342,"text":415},{"id":427,"depth":342,"text":428},{"id":438,"depth":342,"text":439},"CAST-128 from RFC 2144, the cipher OpenPGP told everyone to carry next to AES. Feistel rounds on 8-byte blocks, here in ECB with PKCS#7 padding.","md",null,{},true,{"title":232,"description":482},"5YUYA51_u5C83cc6TtpsCoGh4kna78_VdFV1VOOmpX0",[490,492],{"title":228,"path":229,"stem":230,"description":491,"children":-1},"Anderson, Biham and Knudsen's AES finalist from 1998. Thirty-two rounds of 4-bit S-boxes on 16-byte blocks, keys of 128, 192 or 256 bits. UTF-8 text in, hex out.",{"title":236,"path":237,"stem":238,"description":493,"children":-1},"What gpg --symmetric writes. A PGP MESSAGE block opened with a passphrase, with IDEA, Triple DES, CAST5, Blowfish or AES and ZIP, ZLIB or BZip2 inside.",1791184045027]