I'm currently writing an examen about 'Lessons Learned in the IT-Security'. I already found some thing, which shouldn't be done. But right now I'm in trouble finding the reasons why not to do so. Maybe you could explain me why or even better know about any citable source, which describes the following:
- Why don't I use the same key for encryption in both ways?
- Why don't I use the same key for encryption and authentication?
It would also be helpful, if anyone could tell me about known attacks, that exploit the mistakes above.
By the way I used this site: Lessons learned and misconceptions regarding encryption and cryptology as the starting point for my research.