[60424] in cryptography@c2.net mail archive
Re: Can you keep a secret? This encrypted drive can...
daemon@ATHENA.MIT.EDU (Derek Atkins)
Tue Nov 7 11:02:48 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 06 Nov 2006 18:28:14 -0500
From: Derek Atkins <warlord@MIT.EDU>
To: "Leichter, Jerry" <leichter_jerrold@emc.com>
Cc: Saqib Ali <docbook.xml@gmail.com>,
Alexander Klimov <alserkli@inbox.ru>, cryptography@metzdowd.com,
krstic@solarsail.hcs.harvard.edu, smb@cs.columbia.edu,
adam@homeport.org, djm@mindrot.org, FDE@www.xml-dev.com
In-Reply-To: <Pine.SOL.4.61.0611061126560.8384@mental>
Quoting "Leichter, Jerry" <leichter_jerrold@emc.com>:
> | ...Compusec is great for home / personal use. It is cheap i.e. $0.00
> | (Free), and does not slow down the computer as much as the other
> | products. But that is because it only support 128 bit AES, which is a
> | major drawback as most enterprise settings require at least 256 bit
> | AES....
> Just wondering about this little piece. How did we get to 256-bit
> AES as a requirement? Just what threat out there justifies it?
> There's no conceivable brute-force attack against 128-bit AES as far
> out as we can see, so we're presumably begin paranoid about an analytic
> attack. But is there even the hint of an analytic attack against AES
> that would (a) provide a practical way in to AES-128; (b) would not
> provide a practical way into AES-256? What little I've seen in the
> way of proposed attacks on AES all go after the algebraic structure
> (with no real success), and that structure is the same in both
> AES-128 and AES-256.
It's a management requirement. The manager sees "AES128" and "AES256"
and thinks "256 must be better than 128" and therefore the edict comes
down that AES256 must be used. It's not a technical decision. It's
not a decision made by analyzing the threats. It's made purely
by assertion, but it's a decision that can't easily be refuted.
> -- Jerry
-derek
--
Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
Member, MIT Student Information Processing Board (SIPB)
URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH
warlord@MIT.EDU PGP key available
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com