[60199] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Can you keep a secret? This encrypted drive can...

daemon@ATHENA.MIT.EDU (Leichter, Jerry)
Mon Nov 6 17:32:36 2006

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 6 Nov 2006 11:32:07 -0500 (EST)
From: "Leichter, Jerry" <leichter_jerrold@emc.com>
To: Saqib Ali <docbook.xml@gmail.com>
Cc: Alexander Klimov <alserkli@inbox.ru>, cryptography@metzdowd.com,
	krstic@solarsail.hcs.harvard.edu, smb@cs.columbia.edu,
	adam@homeport.org, djm@mindrot.org, FDE@www.xml-dev.com
In-Reply-To: <addede3b0611031501r1b2e0249tee1f16f9799535ba@mail.gmail.com>

| ...Compusec is great for home / personal use. It is cheap i.e. $0.00
| (Free), and does not slow down the computer as much as the other
| products. But that is because it only support 128 bit AES, which is a
| major drawback as most enterprise settings require at least 256 bit
| AES....
Just wondering about this little piece.  How did we get to 256-bit
AES as a requirement?  Just what threat out there justifies it?
There's no conceivable brute-force attack against 128-bit AES as far
out as we can see, so we're presumably begin paranoid about an analytic
attack.  But is there even the hint of an analytic attack against AES
that would (a) provide a practical way in to AES-128; (b) would not
provide a practical way into AES-256?  What little I've seen in the
way of proposed attacks on AES all go after the algebraic structure
(with no real success), and that structure is the same in both
AES-128 and AES-256.
							-- Jerry

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post