[{"data":1,"prerenderedAt":874},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-openpgp":276,"-ciphers-openpgp-surround":869},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-lucide-book-open",{"title":37,"path":38,"stem":39,"children":40,"icon":275},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235,239,243,247,251,255,259,263,267,271],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Classical","\u002Fciphers\u002Fclassical","2.ciphers\u002F01.classical",{"title":48,"path":49,"stem":50},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F02.caesar",{"title":52,"path":53,"stem":54},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F03.rot13",{"title":56,"path":57,"stem":58},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F04.rot47",{"title":60,"path":61,"stem":62},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F05.atbash",{"title":64,"path":65,"stem":66},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F06.affine",{"title":68,"path":69,"stem":70},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F07.vigenere",{"title":72,"path":73,"stem":74},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F08.beaufort",{"title":76,"path":77,"stem":78},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F09.autokey",{"title":80,"path":81,"stem":82},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F10.trithemius",{"title":84,"path":85,"stem":86},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F11.alberti",{"title":88,"path":89,"stem":90},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F12.playfair",{"title":92,"path":93,"stem":94},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F13.polybius",{"title":96,"path":97,"stem":98},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F14.morse",{"title":100,"path":101,"stem":102},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F15.bacon",{"title":104,"path":105,"stem":106},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F16.tap-code",{"title":108,"path":109,"stem":110},"A1Z26","\u002Fciphers\u002Fa1z26","2.ciphers\u002F17.a1z26",{"title":112,"path":113,"stem":114},"Book cipher","\u002Fciphers\u002Fbook","2.ciphers\u002F18.book",{"title":116,"path":117,"stem":118},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F19.adfgvx",{"title":120,"path":121,"stem":122},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F20.bifid",{"title":124,"path":125,"stem":126},"Straddling checkerboard","\u002Fciphers\u002Fstraddling-checkerboard","2.ciphers\u002F21.straddling-checkerboard",{"title":128,"path":129,"stem":130},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F22.rail-fence",{"title":132,"path":133,"stem":134},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F23.columnar",{"title":136,"path":137,"stem":138},"Route transposition","\u002Fciphers\u002Froute","2.ciphers\u002F24.route",{"title":140,"path":141,"stem":142},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F25.enigma",{"title":144,"path":145,"stem":146},"Block","\u002Fciphers\u002Fblock","2.ciphers\u002F26.block",{"title":148,"path":149,"stem":150},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F27.aes",{"title":152,"path":153,"stem":154},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F28.aes-cbc",{"title":156,"path":157,"stem":158},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F29.aes-cfb",{"title":160,"path":161,"stem":162},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F30.aes-ofb",{"title":164,"path":165,"stem":166},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F31.aes-ctr",{"title":168,"path":169,"stem":170},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F32.aes-ccm",{"title":172,"path":173,"stem":174},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F33.aes-ocb",{"title":176,"path":177,"stem":178},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F34.aes-lrw",{"title":180,"path":181,"stem":182},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F35.aes-xts",{"title":184,"path":185,"stem":186},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F36.aes-cbc-mac",{"title":188,"path":189,"stem":190},"AES (passphrase)","\u002Fciphers\u002Faes-passphrase","2.ciphers\u002F37.aes-passphrase",{"title":192,"path":193,"stem":194},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F38.rijndael",{"title":196,"path":197,"stem":198},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F39.des",{"title":200,"path":201,"stem":202},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F40.desx",{"title":204,"path":205,"stem":206},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F41.triple-des",{"title":208,"path":209,"stem":210},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F42.triple-des-cbc",{"title":212,"path":213,"stem":214},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F43.blowfish",{"title":216,"path":217,"stem":218},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F44.idea",{"title":220,"path":221,"stem":222},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F45.lucifer",{"title":224,"path":225,"stem":226},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F46.mars",{"title":228,"path":229,"stem":230},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F47.serpent",{"title":232,"path":233,"stem":234},"CAST5 (ECB)","\u002Fciphers\u002Fcast5","2.ciphers\u002F48.cast5",{"title":236,"path":237,"stem":238},"OpenPGP (passphrase)","\u002Fciphers\u002Fopenpgp","2.ciphers\u002F49.openpgp",{"title":240,"path":241,"stem":242},"Stream","\u002Fciphers\u002Fstream","2.ciphers\u002F50.stream",{"title":244,"path":245,"stem":246},"Rabbit","\u002Fciphers\u002Frabbit","2.ciphers\u002F51.rabbit",{"title":248,"path":249,"stem":250},"RC4","\u002Fciphers\u002Frc4","2.ciphers\u002F52.rc4",{"title":252,"path":253,"stem":254},"XOR","\u002Fciphers\u002Fxor","2.ciphers\u002F53.xor",{"title":256,"path":257,"stem":258},"Salsa20","\u002Fciphers\u002Fsalsa20","2.ciphers\u002F54.salsa20",{"title":260,"path":261,"stem":262},"XSalsa20","\u002Fciphers\u002Fxsalsa20","2.ciphers\u002F55.xsalsa20",{"title":264,"path":265,"stem":266},"ChaCha20","\u002Fciphers\u002Fchacha20","2.ciphers\u002F56.chacha20",{"title":268,"path":269,"stem":270},"XChaCha20","\u002Fciphers\u002Fxchacha20","2.ciphers\u002F57.xchacha20",{"title":272,"path":273,"stem":274},"ChaCha20-Poly1305","\u002Fciphers\u002Fchacha20-poly1305","2.ciphers\u002F58.chacha20-poly1305","i-lucide-library",{"id":277,"title":236,"body":278,"description":863,"extension":864,"links":865,"meta":866,"navigation":361,"path":237,"seo":867,"stem":238,"__hash__":868},"docs\u002F2.ciphers\u002F49.openpgp.md",{"type":279,"value":280,"toc":855},"minimark",[281,285,303,427,434,441,474,479,485,501,504,508,518,522,533,536,540,550,640,709,728,734,738,773,780,784,791,809,815,845,848,851],[282,283],"cipher-facts",{"name":284},"openpgp",[286,287,288,289,293,294,297,298,302],"p",{},"A ",[290,291,292],"code",{},"-----BEGIN PGP MESSAGE-----"," block on a puzzle page, and a hint that smells like a password? That's ",[290,295,296],{},"gpg --symmetric",". Same idea as ",[299,300,301],"a",{"href":189},"aes-passphrase",", a password instead of a key. Different format though, and a lot more of it.",[304,305,310],"pre",{"className":306,"code":307,"language":308,"meta":309,"style":309},"language-ts shiki shiki-themes ciphers ciphers ciphers","const pgp = create(\"openpgp\");\npgp.decode(`-----BEGIN PGP MESSAGE-----\n\njA0ECQMKHwVT8OzL5gn90lIBzGgrwInQTM+5oFODSD8QMJaarJsJ7kftcv4jWWpP\n2I2U9qLHZ83SeQ1Ol\u002Fi2LutftOLxNYgigrj7idS03A5V1Psl+79RGbXLRDgSQKr7\nCo2B\n=XQvs\n-----END PGP MESSAGE-----`, { key: \"causality\" });\n\u002F\u002F text: \"follow the white rabbit\\n\"\n\u002F\u002F options: { algorithm: \"aes256\", digest: \"sha512\", count: 60817408,\n\u002F\u002F   salt: \"1f0553f0eccbe609\", iv: \"48c74c4430cdbe1ee97f78a7470dd098\",\n\u002F\u002F   compression: \"zip\", filename: \"m.txt\", ... }\n","ts","",[290,311,312,342,356,363,369,375,381,387,402,409,415,421],{"__ignoreMap":309},[313,314,317,321,325,328,332,335,339],"span",{"class":315,"line":316},"line",1,[313,318,320],{"class":319},"skH_V","const",[313,322,324],{"class":323},"s38Sx"," pgp ",[313,326,327],{"class":319},"=",[313,329,331],{"class":330},"sK71F"," create",[313,333,334],{"class":323},"(",[313,336,338],{"class":337},"shU9J","\"openpgp\"",[313,340,341],{"class":323},");\n",[313,343,345,348,351,353],{"class":315,"line":344},2,[313,346,347],{"class":323},"pgp.",[313,349,350],{"class":330},"decode",[313,352,334],{"class":323},[313,354,355],{"class":337},"`-----BEGIN PGP MESSAGE-----\n",[313,357,359],{"class":315,"line":358},3,[313,360,362],{"emptyLinePlaceholder":361},true,"\n",[313,364,366],{"class":315,"line":365},4,[313,367,368],{"class":337},"jA0ECQMKHwVT8OzL5gn90lIBzGgrwInQTM+5oFODSD8QMJaarJsJ7kftcv4jWWpP\n",[313,370,372],{"class":315,"line":371},5,[313,373,374],{"class":337},"2I2U9qLHZ83SeQ1Ol\u002Fi2LutftOLxNYgigrj7idS03A5V1Psl+79RGbXLRDgSQKr7\n",[313,376,378],{"class":315,"line":377},6,[313,379,380],{"class":337},"Co2B\n",[313,382,384],{"class":315,"line":383},7,[313,385,386],{"class":337},"=XQvs\n",[313,388,390,393,396,399],{"class":315,"line":389},8,[313,391,392],{"class":337},"-----END PGP MESSAGE-----`",[313,394,395],{"class":323},", { key: ",[313,397,398],{"class":337},"\"causality\"",[313,400,401],{"class":323}," });\n",[313,403,405],{"class":315,"line":404},9,[313,406,408],{"class":407},"scIB-","\u002F\u002F text: \"follow the white rabbit\\n\"\n",[313,410,412],{"class":315,"line":411},10,[313,413,414],{"class":407},"\u002F\u002F options: { algorithm: \"aes256\", digest: \"sha512\", count: 60817408,\n",[313,416,418],{"class":315,"line":417},11,[313,419,420],{"class":407},"\u002F\u002F   salt: \"1f0553f0eccbe609\", iv: \"48c74c4430cdbe1ee97f78a7470dd098\",\n",[313,422,424],{"class":315,"line":423},12,[313,425,426],{"class":407},"\u002F\u002F   compression: \"zip\", filename: \"m.txt\", ... }\n",[286,428,429,430,433],{},"GnuPG 2.4 wrote that one. You only pass the passphrase. Cipher, hash, salt and compression all come out of the message. And look, a file name. ",[290,431,432],{},"m.txt",". In a puzzle that name can be a hint all by itself.",[286,435,436,437,440],{},"On the command line the block goes in as it is. Five dashes up front? The CLI has no flag called ",[290,438,439],{},"---BEGIN",", so it takes the whole thing as text:",[304,442,446],{"className":443,"code":444,"language":445,"meta":309,"style":309},"language-bash shiki shiki-themes ciphers ciphers ciphers","ciphers decode openpgp --key causality \"$(cat message.asc)\"\n","bash",[290,447,448],{"__ignoreMap":309},[313,449,450,453,456,459,462,465,468,471],{"class":315,"line":316},[313,451,452],{"class":330},"ciphers",[313,454,455],{"class":337}," decode",[313,457,458],{"class":337}," openpgp",[313,460,461],{"class":337}," --key",[313,463,464],{"class":337}," causality",[313,466,467],{"class":337}," \"$(",[313,469,470],{"class":330},"cat",[313,472,473],{"class":337}," message.asc)\"\n",[475,476,478],"h2",{"id":477},"whats-in-the-block","What's in the block",[286,480,481,482,484],{},"The armor is base64 with a CRC-24 after the ",[290,483,327],{},". Under it sit packets:",[486,487,488,492,495,498],"ul",{},[489,490,491],"li",{},"A passphrase packet (SKESK). It names the cipher and the recipe for the key.",[489,493,494],{},"The encrypted data (SEIPD). CFB with a zero IV and a random block in front.",[489,496,497],{},"Inside it, the text in a literal data packet. Often squeezed with ZIP, ZLIB or BZip2 first.",[489,499,500],{},"At the very end, an MDC. That's a SHA-1 over everything before it.",[286,502,503],{},"Signatures inside get skipped, not checked. There's no key to check them with anyway.",[475,505,507],{"id":506},"where-does-the-key-come-from","Where does the key come from?",[286,509,510,511,514,515,517],{},"The S2K, string to key. Simple S2K hashes the passphrase once. Salted puts 8 random bytes in front first. Iterated and salted feeds salt and passphrase into the hash over and over, until ",[290,512,513],{},"count"," bytes went through. The message above asked for SHA-512 over 60,817,408 bytes. That's about 0.6 seconds in plain TypeScript. Compare that with three MD5 calls in ",[290,516,301],{},". Sixty megabytes of hashing per guess makes brute force boring fast.",[475,519,521],{"id":520},"wrong-passphrase-or-a-changed-message","Wrong passphrase or a changed message?",[286,523,524,525,528,529,532],{},"Two checks, two different errors. The random block ends with two bytes that get repeated right after it. A wrong key almost never reproduces them, and decoding stops with ",[290,526,527],{},"Wrong passphrase",". Pass that, and the MDC has to match too. No match? Someone changed or cut the message. You get ",[290,530,531],{},"The MDC does not match"," and no text at all.",[286,534,535],{},"Fun fact about those two repeated bytes. In 2005 Serge Mister and Robert Zuccherato found a leak in them. Give an attacker an oracle to ask, and they hand over two bytes of every block. RFC 4880 mentions it in its security notes. Here the only one asking is you.",[475,537,539],{"id":538},"writing-one","Writing one",[286,541,542,545,546,549],{},[290,543,544],{},"encode"," writes what ",[290,547,548],{},"gpg --symmetric --armor"," writes for a file, minus the compression. The passphrase packet uses an iterated and salted S2K. The literal packet is binary, with no file name and a zero date. Does GnuPG open it? Yes. Version 2.4.9 opened every algorithm and digest pair in a local run, all 42.",[304,551,553],{"className":306,"code":552,"language":308,"meta":309,"style":309},"pgp.encode(\"ATTACK AT DAWN\", {\n  key: \"secret\",\n  salt: \"0123456789abcdef\",\n  iv: \"000102030405060708090a0b0c0d0e0f\",\n  count: 1024,\n}).text;\n\u002F\u002F -----BEGIN PGP MESSAGE-----\n\u002F\u002F\n\u002F\u002F ww0ECQMKASNFZ4mrze8A0j8Br8ZnCdd7vvEG6ySSknAOb12FrBLP4TNGx516\u002F5rP\n\u002F\u002F bdCoMYOkVrPy\u002FKG35GrLD8ib0KRDjcTg9mrGGxBPt+g=\n\u002F\u002F =tyIJ\n\u002F\u002F -----END PGP MESSAGE-----\n",[290,554,555,569,580,590,600,605,610,615,620,625,630,635],{"__ignoreMap":309},[313,556,557,559,561,563,566],{"class":315,"line":316},[313,558,347],{"class":323},[313,560,544],{"class":330},[313,562,334],{"class":323},[313,564,565],{"class":337},"\"ATTACK AT DAWN\"",[313,567,568],{"class":323},", {\n",[313,570,571,574,577],{"class":315,"line":344},[313,572,573],{"class":323},"  key: ",[313,575,576],{"class":337},"\"secret\"",[313,578,579],{"class":323},",\n",[313,581,582,585,588],{"class":315,"line":358},[313,583,584],{"class":323},"  salt: ",[313,586,587],{"class":337},"\"0123456789abcdef\"",[313,589,579],{"class":323},[313,591,592,595,598],{"class":315,"line":365},[313,593,594],{"class":323},"  iv: ",[313,596,597],{"class":337},"\"000102030405060708090a0b0c0d0e0f\"",[313,599,579],{"class":323},[313,601,602],{"class":315,"line":371},[313,603,604],{"class":323},"  count: 1024,\n",[313,606,607],{"class":315,"line":377},[313,608,609],{"class":323},"}).text;\n",[313,611,612],{"class":315,"line":383},[313,613,614],{"class":407},"\u002F\u002F -----BEGIN PGP MESSAGE-----\n",[313,616,617],{"class":315,"line":389},[313,618,619],{"class":407},"\u002F\u002F\n",[313,621,622],{"class":315,"line":404},[313,623,624],{"class":407},"\u002F\u002F ww0ECQMKASNFZ4mrze8A0j8Br8ZnCdd7vvEG6ySSknAOb12FrBLP4TNGx516\u002F5rP\n",[313,626,627],{"class":315,"line":411},[313,628,629],{"class":407},"\u002F\u002F bdCoMYOkVrPy\u002FKG35GrLD8ib0KRDjcTg9mrGGxBPt+g=\n",[313,631,632],{"class":315,"line":417},[313,633,634],{"class":407},"\u002F\u002F =tyIJ\n",[313,636,637],{"class":315,"line":423},[313,638,639],{"class":407},"\u002F\u002F -----END PGP MESSAGE-----\n",[286,641,642,645,646,649,650,653,654,653,657,653,660,653,663,653,666,669,670,673,674,677,678,653,681,653,684,653,687,653,690,653,693,653,696,653,699,669,702,704,705,708],{},[290,643,644],{},"algorithm"," is ",[290,647,648],{},"aes256"," by default, or ",[290,651,652],{},"idea",", ",[290,655,656],{},"3des",[290,658,659],{},"cast5",[290,661,662],{},"blowfish",[290,664,665],{},"aes128",[290,667,668],{},"aes192",". ",[290,671,672],{},"digest"," is the S2K hash, ",[290,675,676],{},"sha512"," by default like GnuPG 2.4, or ",[290,679,680],{},"md5",[290,682,683],{},"sha1",[290,685,686],{},"ripemd160",[290,688,689],{},"sha224",[290,691,692],{},"sha256",[290,694,695],{},"sha384",[290,697,698],{},"sha3-256",[290,700,701],{},"sha3-512",[290,703,513],{}," is how many bytes that hash eats, 1024 to 65011712. OpenPGP stores it in one byte. So it gets rounded up to the next value that byte can hold. The default is the maximum, about 0.7 seconds. SHA3-512 chews on it for more than twice as long. Pass ",[290,706,707],{},"count: 1024"," when you just want to try things.",[286,710,711,714,715,718,719,721,722,724,725,727],{},[290,712,713],{},"salt"," and ",[290,716,717],{},"iv"," fix the two random parts, the 8-byte salt and the random first block. Leave them out and every run looks different. ",[290,720,350],{}," reports both, so its options fed back into ",[290,723,544],{}," give the same armor again, byte for byte. That works for what this cipher wrote. A GnuPG message carries a file name and a date that ",[290,726,544],{}," doesn't write.",[286,729,730,731,733],{},"RFC 9580 says nobody should encrypt with IDEA, Triple DES or CAST5 anymore. They're still here for ",[290,732,544],{},". Old puzzles were made with them, and you might want to make another. The default stays AES-256.",[475,735,737],{"id":736},"what-it-reads","What it reads",[486,739,740,743,746,749,756,759,766],{},[489,741,742],{},"Armor, or the bare packets in base64 or hex.",[489,744,745],{},"IDEA, Triple DES, CAST5, Blowfish and AES at all three sizes.",[489,747,748],{},"Simple, salted and iterated S2K, over MD5, SHA-1, RIPEMD-160, SHA-224, SHA-256, SHA-384, SHA-512, SHA3-256 or SHA3-512.",[489,750,751,752,755],{},"ZIP, ZLIB, BZip2 or no compression. ",[290,753,754],{},"@agntn\u002Fcompressions"," does the unpacking, so there's no second inflate to keep honest here.",[489,757,758],{},"Partial body lengths. GnuPG writes them when it reads from a pipe.",[489,760,761,762,765],{},"A session key encrypted under the passphrase. ",[290,763,764],{},"gpg -c -e"," writes one next to a public key packet.",[489,767,768,769,772],{},"Text mode. CRLF turns back into LF, the way ",[290,770,771],{},"gpg --decrypt"," does it.",[286,774,775,776,779],{},"Hiding a key or a file rather than text? ",[290,777,778],{},"bytes: \"hex\""," gives the plain side back as hex.",[475,781,783],{"id":782},"what-it-doesnt","What it doesn't",[286,785,786,787,790],{},"No public keys, no signatures, no web of trust. And a few things GnuPG can write that this can't open yet. Each one is a ",[290,788,789],{},"CipherError"," that names it:",[486,792,793,796,803,806],{},[489,794,795],{},"Twofish and Camellia. No block cipher for them here.",[489,797,798,799,802],{},"AEAD packets. GnuPG writes them with ",[290,800,801],{},"--force-ocb",", and for keys that ask for it.",[489,804,805],{},"Old encrypted data without an MDC, from PGP 2 and 6.",[489,807,808],{},"Argon2 S2K.",[286,810,811,812,814],{},"A message gets at most 8 passphrase packets tried, since each can cost 65 MB of hashing. Compressed data may grow to 4 MiB and nest 4 deep. Past that it's a ",[290,813,789],{}," too. Sounds stingy? BZip2 packs 5 MiB of zeros into a 137-byte packet, and the test suite has exactly that message.",[286,816,817,818,821,822,825,826,653,828,653,830,653,832,834,835,837,838,841,842,844],{},"A missing ",[290,819,820],{},"key"," is a ",[290,823,824],{},"MissingOptionError",". An ",[290,827,644],{},[290,829,672],{},[290,831,513],{},[290,833,713],{}," or ",[290,836,717],{}," it can't use is an ",[290,839,840],{},"InvalidOptionError",". A broken armor checksum, a cut packet, a wrong passphrase or a failed MDC is a ",[290,843,789],{},".",[286,846,847],{},"The vectors are messages from GnuPG 2.4.9. One per algorithm, S2K type, hash and compression above. Plus the one from the issue that asked for this cipher. GnuPG doesn't know SHA-3 at all, so the two SHA-3 messages come from OpenPGP.js. Cheating? A second implementation is a better witness anyway.",[286,849,850],{},"Plain TypeScript, not constant time. For opening puzzle pages, not for your diary.",[852,853,854],"style",{},"html pre.shiki code .skH_V, html code.shiki .skH_V{--shiki-light:var(--shiki-token-keyword);--shiki-default:var(--shiki-token-keyword);--shiki-dark:var(--shiki-token-keyword)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":309,"searchDepth":344,"depth":344,"links":856},[857,858,859,860,861,862],{"id":477,"depth":344,"text":478},{"id":506,"depth":344,"text":507},{"id":520,"depth":344,"text":521},{"id":538,"depth":344,"text":539},{"id":736,"depth":344,"text":737},{"id":782,"depth":344,"text":783},"What gpg --symmetric writes. A PGP MESSAGE block opened with a passphrase, with IDEA, Triple DES, CAST5, Blowfish or AES and ZIP, ZLIB or BZip2 inside.","md",null,{},{"title":236,"description":863},"1FF5zZnAeumOavGnH0G096-ETx9YTxdosSZeHxjH9lM",[870,872],{"title":232,"path":233,"stem":234,"description":871,"children":-1},"CAST-128 from RFC 2144, the cipher OpenPGP told everyone to carry next to AES. Feistel rounds on 8-byte blocks, here in ECB with PKCS#7 padding.",{"title":240,"path":241,"stem":242,"description":873,"children":-1},"Rabbit, RC4, XOR, Salsa20 and ChaCha20. A short key grows a long keystream, and the keystream is XORed into the text. UTF-8 bytes in and hex out.",1791184045062]