Discussion Forums

re: Encryption Framework Discussion
Danny Shobrook / Apt Computer Systems Ltd
7 Apr 1998 4:58PM ET

Firstly, any traffic analysis will give you alot of information of heavy trading. As dest and source IDs are not encrypted, putting a sniffer will give you a clue if someone is trying to split a large trade up amongst smaller guys.

Secondly, any encryption/signing will have to be resistant to differential cryptoanalysis as alot of the plaintext will already be known.

Thirdly, you have to ask yourself about the perfomance tradeoffs with double encryption at transport and app layer. It *might* make sense for large institutional trades, we deal with retail and this would put an unacceptable overhead for really rather little return.

Fourthly, you would need to make sure there was a way of negotiating any app level encryption. The current "agree before" was maybe OK when the FIX community was small, but increasingly it will be used between parties that have no fixed relationship. There would need to be the opportunity to adjust between the level Charles wants and the level retail customers are happy with.

Fifthly, the most common security flaws are bugs in implementation and people probs. Coming up with a new app level protocol faces both these complications.

Finally, it puts a stress on FIX implementers to be encryption experts as well.

Danny Shobrook
Apt Computer Systems


Encryption Framework Discussion
Bob Lamoureux / Bridge Information Systems   3 Apr 1998 2:46PM ET
re: Encryption Framework Discussion
Charles Blauner / J.P. Morgan & Co. Incorporated   6 Apr 1998 9:22AM ET
re: Encryption Framework Discussion
Ryan Pierce / Townsend Analytics Ltd. / Archipelago LLC   6 Apr 1998 10:33AM ET
re: Encryption Framework Discussion
Charles Blauner / J.P. Morgan & Co. Incorporated   6 Apr 1998 11:01AM ET
re: Encryption Framework Discussion
Danny Shobrook / Apt Computer Systems Ltd   7 Apr 1998 4:58PM ET
re: Encryption Framework Discussion
Bob Lamoureux / Bridge Information Systems   8 Apr 1998 8:26AM ET
re: Encryption Framework Discussion
Ryan Pierce / Townsend Analytics Ltd. / Archipelago LLC   8 Apr 1998 4:51PM ET
re: Encryption Framework Discussion
Dwight Arthur / National Securities Clearing Corp   14 May 1998 4:02PM ET