On Wed, Jun 28, 2006 at 12:58:59AM +0200, Alexander Schmehl wrote: > [ Cc-ing the bug report, so we have it in the bts, too ] > > Hi! > > - Now the real problem: shc.c > > Lookit at it we have: > > /** > * This software contains the 'Alleged RC4' source code. > * The original source code was published on the Net by a group of > cypherpunks. > * I picked up a modified version from the news. > * The copyright notice does not apply to that code. > */
As far as I remember, the general belief is that 'Alleged RC4' was in fact leaked intentionnaly by RSA inc. itself (which designed RC4). So much for the group of cypherpunks. > /** > * 'Alleged RC4' Source Code picked up from the news." > * From: [EMAIL PROTECTED] (John L. Allen)" > * Newsgroups: comp.lang.c" > * Subject: Shrink this C code for fame and fun" > * Date: 21 May 1996 10:49:37 -0400" > */ I think it should be easy to replace that code by a DFSG-free implementation of RC4. Openssl include one. Cheers, -- Bill. <[EMAIL PROTECTED]> Imagine a large red swirl here. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]